MALICIOUS
150
Risk Score
Malware Insights
MITRE ATT&CK
T1566.002 Spearphishing Attachment
T1204.002 Malicious Link
The PDF contains a large number of embedded links, many of which point to Shopify domains, likely as part of a link farm for SEO manipulation. One critical heuristic identified a direct link to a known malicious redirector, ttraff.me, which is presented to the user in the context of a 'Spanish adjectives quiz'. This suggests a social engineering lure to drive traffic to malicious sites. The ML classifier strongly supports the malicious nature of this PDF.
Machine Learning
- Nyx PDF Classifier malicious score 1.0000
Heuristics 3
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://ttraff.me/wix?keyword=spanish+adjectives+quiz
- https://cdn.shopify.com/s/files/1/0427/8288/4006/files/free_cover_letter_template_reed._co._uk.pdf
- https://cdn.shopify.com/s/files/1/0430/8828/1761/files/cbema_full_form.pdf
- https://cdn.shopify.com/s/files/1/0434/0262/5178/files/sakiguvi.pdf
- https://b88110c2-8699-4f2d-991b-31b020a63020.filesusr.com/ugd/b463f2_c5c502bd1bd94f4d97aec3fa37f4af58.pdf?index=true
- https://6e2798e3-00fb-4bfd-8fb6-3f01a7adb61d.filesusr.com/ugd/6290de_8819ec778b4b4a01ac469fdc080076ba.pdf?index=true
- https://a34c4e6f-ebbd-46ad-89b4-eea9a34d52da.filesusr.com/ugd/26481d_407564f9ffbb43d8ad9e3fe25ea6ae41.pdf?index=true
- https://0d801e41-584d-447d-8a86-7231a2f10f95.filesusr.com/ugd/a91264_c455310d8f634fb98a8c85d26b6f11c6.pdf?index=true
- https://d17ee275-5f24-44cc-bb1f-b8d0b516a156.filesusr.com/ugd/0d089b_0175988fc47d45d98533cae0f7fa2234.pdf?index=true
- https://3164eff4-cdab-440e-ac72-b4ed17006d13.filesusr.com/ugd/65e777_6df7e8163ffa45f798c3c96d80703a9a.pdf?index=true
- https://d17ecdee-efd3-451c-927f-27f62d9c090c.filesusr.com/ugd/33a2e4_32be1205d57744bcaeec385616db8174.pdf?index=true
- https://e26eb81b-f27c-49f7-81f2-8b5149a472ab.filesusr.com/ugd/ed8107_94131d885ca94c55b08bb5841573d8ec.pdf?index=true
- https://a1d474f5-aa34-4330-9c45-4e6659dce1c8.filesusr.com/ugd/3c2969_3c288ef57dd4422d87330d4be3daac3a.pdf?index=true
- https://605db03f-8e99-4bb1-a84c-bdaec63a1dfe.filesusr.com/ugd/384ea4_ff096f2566144a639d3b7ba9aaaf6306.pdf?index=true
- https://db80da30-dc2f-42a5-8b84-6ef3486e30aa.filesusr.com/ugd/594ae5_c708311dbb314606a29f53547db0ef3c.pdf?index=true
- https://04c2d68b-2ae6-4acf-a806-3c63b91c0115.filesusr.com/ugd/405339_47bf1681105c467c81f3333e238cedda.pdf?index=true
- https://d6c6a3a6-a2c1-4884-897f-b04135f32833.filesusr.com/ugd/696117_ea26cb03bfda43bea7fd4b912d7e8ce6.pdf?index=true
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- https://04c2d68b-2ae6-4acf-a806-3c63b91c0115.filesusr.com/ugd/405339_47bf1681105c467c81f3333e
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00004c2c.bin2e25d5d1e7a62847f816cac25fbd20ae5c3cac3e8be73ac5c8fed9f226db485d |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x4C2C | 5448 bytes |
font_01_sfnt_off00005eca.bin14e33a6855d975f6f621ef77887f35c6f4bd6c9bc73f0e9649f31e9d1b31b6c1 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x5ECA | 10324 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.