MALICIOUS
152
Risk Score
Malware Insights
MITRE ATT&CK
T1566.002 Spearphishing Attachment
T1204.002 Malicious Link
The PDF contains embedded links that redirect to a malicious domain, identified by the PDF_MALICIOUS_REDIRECTOR_LINK heuristic. The document body, though heavily obfuscated, contains text suggesting it is a 'Spectrum math workbook grade 7 answer key' and includes the malicious URL, indicating a lure to a phishing or malware distribution site. The PDF_SEO_LINK_FARM heuristic further suggests the document is part of a larger link farm designed for SEO manipulation, likely to distribute malicious content.
Machine Learning
- Nyx PDF Classifier malicious score 0.9999
Heuristics 4
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://ttraff.club/wix?keyword=spectrum+math+workbook+grade+7+answer+key
- https://0ab20def-f588-4b60-9c28-43f3d6cb62ac.filesusr.com/ugd/031dda_5d26355ee3354170aac62bc352b875f0.pdf?index=true
- https://2d71682f-d2ae-4002-b42f-11585e70ab08.filesusr.com/ugd/d2759c_192874e227cf43b59c5fd5a3e95855db.pdf?index=true
- https://033bf012-c28f-4e5d-9d61-9a4cc1c838ea.filesusr.com/ugd/cc3ca9_fdefa1e40a6645368a5bf442be79278d.pdf?index=true
- https://521216f7-0dba-4108-9c07-5b48e134597c.filesusr.com/ugd/ede58b_464a597be5984ee7809e251ad20d3676.pdf?index=true
- https://f422d990-a528-4345-b479-2ca619a16975.filesusr.com/ugd/3f2390_0212aca13845410c8bf6a5dc99afe6db.pdf?index=true
- https://fded8412-78e7-4c39-bf82-453f95764885.filesusr.com/ugd/0779a3_d652f2b440ff4c6aa32103c9383011d1.pdf?index=true
- https://e6b3a09b-cf52-49ad-aa37-d062a7168157.filesusr.com/ugd/b0c8dc_7ab82e3a53cd4da8aebc6d0a07f757ef.pdf?index=true
- https://e91ce143-a727-41dc-97c4-b41ab04e943e.filesusr.com/ugd/c33cdb_d4d3aa2731264dc59fb57e611334cb4f.pdf?index=true
- https://cdn.shopify.com/s/files/1/0434/0239/5813/files/optical_properties_of_nanomaterials_nptel.pdf
- https://cdn.shopify.com/s/files/1/0431/7013/6218/files/como_convertir_un_a_word_en_mac.pdf
- https://cdn.shopify.com/s/files/1/0433/7932/7141/files/mumutevojododonugigorene.pdf
- https://35781ef4-bda8-4870-bf97-ad54a9e33a20.filesusr.com/ugd/6f58fb_b5cfa8b0ea724dc2b81c4199884bc201.pdf?index=true
- https://e2604a1c-989c-4f48-adee-40f92e352442.filesusr.com/ugd/a43ec6_f07b88f57e914767a78db44287219d39.pdf?index=true
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Extracted artifacts 4
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00018c02.binedc4a30b9c6c4ad0e3dec7aa625d66200dd4fd535e3253d8b4d73d12b589314e |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x18C02 | 6036 bytes |
font_01_sfnt_off0001a07c.bin9ff755b184ba5ea193be6bfccb632d04c4e59bccea95c1885941b548de693ae9 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x1A07C | 20908 bytes |
font_02_sfnt_off0001c07c.bineeb296a68bc4475c80278b740af9b4ecd04c2d3fa24c2173e3a7dc55905a40e5 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x1C07C | 4092 bytes |
font_03_sfnt_off0001d047.bin7c8c239a538eef9f242aaf042385fcd75ce9fd3f5672601b741e0262e41ac728 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x1D047 | 11172 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.