MALICIOUS
152
Risk Score
Malware Insights
MITRE ATT&CK
T1566.002 Spearphishing Attachment
T1204.002 Malicious Link
This PDF file contains numerous embedded links, forming a link farm designed to redirect users. One prominent malicious redirector URL is https://ttraff.club/wix?keyword=gordon+ramsay+knives+nz. The ML classifier strongly indicated maliciousness, and the PDF structure suggests a deliberate attempt to obscure the malicious intent through a large number of links. No scripts were extracted, and the document body was heavily obfuscated.
Machine Learning
- Nyx PDF Classifier malicious score 1.0000
Heuristics 4
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://ttraff.club/wix?keyword=gordon+ramsay+knives+nz
- http://files.stjohnlandconservancy.org/uploads/1/3/1/1/131164311/jeref.pdf
- http://vovupuv.frank-webb.com/uploads/1/3/1/4/131482952/1731168.pdf
- http://files.arkjprogram.com/uploads/1/3/1/1/131164202/wefizanu.pdf
- https://73437945-31ea-4a53-8f26-0b1049349dcd.filesusr.com/ugd/610d21_5ae5bab5df7546bb9dd6ffab81360259.pdf?index=true
- https://74936539-5713-45eb-9f9a-d2a2f4be7ac6.filesusr.com/ugd/911c12_e9859a0615154e808df263a38765d0dd.pdf?index=true
- https://d2b09253-1561-43ef-9161-05034f914254.filesusr.com/ugd/625844_eabfb73cf0e84f139d8d6c1e1f9bf909.pdf?index=true
- https://357c084e-71e6-40af-8b83-297a8dc89711.filesusr.com/ugd/3283b0_ea3eea5b30f04dda98360a812a6d2c23.pdf?index=true
- https://a229a4db-81a9-489e-8a6a-589d0ee31073.filesusr.com/ugd/6203b9_354e2f1591a24c9cb6b0935615f8d027.pdf?index=true
- https://28d9adbb-9883-4f0a-a8f8-444006670539.filesusr.com/ugd/0cd3a8_a8d4a2fc22454d7abfa3b2c018889216.pdf?index=true
- https://a3f0be66-a022-4bbb-b5aa-3d88afbb0dc6.filesusr.com/ugd/e3c460_6949479b699f4cf897e6b6f730d5d400.pdf?index=true
- https://2ccb5821-aa6a-4571-9e40-68c9d4e4952c.filesusr.com/ugd/48bf55_2a6982a33f82438786d39771bd82d9cd.pdf?index=true
- https://6169c09d-20cd-4e83-98c5-5be0440a95b9.filesusr.com/ugd/145364_ebb302fb0ecb4945b3d988de599d5a1b.pdf?index=true
- https://58718531-b675-40fb-af6a-b45b55426d38.filesusr.com/ugd/5ea691_6d0da446df1249fe8d7bf5b42ac348e4.pdf?index=true
- https://c1d49198-9e1e-434d-87e4-e3bbdd557813.filesusr.com/ugd/dcf311_0bff750c5f5c428bbeda8a90df3a7f76.pdf?index=true
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00005d39.bin5d7be9e5a7a82f2a04d5add97033c18747825b723c9d800bd369f4a1bcf78c90 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x5D39 | 5244 bytes |
font_01_sfnt_off00006f12.binbf7fe9f7dae71340214000f18738fdb980fc722c30274a1d19a4b86b55a86f24 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x6F12 | 10396 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.