MALICIOUS
150
Risk Score
Malware Insights
MITRE ATT&CK
T1566.002 Spearphishing Attachment
T1059.001 PowerShell
The PDF contains a link that redirects to known malicious infrastructure, as indicated by the PDF_MALICIOUS_REDIRECTOR_LINK heuristic. The document body, though heavily obfuscated, contains the URL https://ttraff.ru/wix?keyword=words+of+radiance+quotes, which is the primary IOC. The PDF_SEO_LINK_FARM heuristic suggests the PDF is part of a larger link farm designed for SEO manipulation, likely to distribute malicious content. The ML classifier also strongly indicates maliciousness.
Machine Learning
- Nyx PDF Classifier malicious score 1.0000
Heuristics 3
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://ttraff.ru/wix?keyword=words+of+radiance+quotes
- https://static.usrfiles.com/ugd/eb5a6a_553c3589f1f642b598b7979d326d7d3c.pdf
- https://static.usrfiles.com/ugd/b8c837_a0d3364034134d359eb31f41ffd4f906.pdf
- https://static.usrfiles.com/ugd/b8c837_fbc3e5146f5d47b9bd1c8682daaed1fc.pdf
- https://static.usrfiles.com/ugd/b8c837_d967a99cd044451d89a542901f258b04.pdf
- https://static.usrfiles.com/ugd/d2cc1f_7ad68c2b3b2544c093b759e87033fcc5.pdf
- https://static.usrfiles.com/ugd/a64c8c_50bcbd8fa7f6490a91e79960eba04963.pdf
- https://static.usrfiles.com/ugd/b8c837_ad74b0de7d444d92bd1906a93270d4a2.pdf
- https://static.usrfiles.com/ugd/d01287_6dd77f5c19e748338ff0c1c5d3d35575.pdf
- https://cdn.shopify.com/s/files/1/0428/9835/8432/files/15138334831.pdf
- https://cdn.shopify.com/s/files/1/0432/6939/0500/files/36735456915.pdf
- https://cdn.shopify.com/s/files/1/0432/1044/0862/files/34052256161.pdf
- https://cdn.shopify.com/s/files/1/0434/6888/2072/files/folawelepidok.pdf
- https://cdn.shopify.com/s/files/1/0432/3111/7467/files/agisoft_photoscan_tutorial_italiano.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00010f9f.bin9844dcf1fe2707184926d64f9f804e79ed6740172809ff0c3cfd08bd18a76d19 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x10F9F | 5120 bytes |
font_01_sfnt_off00012127.bin134c6dc2c6e64689580d6897ebbede6edbd3f6009d7c94dd9389ba2624c5444b |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x12127 | 10372 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.