MALICIOUS
150
Risk Score
Malware Insights
MITRE ATT&CK
T1566.002 Spearphishing Attachment
T1204.002 Malicious Link
The PDF contains a significant number of embedded links, many of which point to redirectors or link farms designed for SEO manipulation. One critical heuristic identified a link to known malicious redirector infrastructure at https://ttraff.ru/wb?keyword=toefl%20paper%20based%20test%20pdf. The ML classifier also strongly indicated maliciousness. No scripts were extracted from this sample.
Machine Learning
- Nyx PDF Classifier malicious score 1.0000
Heuristics 3
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://ttraff.ru/wb?keyword=toefl%20paper%20based%20test%20pdf
- http://files.babylonboatworks.com/uploads/1/3/2/7/132740405/8615662.pdf
- http://files.nikosmarinos.com/uploads/1/3/1/4/131437615/21c52beae6c2e9.pdf
- http://files.doctorsparkanimalhospital.com/uploads/1/3/0/8/130813645/4469518.pdf
- http://nisowa.rubyrosecowgirlclothes.com/uploads/1/3/1/6/131636655/nizibafolufokudefek.pdf
- http://files.imagesbylk.com/uploads/1/3/1/0/131069819/dulaviwiketebawir.pdf
- http://files.forouryouthfoundation.org/uploads/1/3/2/8/132815791/7997533.pdf
- http://files.conscious-pictures.com/uploads/1/3/1/8/131871823/5215534.pdf
- http://files.christykiespertpianostudio.com/uploads/1/3/0/8/130873804/jinudakinex.pdf
- https://static.usrfiles.com/ugd/b8c837_a0f184f9bf4349768a38ab38577e1672.pdf
- https://static.usrfiles.com/ugd/cbe7f7_5621106d083d48bd94fb84eceee9d823.pdf
- https://static.usrfiles.com/ugd/8e66a5_990281a16f094f3ca2d10a04928ceb1d.pdf
- https://static.usrfiles.com/ugd/0dd040_49dad87f72fa4435829b5ad77d7badde.pdf
- https://static.usrfiles.com/ugd/1be480_9c3c751c2ec940678fc2e2c4c3c05ba5.pdf
- https://static.usrfiles.com/ugd/35dc59_258b084b377c4161b326524d6c8e8a92.pdf
- https://static.usrfiles.com/ugd/2994dd_de0faa0455314114b2ff7453ed7e558b.pdf
- https://static.usrfiles.com/ugd/003b86_ecf162d519934935966d91b3994b4f27.pdf
- https://static.usrfiles.com/ugd/a382ee_6d871b3505e646bc84fe01d7ff446978.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00006d34.bin44ed341f9121ce5e4cc8639f408d7b8995091155c62af0dd5ed3b9d283951a6c |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x6D34 | 5124 bytes |
font_01_sfnt_off00007ea1.bin51f8ebf9a82d7c020c0e31b7a4cdea71d7f7a0f551b5dfe1fb6bd28820a21fae |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x7EA1 | 10448 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.