Malware Insights
The PDF contains a heuristic firing for a malicious redirector link, pointing to 'https://ttraff.cc/wix?keyword=kingdom%253A+new+lands+royal+edition'. The document body, though heavily obfuscated, contains references to 'Kingdom: new lands royal edition' and the malicious URL, suggesting a lure to a fake game or software download. The PDF also exhibits characteristics of a link farm, with numerous embedded links, many pointing to Shopify domains, but the primary malicious intent appears to be the redirector. No scripts were extracted from this sample.
Machine Learning
- Nyx PDF Classifier malicious score 1.0000
Heuristics 3
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://ttraff.cc/wix?keyword=kingdom%253A+new+lands+royal+edition
- https://cdn.shopify.com/s/files/1/0429/1903/5033/files/42733067383.pdf
- https://cdn.shopify.com/s/files/1/0430/8933/0330/files/nested_for_loops_javascript.pdf
- https://cdn.shopify.com/s/files/1/0438/8130/0123/files/31655748887.pdf
- https://cdn.shopify.com/s/files/1/0427/8992/9116/files/tukinebutemivemisejo.pdf
- https://cdn.shopify.com/s/files/1/0428/2161/5775/files/nasabibodugadirebiveba.pdf
- https://static.usrfiles.com/ugd/a86d68_ea78c4d2c2a4479e9a9762d540708370.pdf
- https://static.usrfiles.com/ugd/eaf48f_c65480855d644eca9b61381ec77cb53a.pdf
- https://static.usrfiles.com/ugd/12dc78_df465ec70e2f475aa10b428e53ee0704.pdf
- https://static.usrfiles.com/ugd/7baf93_a02d8abfef324f1caa8d0fe9cd66fb07.pdf
- https://static.usrfiles.com/ugd/e2b09b_aa53ebd962624083881f4907fec7a559.pdf
- https://static.usrfiles.com/ugd/b8c837_3423be792ee54b759835f1d68b388df1.pdf
- https://static.usrfiles.com/ugd/b8c837_b5dee72b39b8427087733b168de09a7f.pdf
- https://static.usrfiles.com/ugd/1e32c2_76771a50ec394b57bfb98bc4cd0a18ee.pdf
- https://static.usrfiles.com/ugd/314c35_343147ee7b2e4d7db4c8bf0d10e2f34c.pdf
- https://static.usrfiles.com/ugd/2b25b5_7085a0ec6f3d41538b3736cc68aa1ee2.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Extracted artifacts 3
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off000050f0.bin91c30e2d1ada78d216450f988df81a9b8af68f06a1eabed5d87816fe5ae9965c |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x50F0 | 3352 bytes |
font_01_sfnt_off00005cef.bin75abe8cccbcb5e7e31779bf483a3b2b2c243d2c891e9557e20a2749423c512c0 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x5CEF | 5360 bytes |
font_02_sfnt_off00006f22.bin7a31672d0034836e9de9c24d507eb3456ab0c00efab1b5a3f220ccd71aa3a57d |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x6F22 | 12592 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.