MALICIOUS
184
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF file contains a large number of embedded links, many of which point to disposable hosting and redirectors, indicating a link farm or SEO spamming operation. One prominent link, 'https://ttraff.link/wix?keyword=scatter+plots+and+correlation+worksheet+answer+key', is flagged as malicious. The document body, though heavily obfuscated, contains this URL, suggesting an attempt to disguise malicious activity as a legitimate worksheet answer key. The ML classifier also strongly indicated maliciousness.
Machine Learning
- Nyx PDF Classifier malicious score 1.0000
Heuristics 5
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARMSmall PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://ttraff.link/wix?keyword=scatter+plots+and+correlation+worksheet+answer+key
- http://vogamogad.wallaroocampinghire.com/uploads/1/3/2/8/132815296/17edad938a53.pdf
- http://zawexap.wildtimes.co.uk/uploads/1/3/0/7/130739206/jujeretazeru-nozum-fapawedawonog.pdf
- http://files.csno-sdi.org/uploads/1/3/2/7/132710763/jifukav.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- http://www.daltonmaag.com/
- https://daf55b59-bcf6-4ae4-8acc-4680fd208ff2.filesusr.com/ugd/01f9b9_12f3dc216c4749c7b23fb2bb0cd43e14.pdf?index=true
- https://8980c9d2-0493-4edb-a8f3-2f31e7d453eb.filesusr.com/ugd/f80014_2e6f3f73b6664a9fa32c75484b2be892.pdf?index=true
- https://f33eba85-8487-4fad-8e86-eb2e9424c837.filesusr.com/ugd/cb2bed_634edab4833645828e2c1b32cf9fbf02.pdf?index=true
- https://a4bdf3a7-c796-4a38-bf58-b79d8279efe1.filesusr.com/ugd/9c66ff_87d11aa415a64dce95d4b3f8802e3826.pdf?index=true
- https://158242c9-902e-44c1-af04-4e7d39727589.filesusr.com/ugd/834936_99cedd9f03134181afc0d6a62d1ff56b.pdf?index=true
- https://f25a1696-eb74-432a-b2ef-0388d4ef3113.filesusr.com/ugd/5a1791_d518704b9cdf4eba98489427d09c98cf.pdf?index=true
- https://fe850bb2-a6b7-4543-8b9a-884920ec9b30.filesusr.com/ugd/93971e_fb45e1161a4b4e809f1f080673a278b8.pdf?index=true
- https://061c7e15-16f9-495e-bc0b-b49eb2059823.filesusr.com/ugd/f09a9d_91d7d83052004741a4b837f4ca273d44.pdf?index=true
- https://316113c7-d3d5-4d25-af78-0ef131534a94.filesusr.com/ugd/9ea91e_0d0dd95823b9427f81498fc5f7cb754d.pdf?index=true
- https://481d1367-957a-45f0-8447-51e6c062ffce.filesusr.com/ugd/9d869b_cb9ccff53e1143ed8f18f2ca88745aa1.pdf?index=true
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 3
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000e568.bin3bc159d32a7a9d4a33a9aee178410c69835b5ffbc3991075f19e463facbe4138 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xE568 | 5308 bytes |
font_01_sfnt_off0000f76a.binbdc8c22c5095ff3dbc9508b7190436f9011180d47c2139ff670d67bfa9a2578d |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xF76A | 12744 bytes |
font_02_sfnt_off00012033.bind1f4a20f0e35a0564be54678b929bb8c711862c507f070c2b9a6abea8daf4378 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x12033 | 4324 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.