MALICIOUS
150
Risk Score
Malware Insights
MITRE ATT&CK
T1566.002 Spearphishing Attachment
T1059.001 PowerShell
The PDF contains a prominent link that redirects to a malicious URL, disguised with keywords related to hacking Instagram. This is further supported by heuristics indicating a malicious redirector and a link farm, suggesting an attempt to drive traffic to malicious sites. The ML classifier also strongly flagged this PDF as malicious.
Machine Learning
- Nyx PDF Classifier malicious score 1.0000
Heuristics 3
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://ttraff.ru/wix?keyword=instagram+hack+without+survey+or+dow
- https://static.usrfiles.com/ugd/eda9ba_335e1fdb2ae340e8a8524e2be9969340.pdf
- https://static.usrfiles.com/ugd/b8c837_c8177ee939264312bc87960bd83c0ff5.pdf
- https://static.usrfiles.com/ugd/b8c837_3d8d25558c324058b98cf572a12700a8.pdf
- https://static.usrfiles.com/ugd/804ff6_ce5c3464ed284cc6bc49cc16c4315f99.pdf
- https://static.usrfiles.com/ugd/b8c837_8966cdd46d774439b8575ae65da3d8bf.pdf
- https://static.usrfiles.com/ugd/b8c837_f597cbd6716a4d549b8655d98ca9ebd9.pdf
- https://static.usrfiles.com/ugd/3f4b99_610711717ca54bd6af4ffa6b10d9217e.pdf
- https://static.usrfiles.com/ugd/83d902_185e1b8586234a9eacd97c002dc5b02f.pdf
- https://static.usrfiles.com/ugd/b8c837_90469ef81c544b36abbc2934d9dec548.pdf
- https://static.usrfiles.com/ugd/510a18_e7215d88d0cb4b27b34206a177de15c0.pdf
- https://cdn.shopify.com/s/files/1/0431/2019/7789/files/jumixawugixulemunuwixigo.pdf
- https://cdn.shopify.com/s/files/1/0435/5362/0136/files/16031048473.pdf
- https://cdn.shopify.com/s/files/1/0438/7376/3496/files/nimezopotebalexokudimi.pdf
- https://cdn.shopify.com/s/files/1/0433/0687/7080/files/3152232763.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00007871.bin2d362bd760804c0a3d91b5ed07b8dd927191196132a3f53645ae37318234b69a |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x7871 | 5576 bytes |
font_01_sfnt_off00008b4c.binac6ca622073391cb61902830537bc33b3d2021d3ba68f6da8916df4c4756bca3 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x8B4C | 10944 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.