MALICIOUS
150
Risk Score
Malware Insights
MITRE ATT&CK
T1566.002 Spearphishing Attachment
T1204.002 Malicious Link
The PDF contains a large number of embedded links, many of which point to a redirector service. The primary malicious URL identified is ttraff.ru, which is flagged as a malicious redirector. The document body, though heavily obfuscated, contains references to marketing and PDF content, likely serving as a lure. The ML classifier strongly indicates maliciousness.
Machine Learning
- Nyx PDF Classifier malicious score 1.0000
Heuristics 3
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://ttraff.ru/pify?keyword=marketing+pdf+for+secondary+school
- http://zumala.lamotteviolins.com/uploads/1/3/2/7/132710712/vumuxajanidami.pdf
- http://zokatokoj.affordablestoragebrownfield.com/uploads/1/3/1/4/131407469/d2fb0963fe222.pdf
- http://rajefuza.3realms.ca/uploads/1/3/1/0/131070792/vasudelawis.pdf
- https://cdn.shopify.com/s/files/1/0431/4713/3088/files/metapafimubidugadadafel.pdf
- https://cdn.shopify.com/s/files/1/0437/2905/9989/files/danadebitogib.pdf
- https://cdn.shopify.com/s/files/1/0431/2177/0656/files/18182598448.pdf
- https://cdn.shopify.com/s/files/1/0428/5412/1635/files/buveraresobo.pdf
- https://cdn.shopify.com/s/files/1/0431/5080/3099/files/xabinemifelinewesobo.pdf
- https://cdn.shopify.com/s/files/1/0428/9835/8432/files/86399573169.pdf
- https://cdn.shopify.com/s/files/1/0435/0679/4656/files/effects_of_hyperinflation_in_zimbabwe.pdf
- https://cdn.shopify.com/s/files/1/0433/3672/8735/files/take_a_shot_for_me_lyrics.pdf
- https://cdn.shopify.com/s/files/1/0431/3199/4280/files/kakenuzipogatemolojiw.pdf
- https://cdn.shopify.com/s/files/1/0433/2378/5370/files/guwajoxuna.pdf
- https://cdn.shopify.com/s/files/1/0429/7526/4919/files/88654587145.pdf
- https://cdn.shopify.com/s/files/1/0430/1350/5185/files/how_to_make_a_enderman_farm.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Extracted artifacts 3
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off000067ea.bin37aaf3f89df14b260fed3eac9354fd03bb53921e92ab2d7196dc9c3f15c1b58c |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x67EA | 5376 bytes |
font_01_sfnt_off00007a3d.bin8c2162cdbd95ea87af1258f3ab33ea667c82b6959dc7370107de2b9c9ea4540b |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x7A3D | 10536 bytes |
font_02_sfnt_off00009e3e.bin05d2457133b820fa77aa358e30e9acfbad3f04c46ced9a37296d9311117db176 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x9E3E | 4324 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.