MALICIOUS
120
Risk Score
Malware Insights
MITRE ATT&CK
T1566.002 Spearphishing Attachment
T1059.001 PowerShell
The PDF file contains a large number of embedded links, many of which point to suspicious domains and are likely part of a link farm designed for SEO manipulation. One critical heuristic identified a link to known malicious redirector infrastructure. The document body, though partially corrupted, contains text related to a 'leveling guide' and the URL https://ttraff.club/wix?keyword=leveling+guide+85-90, suggesting a lure to a malicious site. No scripts were extracted from this sample.
Heuristics 3
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://ttraff.club/wix?keyword=leveling+guide+85-90
- http://jagitavus.christopherwongld.com/uploads/1/3/2/6/132681602/bivajesosubidog-lisuxofazumo-zemiwena.pdf
- http://files.designforequity.org/uploads/1/3/0/9/130968921/7c74512e.pdf
- http://xozala.midwestaaoe.com/uploads/1/3/2/6/132681824/pojifufinu.pdf
- http://files.crystal-river-healing.com/uploads/1/3/0/8/130813982/9a877e15c77612.pdf
- http://lowagojo.friendsofraymondjames.org/uploads/1/3/2/8/132815296/buvat_xateve_dulile.pdf
- https://6f775e63-0572-4a21-9a42-1013e3d440fc.filesusr.com/ugd/3835dd_5689e07dca3347d1b179bca56342b994.pdf?index=true
- https://24a0b585-5f16-462a-9400-1b988becb3d8.filesusr.com/ugd/b42fd6_88138ae4ddc24b6e81113d3f0fae483e.pdf?index=true
- https://3d2736fd-dcc4-46bf-8592-c8c90f271b97.filesusr.com/ugd/738632_b32bad23104e4cbf96b8a6af9899eeb4.pdf?index=true
- https://56c137de-7c20-4aec-8fe8-38cfba95a2cd.filesusr.com/ugd/70e7d4_b64eef06761d4675b88ae32fb58b775a.pdf?index=true
- https://0c005061-34c5-455b-8ef0-e76b8fa017cc.filesusr.com/ugd/3f80ec_2dd5bc4a5f5049c78e41833b3c5272b9.pdf?index=true
- https://ee4bb60c-ddc5-40f5-8ece-1892d4b9bb55.filesusr.com/ugd/fd4c29_671a14a98c3746f5a1d8cf97cc399a0b.pdf?index=true
- https://2164f6d4-5266-4f3f-a89e-532e762ae8d0.filesusr.com/ugd/e3c460_4543dd82f94e40e3b5b0abe8c786f05b.pdf?index=true
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00006642.binc46f1815d923f9dd8916f94a2a070e03ce0fa3c7de21a4f5a67b7e55f8ef767e |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x6642 | 5156 bytes |
font_01_sfnt_off00007803.bin6b187f01b638d8db0d1ca26ce3e35bb09a7c1f57c8243bf6d8c90000ba6f6400 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x7803 | 10528 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.