MALICIOUS
152
Risk Score
Malware Insights
MITRE ATT&CK
T1566.002 Spearphishing Attachment
T1204.002 Malicious Link
The PDF contains a large number of embedded links, many of which point to suspicious domains and are flagged as part of a link farm. One prominent URL, 'https://ttraff.club/wix?keyword=overview+clues+to+earth%2527s+past+answer+key', is identified as a malicious redirector. The document body, though heavily obfuscated, contains similar URLs, suggesting a coordinated effort to direct users to potentially harmful content.
Machine Learning
- Nyx PDF Classifier malicious score 1.0000
Heuristics 4
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://ttraff.club/wix?keyword=overview+clues+to+earth%2527s+past+answer+key
- http://files.choestoebaptistchurch.org/uploads/1/3/1/6/131607163/mofojajoku.pdf
- http://files.bedbugsremoval.com.au/uploads/1/3/2/3/132302926/favuraxoduzut.pdf
- http://rarujinaf.objectpages.com/uploads/1/3/1/4/131453872/jogadug_falerun_visimuleve_fibawesazu.pdf
- http://mefozaneb.litturi-photography.com/uploads/1/3/2/7/132710567/rijusiwub.pdf
- http://files.knightsautowash.com/uploads/1/3/0/7/130776386/8500239.pdf
- https://cdn.shopify.com/s/files/1/0431/7600/1704/files/34440505086.pdf
- https://cdn.shopify.com/s/files/1/0434/8814/9654/files/javarukaxalaveku.pdf
- https://f092bec7-e105-4e44-bf20-fd1eeb3e23a5.filesusr.com/ugd/3ed902_2a3d1838a4b74895b3e579fa5df878be.pdf?index=true
- https://4ae5a20e-6764-4ec4-8b01-9c7529a94cc3.filesusr.com/ugd/80bfa9_4245df53cec44fad86b53369f6b08c02.pdf?index=true
- https://b5b3e5c8-5807-4c85-8f27-8b7d0e237dac.filesusr.com/ugd/0b46e6_fad31ae4cc0142ae94257b70600cef2c.pdf?index=true
- https://4a81779e-23ba-4f1c-a811-b8f781134158.filesusr.com/ugd/48bf55_020351a9c4534ce28007d6160f1757ac.pdf?index=true
- https://d2d7aba7-83de-475f-93cc-e9bdccb07b1c.filesusr.com/ugd/0b46e6_3050af66f4c549eb94a2d7c847e203c3.pdf?index=true
- https://d33ba8b3-a666-4303-9248-0610a85f1f8e.filesusr.com/ugd/2994dd_d1cc7326e39349f4938ea291edcefcf0.pdf?index=true
- https://c8fbccee-eb0d-48f7-8803-1b3fd3406348.filesusr.com/ugd/565485_5c3bc1dd35e04de8a109a1218113982e.pdf?index=true
- https://bd9b38d7-755e-4204-9950-d5a349025850.filesusr.com/ugd/b90ba1_659f2b9359ab4388bd4ab538be37f80c.pdf?index=true
- https://dd894573-7770-4b88-9555-d0d04f311cde.filesusr.com/ugd/430cb2_e449efa94ff84538be7efa76e6801277.pdf?index=true
- https://19867a25-dc77-425f-97a9-ab14bda4a674.filesusr.com/ugd/9df9d6_d200703251a848a6b97a32655d8de01f.pdf?index=true
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00008a87.bin346dd93939193190cde96645f66aec3542cdfedef345a642fa86f1643b77b00e |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x8A87 | 5400 bytes |
font_01_sfnt_off00009d00.bin8d7dc922b448f0300acb03b34be37ff3bcf8685abf004096bf763fc3f903cbfe |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x9D00 | 10072 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.