MALICIOUS
152
Risk Score
Malware Insights
MITRE ATT&CK
T1566.002 Spearphishing Attachment
T1204.002 Malicious Link
T1059.001 PowerShell
This PDF document is designed to appear as a lab report answer key, but it contains a malicious redirector link. The document leverages a link farm with numerous embedded URLs, ultimately pointing to a redirector at 'ttraff.link'. This infrastructure is used to obscure the final malicious destination, likely for phishing or malware distribution.
Machine Learning
- Nyx PDF Classifier malicious score 1.0000
Heuristics 4
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://ttraff.link/wix?keyword=cellular+respiration+and+fermentation+lab+report+answers
- https://537deb8d-1715-4b5f-84b1-451b89318887.filesusr.com/ugd/80bfa9_28538a621f8547d48c1443d8f46e126b.pdf?index=true
- https://03fedd0a-9f62-4aae-9200-180952dfcf0b.filesusr.com/ugd/ce4b7c_46e6dd20edf94cf4860a096198f142d4.pdf?index=true
- https://1d2f6abd-f036-457f-a920-ae901a46d81d.filesusr.com/ugd/8ba634_ce8d22c56d20412184bba7b4d141fc16.pdf?index=true
- https://a329d061-d875-47ea-a852-be16dedb270a.filesusr.com/ugd/9c0842_76b758b4eff5422f94dbe1740b94b45b.pdf?index=true
- https://4c8b8ff7-e9a3-4002-b45f-3cf924d66e58.filesusr.com/ugd/bbd3cf_167369c8cead45cb86ecdb6a354fd3ee.pdf?index=true
- https://1bf10450-84e3-4c07-a57c-8a5c57bc7457.filesusr.com/ugd/622218_43205bb1cfae404e808dc14fb35ce4fd.pdf?index=true
- https://98c8f798-d4d5-4ed6-a4f4-040ee5bad0e8.filesusr.com/ugd/9117e0_458718c3079b4d9abb9216dcf6ef3986.pdf?index=true
- https://7eda763f-e846-4c1b-ba07-d0aa075229d0.filesusr.com/ugd/48f461_5dceb56764f94043a7eb9e83f4182939.pdf?index=true
- https://709d829e-63e5-4043-8a0a-86a3290bb87f.filesusr.com/ugd/891219_aa9d5e88037445518bcc58c2aecc8360.pdf?index=true
- https://353e034b-413c-43e2-a202-cae958d67769.filesusr.com/ugd/3db607_9b063dd16c4f471997119e2281e2c7f9.pdf?index=true
- https://ad560392-fcdd-4cae-af3a-b5e1ae3cbcb4.filesusr.com/ugd/66f3f9_0aca77a1b3e34ea3aa502dfa0c1b46fe.pdf?index=true
- https://cdn.shopify.com/s/files/1/0431/2521/1296/files/44921789712.pdf
- https://cdn.shopify.com/s/files/1/0437/1991/7717/files/xojubob.pdf
- https://cdn.shopify.com/s/files/1/0429/3751/6191/files/descargar_ccleaner_pro_apk_2018.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- https://ad560392-fcdd-4cae-af3a-b5e1ae3cbcb4.filesusr.com/ugd/66f3f9_0aca77a1b3e34ea3aa502dfa0c1b46fe
Extracted artifacts 3
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off000068ea.binc47328b99d1a8106722297ddf3976446a0c29354b3be907203f77db8ad888c37 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x68EA | 1684 bytes |
font_01_sfnt_off0000714f.bin0e943286e685e267e9eaa7b47533f64a4659c6f9c458856e5adeef7877ad61c2 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x714F | 5324 bytes |
font_02_sfnt_off0000835f.bin252575f96906c52e31a231d2a938a9eb794bda545d34c31835cac964eb621368 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x835F | 11820 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.