MALICIOUS
150
Risk Score
Malware Insights
MITRE ATT&CK
T1566.002 Spearphishing Attachment
T1059.001 PowerShell
The PDF file contains a large number of embedded links, many of which point to a link farm designed to manipulate search engine results. One prominent link redirects to a malicious domain, 'ttraff.club', which is likely used for phishing or malware distribution. The document body, though heavily obfuscated, contains text related to a weather report, serving as a lure. The presence of numerous PDF links and a malicious redirector strongly suggests an attempt to drive traffic to malicious infrastructure.
Machine Learning
- Nyx PDF Classifier malicious score 1.0000
Heuristics 3
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://ttraff.club/wix?keyword=jaunpur+current+weather+report
- https://cdn.shopify.com/s/files/1/0432/1034/2559/files/80986709661.pdf
- https://cdn.shopify.com/s/files/1/0435/5942/0063/files/irrigation_engineering_by_rk_sharma_free_download.pdf
- https://cdn.shopify.com/s/files/1/0435/0155/1771/files/65618712924.pdf
- https://cdn.shopify.com/s/files/1/0447/8432/0661/files/origin_and_development_of_sociology_and_anthropology.pdf
- https://static.usrfiles.com/ugd/436160_14c483072e214444a97cee3ef15aaf51.pdf
- https://static.usrfiles.com/ugd/c4f63d_cf4de22021ee42b1b6c57bcfcbf5a2c6.pdf
- https://static.usrfiles.com/ugd/b8c837_b04b151de58545ecbe6dbab3f5d30991.pdf
- https://static.usrfiles.com/ugd/762c1a_4c1c294142a94e5a87ce357d86860d6f.pdf
- https://static.usrfiles.com/ugd/b8c837_fb4b5bde7f1349dd9374ac1656a84e99.pdf
- https://static.usrfiles.com/ugd/b8c837_042c7a517b0643419b96d90e413b3267.pdf
- https://static.usrfiles.com/ugd/c63dba_49eeead2d9b441648609745dda50fa53.pdf
- https://static.usrfiles.com/ugd/2994dd_aaf595824a084ca7b9adad5d4c8b6f36.pdf
- https://static.usrfiles.com/ugd/79cb75_52989b6302184e44805867a6910055d2.pdf
- https://static.usrfiles.com/ugd/d1d005_c46e00e017824336bed74a9c62f5058b.pdf
- https://static.usrfiles.com/ugd/b8c837_f51a4045a515473d84f23bf42b5d6aa6.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00005333.bin67cc39d80309ec6ac21ce1438204d8102618c08d1f866d017888ec85397ebba1 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x5333 | 4892 bytes |
font_01_sfnt_off000063e9.bin87f0c9cfefb0cbe76a347f0a570217ae0259c6fa7beb5914a78647804218f570 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x63E9 | 9972 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.