Malware Insights
The PDF file contains numerous embedded links, with a critical heuristic firing indicating a link to known malicious redirector infrastructure. The document body, though heavily obfuscated, contains the URL 'https://ttraff.cc/pify?keyword=shrug+copy+and+paste', which is flagged as malicious. The presence of a large number of external PDF links, many hosted on cdn.shopify.com, suggests a link farm or content distribution network being abused for malicious purposes. No scripts were extracted, but the primary attack vector appears to be the malicious redirection URL.
Machine Learning
- Nyx PDF Classifier malicious score 0.9995
Heuristics 4
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://ttraff.cc/pify?keyword=shrug+copy+and+paste
- http://files.happymamahappybaby.us/uploads/1/3/0/7/130739116/0c268.pdf
- http://files.goldenruleservices.org/uploads/1/3/0/7/130739533/tigorogajojek.pdf
- http://files.glennmarshall.org/uploads/1/3/1/4/131408899/jagopiliteleva-bovofe.pdf
- http://files.narragansettgunclub.com/uploads/1/3/0/8/130815009/4292611.pdf
- https://cdn.shopify.com/s/files/1/0433/1218/5499/files/zunenukutolovuwi.pdf
- https://cdn.shopify.com/s/files/1/0434/3303/3877/files/reroboxetavimefekalibu.pdf
- https://cdn.shopify.com/s/files/1/0430/6799/8359/files/gilipesujoru.pdf
- https://cdn.shopify.com/s/files/1/0429/9735/0554/files/14258873411.pdf
- https://cdn.shopify.com/s/files/1/0429/6055/2085/files/52808695813.pdf
- https://cdn.shopify.com/s/files/1/0431/0879/4525/files/nimozunuxom.pdf
- https://cdn.shopify.com/s/files/1/0439/7747/4206/files/78583625475.pdf
- https://cdn.shopify.com/s/files/1/0434/1573/2376/files/98994389645.pdf
- https://cdn.shopify.com/s/files/1/0432/6499/9590/files/gopalutadoduwojipitokano.pdf
- https://cdn.shopify.com/s/files/1/0430/7084/9181/files/73616719421.pdf
- https://cdn.shopify.com/s/files/1/0431/5506/2938/files/movif.pdf
- https://cdn.shopify.com/s/files/1/0435/9746/3715/files/bimekujoni.pdf
- https://cdn.shopify.com/s/files/1/0433/9548/1750/files/83221777645.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Extracted artifacts 8
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
stream_006_off00009119.bin737fdb128980c29202f199d669df1c2b9bc8674595f8343a561c7e0c0acd5c0c |
decompressed-pdf-stream | PDF FlateDecoded stream at offset 0x9119 | 1540 bytes |
font_00_sfnt_off00005f40.bin27ad38335e32635d295e7e07cac0ac0d8bfe740def189a00df18c31e4a990cf8 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x5F40 | 4104 bytes |
font_01_sfnt_off00006d48.bin818b7a0944e05ab14dd82785615c48a7a053fb554bbce39b0288da5b5242cea9 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x6D48 | 5340 bytes |
font_02_sfnt_off00007f69.bin3791412462341bc546155723b24bf67472bb9bcfc57cb17b600505a7dcb7469a |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x7F69 | 8904 bytes |
font_04_sfnt_off00009958.bin1dee64feb338e2cc595d88a35b766ea8b8b199e124349708576bb4cf11bee47e |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x9958 | 1772 bytes |
font_05_sfnt_off0000a20b.bin0e3146ffbced92169f24fa65ca38bcb9d49a961aa0e9ec5cef978e14f2058ac0 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xA20B | 12560 bytes |
font_06_sfnt_off0000cced.bin7c080d2a132b47f4cbc2ca4f1f053a7172fce262fc41b07a076770ad6710c486 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xCCED | 18080 bytes |
font_07_sfnt_off0000e91f.bina542ec26cea93e049a2e27cd59b1347dd9bbdea13775fd7b822b3c2b3136116f |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xE91F | 4324 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.