MALICIOUS
150
Risk Score
Malware Insights
MITRE ATT&CK
T1566.002 Spearphishing Attachment
T1059.001 PowerShell
The PDF contains a critical heuristic firing for a malicious redirector link, specifically pointing to 'https://ttraff.me/wix?keyword=spotify+mega+mod+apk+no+root'. The document body also contains this URL, suggesting the primary purpose is to redirect users to potentially malicious content under the guise of providing a modded application. The ML classifier also strongly indicated maliciousness.
Machine Learning
- Nyx PDF Classifier malicious score 1.0000
Heuristics 3
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://ttraff.me/wix?keyword=spotify+mega+mod+apk+no+root
- https://e4e56192-bc0c-48bd-8237-376084091555.filesusr.com/ugd/ea9bdf_e4632c9e5c674249b854f30b5b5895f0.pdf?index=true
- https://cc371ef8-90b7-43b4-bf86-72c07322589c.filesusr.com/ugd/22bf55_5b54e0806f50418d936b859b14d25ac7.pdf?index=true
- https://38895414-ccd8-4e43-a36d-b7f30daed8d4.filesusr.com/ugd/7d21c0_0bc76978478344f7afec5e7ea00609d6.pdf?index=true
- https://cdn.shopify.com/s/files/1/0436/5287/4390/files/axis_mutual_fund_sip_form.pdf
- https://8e0bf6df-a4b2-46ea-adcf-f597c2ce9202.filesusr.com/ugd/694d5d_c2a315e6b90d46cb833dc444045714b7.pdf?index=true
- https://1926c750-463e-4ef1-b1a1-57a0646c4360.filesusr.com/ugd/97aff7_08358923c96544be8d6aa36dd6e8da57.pdf?index=true
- https://65846087-24f5-4e98-9375-ed3239580191.filesusr.com/ugd/4f270c_4452bd3ba23547d7ac31f270f74474b2.pdf?index=true
- https://81ef9909-2941-4c5d-8d1d-7983234c2ef3.filesusr.com/ugd/9ff9b8_35b3c5eab5c842a38f3de0cc0cb97e0d.pdf?index=true
- https://303a5c24-5647-4cb4-b1a3-1d3d36e3bf88.filesusr.com/ugd/5f226e_d67d4d5280fa487489842506a6a821f4.pdf?index=true
- https://08e7f8ce-ae88-4d2e-b150-fbe1b477d5f5.filesusr.com/ugd/270e53_10b7387426a84deeaa76ff90fb8214fe.pdf?index=true
- https://5a4cea68-2074-42f5-b97e-fbacd63edfb3.filesusr.com/ugd/0e2875_cc1cacf3ef1b42a781961e2e6b6f2f22.pdf?index=true
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00008192.bin7cc0ec4bef0642ee003c8ac968c4afa3b652bd6d7a15a1078da268a20b372523 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x8192 | 5420 bytes |
font_01_sfnt_off000093fc.bine8254365f9202799a9bf4086ed1d9af325f79251cdc4d98b62d71a59a6ad8c67 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x93FC | 10828 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.