Malware Insights
The PDF was flagged by multiple critical heuristics for containing malicious redirector links and a link farm. The primary malicious URL, https://ttraff.cc/wix?keyword=comptia+a++complete+study+guide%253A+exams+220-901+and+220-902%252C+3rd+edition+%2528220-901%252F220-902%2529+pdf, is associated with known malicious redirector infrastructure. The document body appears to be malformed or obfuscated, but the presence of numerous links to static.usrfiles.com suggests an attempt to create a large number of SEO-optimized links, likely to mask the malicious redirector.
Machine Learning
- Nyx PDF Classifier malicious score 1.0000
Heuristics 3
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://ttraff.cc/wix?keyword=comptia+a++complete+study+guide%253A+exams+220-901+and+220-902%252C+3rd+edition+%2528220-901%252F220-902%2529+pdf
- https://static.usrfiles.com/ugd/b8c837_cd37b76d2ec74490b5eea5eed756c6b8.pdf
- https://static.usrfiles.com/ugd/b8c837_01997eb66f384cb2b5483b4ff4489c7d.pdf
- https://static.usrfiles.com/ugd/b8c837_c3954f0b56d548478077c4952f816435.pdf
- https://static.usrfiles.com/ugd/b8c837_c20eb92b6cb9488897b5fdd42d1e0f5c.pdf
- https://static.usrfiles.com/ugd/b8c837_7c8334de11cb427abfe117f3087708ba.pdf
- https://static.usrfiles.com/ugd/b8c837_5a4f4d32b2624a3fbff21338455a56a7.pdf
- https://static.usrfiles.com/ugd/b8c837_088496f877554fc7baa16a55277a884e.pdf
- https://static.usrfiles.com/ugd/b8c837_e7a8f57579a54e8bb5522ce5f8d24548.pdf
- https://cdn.shopify.com/s/files/1/0437/0182/9797/files/green_lantern_2_movie_free.pdf
- https://cdn.shopify.com/s/files/1/0454/2965/3660/files/the_water_cycle_worksheet_answers_biology.pdf
- https://cdn.shopify.com/s/files/1/0431/8347/2802/files/xozowemibemowun.pdf
- https://static.usrfiles.com/ugd/b8c837_9ed621cae4ff4374b95ba5c56f3b0acf.pdf
- https://static.usrfiles.com/ugd/b8c837_6a48313f12cb42d1958bc16b95cd16cc.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Extracted artifacts 3
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00006811.bin31332289a6fcfc8ed0656f210abd9afc52ad5d9fc8af96f88723e38f5608596e |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x6811 | 6524 bytes |
font_01_sfnt_off00007e5b.bin5979b9af21d06f7ac405fa551ac1a7f29deafe2275113ca9827920dbb1e7759d |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x7E5B | 14076 bytes |
font_02_sfnt_off0000ab4e.bin4fcfa7c68d76e23b667942a3ac892d2d5d88346478daafc61479ad4df4af3dd3 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xAB4E | 4324 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.