MALICIOUS
150
Risk Score
Malware Insights
MITRE ATT&CK
T1566.002 Spearphishing Attachment
T1059.001 PowerShell
The PDF contains a heuristic firing for a malicious redirector link, specifically pointing to 'ttraff.com'. The document body, though heavily obfuscated, contains text related to 'triple beam balance worksheet answers' and the malicious URL itself, suggesting a lure to trick users into clicking the link. The presence of numerous other PDF links, many pointing to Shopify domains, indicates a link farm strategy, likely for SEO poisoning or to obscure the malicious destination. No scripts were extracted from this sample.
Machine Learning
- Nyx PDF Classifier malicious score 1.0000
Heuristics 3
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://ttraff.com/wix?keyword=triple+beam+balance+worksheet+answers
- http://dufodaze.vtk.co.nz/uploads/1/3/2/6/132695643/3961732.pdf
- http://files.willettswelding.com/uploads/1/3/1/4/131437402/1778848.pdf
- http://koxopimo.bzhanglab.com/uploads/1/3/0/9/130969186/retonuduxegugova.pdf
- http://bopul.vigilantics.com/uploads/1/3/1/1/131164104/6947007.pdf
- https://cdn.shopify.com/s/files/1/0430/2916/8282/files/airplane_english_movie_free.pdf
- https://cdn.shopify.com/s/files/1/0436/0978/4482/files/65717118473.pdf
- https://cdn.shopify.com/s/files/1/0463/5118/8125/files/wujimuletafeboso.pdf
- https://904526ea-8b80-410d-a713-7974c6932f55.filesusr.com/ugd/9b7d8a_448299f4ce784f9996a301ed69597a8f.pdf?index=true
- https://7a6f93d3-38f4-4d94-888d-48c52ae1a901.filesusr.com/ugd/7cefa9_58c6faa413104fb493489e1a43b21cb1.pdf?index=true
- https://0a356b5f-edea-4b3d-83c5-2d73396b84e1.filesusr.com/ugd/8ba634_90d496557ff5469eb1901cacb82414ff.pdf?index=true
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00004f2c.bindc2cace1db89d6ec1652d4eddc2aaa39b6d751afdd18cb4280dcf565cd4f1095 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x4F2C | 5416 bytes |
font_01_sfnt_off0000617a.bineb0e3abbf58b08fb8c2dbe02c6b1e6c468a8a480ad702a33bccd78af04a83dfe |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x617A | 10132 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.