MALICIOUS
150
Risk Score
Malware Insights
MITRE ATT&CK
T1566.002 Spearphishing Attachment
T1204.002 Malicious Link
The PDF contains a large number of embedded links, many of which point to suspicious domains and are likely part of an SEO link farm. One prominent link, 'https://ttraff.link/wix?keyword=fabozzi+fixed+income+pdf+free+download', is identified as a malicious redirector. The document body, though heavily corrupted, contains fragments of text related to financial documents and the malicious URL, suggesting a lure to trick users into downloading malware or visiting a malicious site.
Machine Learning
- Nyx PDF Classifier malicious score 1.0000
Heuristics 3
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://ttraff.link/wix?keyword=fabozzi+fixed+income+pdf+free+download
- http://bisimizil.pldogwalking.nyc/uploads/1/3/1/4/131408899/jokekemogud.pdf
- http://files.kachinacountryusa.com/uploads/1/3/1/4/131438397/9475990.pdf
- http://files.aasstcjr.com/uploads/1/3/1/8/131857305/nimovupul.pdf
- http://nexajejo.jjphotos.net/uploads/1/3/1/4/131407406/xiwapelufam.pdf
- http://fenebe.awakeningtoyes.com/uploads/1/3/2/6/132695829/2bf004befd6241.pdf
- http://files.djheylove.com/uploads/1/3/1/6/131606174/kolakekozepuzexew.pdf
- http://xadologu.yosnacks.org/uploads/1/3/1/6/131637312/japepagonesimigixa.pdf
- http://woromade.perryperkcoffee.com/uploads/1/3/1/1/131164250/zafejesug.pdf
- http://files.kreativefutures.co.uk/uploads/1/3/1/3/131382113/598164.pdf
- https://faafb2e2-fa8a-4dff-9d4d-0f92c9c4c8ea.filesusr.com/ugd/3f0e57_2db16e50b95f457e97cb79d0e800ee9d.pdf?index=true
- https://a2c59122-d7f5-4c5b-a648-a874f8b4facb.filesusr.com/ugd/1c8c6c_7968b841c72f4080b7de928c5ed3b929.pdf?index=true
- https://643fa8bb-877c-44c0-aa38-6e291f1be8eb.filesusr.com/ugd/3bbd68_8f9b887c922947d8ad9ae4fdfe58811f.pdf?index=true
- https://75ea28ff-c03c-4242-ae2e-3ff957033fee.filesusr.com/ugd/cec570_0b578f2924b442c78746088bd6d6a7a4.pdf?index=true
- https://7116e16c-1d8a-4a01-8c9d-4f8da667160a.filesusr.com/ugd/5f5755_33865f855f944332ab3b59d7120cfcf1.pdf?index=true
- https://453618bd-547c-41ef-931b-0fe9f1da48ce.filesusr.com/ugd/ee4a13_90083875ef7b452ea7a1a9c01952a551.pdf?index=true
- https://5eb4cf8b-3dc3-4585-8198-dd61a0d27aba.filesusr.com/ugd/3bcfef_2c829e61c1864b13bc99a9a2fa5cb694.pdf?index=true
- https://72b225ec-4a34-4d98-bca0-6f53170fad75.filesusr.com/ugd/19103d_89a5c01dc89c4244972ab8036b43bff2.pdf?index=true
- https://04cb7ade-8699-4b1e-a837-1d608fc65977.filesusr.com/ugd/71fd01_b6fa21c0ef6f43ccb17e4a6bdc4f8926.pdf?index=true
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00004e2d.bin289fed32442ad93601035e7723eb655e3be1b6fe78d7e53a7c3e89151c5d9f78 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x4E2D | 5428 bytes |
font_01_sfnt_off000060ab.bina7835246644d0571ae07714b80980e6acbb297d3d5958fafd0c2cf24ec068aca |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x60AB | 9932 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.