MALICIOUS
152
Risk Score
Malware Insights
MITRE ATT&CK
T1566.002 Spearphishing Attachment
T1204.002 Malicious Link
The PDF was flagged by a malicious classifier and contains a large number of embedded links, many of which point to a link farm. One of the primary links, 'https://ttraff.com/pify?keyword=already+by+beyonce+and+shatta+wale', is identified as a known malicious redirector. The document body contains text related to this URL, suggesting a lure to entice users to click the malicious links.
Machine Learning
- Nyx PDF Classifier malicious score 1.0000
Heuristics 4
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://ttraff.com/pify?keyword=already+by+beyonce+and+shatta+wale
- http://tirojo.nutrition-girl.com/uploads/1/3/1/3/131383900/vigexewumuga_xejexasifofa_bikale_buvejaxolemoge.pdf
- http://zorajefek.freshenitup.org/uploads/1/3/1/6/131636655/7442652.pdf
- https://cdn.shopify.com/s/files/1/0427/8734/0454/files/8512922810.pdf
- https://cdn.shopify.com/s/files/1/0436/1319/2349/files/vunafunatexijaligupawew.pdf
- https://cdn.shopify.com/s/files/1/0433/3522/1403/files/nba_teams_names.pdf
- https://cdn.shopify.com/s/files/1/0438/1478/1085/files/65432915867.pdf
- https://cdn.shopify.com/s/files/1/0439/9644/6878/files/prevalence_of_gestational_diabetes_mellitus.pdf
- https://cdn.shopify.com/s/files/1/0432/3305/0779/files/stewart_calculus_7th_edition.pdf
- https://cdn.shopify.com/s/files/1/0429/8326/0314/files/the_national_interest_in_international_relations_theory_scott_burchill.pdf
- https://cdn.shopify.com/s/files/1/0432/1122/7300/files/26900997963.pdf
- https://cdn.shopify.com/s/files/1/0436/9163/8934/files/16729841000.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Extracted artifacts 5
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00005cb7.bin46c6ad6f5141016dd22db0e8b34242e49ef9b3ba32fdcc6cce8b0ed0ca66b897 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x5CB7 | 6872 bytes |
font_01_sfnt_off00006e0d.bina2a799ce2b0b5ab31c7d4d505f9df620226b876b5a809a871ff370175d692a90 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x6E0D | 5352 bytes |
font_02_sfnt_off00008036.binc16475d6647fef86f330377503a124e3260ff3496e63d7a128f689530eee7d6b |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x8036 | 11524 bytes |
font_03_sfnt_off00009bb3.bin5d958b343f047ee2c127f2964caf097ba133bd1f36bea70d41aae3026f6e0f5e |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x9BB3 | 10704 bytes |
font_04_sfnt_off0000c097.bin72b7bf7dadd2b26e29884f883b7a62650a2b85a6e7bd85938e5dd47c4a44031e |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xC097 | 16760 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.