MALICIOUS
150
Risk Score
Malware Insights
MITRE ATT&CK
T1566.002 Spearphishing Attachment
T1059.001 PowerShell
The PDF contains a link farm designed to redirect users to malicious infrastructure, as indicated by the PDF_MALICIOUS_REDIRECTOR_LINK and PDF_SEO_LINK_FARM heuristics. The embedded URL https://ttraff.link/pify?keyword=hakata+japan+travel+guide is a primary indicator of this malicious redirection. The ML classifier also strongly flagged this PDF as malicious.
Machine Learning
- Nyx PDF Classifier malicious score 1.0000
Heuristics 3
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://ttraff.link/pify?keyword=hakata+japan+travel+guide
- https://cdn.shopify.com/s/files/1/0433/0687/7080/files/29876283886.pdf
- https://cdn.shopify.com/s/files/1/0432/1637/1867/files/rejulot.pdf
- https://cdn.shopify.com/s/files/1/0431/4012/0733/files/92689274699.pdf
- https://cdn.shopify.com/s/files/1/0463/2690/7035/files/82004449929.pdf
- https://cdn.shopify.com/s/files/1/0431/4693/6482/files/equilbrio_cido-_base_fisiologia.pdf
- https://static.usrfiles.com/ugd/aef5b7_79f649b5c9f2489a9661bf156ddefe9e.pdf
- https://static.usrfiles.com/ugd/15ebe2_e68e4545c0a94fc0a213a9c1a2b78fb0.pdf
- https://static.usrfiles.com/ugd/2eec94_d7320162fd264e45b2bbfad895c713b2.pdf
- https://static.usrfiles.com/ugd/3de8a6_18e261aff61c4378918bc97e1e0ba70e.pdf
- https://static.usrfiles.com/ugd/031dda_ec004d4b1b50439fb6b5966f82d536e8.pdf
- https://static.usrfiles.com/ugd/70a38d_a1abfc0b26ba44d59aa252d489210814.pdf
- https://static.usrfiles.com/ugd/ee9d3f_0da85b8e94f642839c60f8a5221a4663.pdf
- https://static.usrfiles.com/ugd/3f80ec_8c43d6ad9b1542c3b160dd87697d8753.pdf
- https://static.usrfiles.com/ugd/e5cbe5_3ea19c43f2cd474f8b43037d57f75d48.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- https://cdn.shopify.com/s/files/1/0431/4693/6482/files/equilbrio_cido-_bas
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00006171.bin7e5b4718b36dc1ea3206f3b4d56fb7962d905b4f34d18b365cc2ce040bf91892 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x6171 | 5108 bytes |
font_01_sfnt_off000072f0.binc6ee1b3ed20561cf76e0d5605729c13120eef4e11c4c69ee74c549edea116c77 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x72F0 | 10412 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.