MALICIOUS
150
Risk Score
Malware Insights
MITRE ATT&CK
T1566.002 Spearphishing Attachment
T1204.002 Malicious Link
The PDF was flagged for containing a malicious redirector link and a link farm. The primary malicious URL, https://ttraff.com/wix?keyword=elgato+thunderbolt+drive, is likely used to direct users to a phishing or malware distribution site. The document body contains obfuscated text and URLs, further supporting the malicious intent.
Machine Learning
- Nyx PDF Classifier malicious score 1.0000
Heuristics 3
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://ttraff.com/wix?keyword=elgato+thunderbolt+drive
- https://static.usrfiles.com/ugd/b8c837_fe4db59a38d34125ab614f0278647cb5.pdf
- https://static.usrfiles.com/ugd/b8c837_7b096c093df247f990f3b43c424a6382.pdf
- https://static.usrfiles.com/ugd/93c935_f472a504402246aa9d7c205dc1fc0213.pdf
- https://static.usrfiles.com/ugd/b8c837_6f1c2f6205f14e028ffd4927e95572bf.pdf
- https://static.usrfiles.com/ugd/b8c837_bff4998c205e45298f11042c574171aa.pdf
- https://cdn.shopify.com/s/files/1/0431/7901/6349/files/22639744715.pdf
- https://cdn.shopify.com/s/files/1/0438/2759/3376/files/nakivafa.pdf
- https://cdn.shopify.com/s/files/1/0431/2793/1029/files/guia_maestra_para_ceneval_medicina.pdf
- https://cdn.shopify.com/s/files/1/0430/8277/6725/files/89384619755.pdf
- https://static.usrfiles.com/ugd/b8c837_aadcf8a96d084ebfa32b9fbf7c27fc9f.pdf
- https://static.usrfiles.com/ugd/b8c837_fd134cce73ed48b3b14e5292415ba184.pdf
- https://static.usrfiles.com/ugd/856cea_6966a082820f406db26fa505b10d5f88.pdf
- https://static.usrfiles.com/ugd/d5d855_d881c700abb54c83841d9c97c8dadec1.pdf
- https://static.usrfiles.com/ugd/3f80ec_ec25adc2745f45459c6f856055ac18ce.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Extracted artifacts 4
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
stream_005_off00009353.bin174177a05374501f3d6c97c946105287742505b8ed2a3b6add6854fa3dee5329 |
decompressed-pdf-stream | PDF FlateDecoded stream at offset 0x9353 | 17048 bytes |
font_00_sfnt_off00005f3c.binf74ca03aa3ed106fefd23105dd86408d2b5180ba5081e49c9ebb42027f7a8570 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x5F3C | 4948 bytes |
font_01_sfnt_off00007007.bind0e22ab0fa83366a34a4c8f7b149771e0d617fbb64745782febc1227dd025f44 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x7007 | 10220 bytes |
font_03_sfnt_off0000abef.bin9f355172d696dda274cac500966718f112ce76951f19577ac4888987ea6471b2 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xABEF | 4324 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.