MALICIOUS
120
Risk Score
Malware Insights
MITRE ATT&CK
T1566.002 Spearphishing Attachment
T1059.001 PowerShell
The PDF file contains a heuristic firing for a malicious redirector link, specifically pointing to 'https://ttraff.com/wix?keyword=soprano+sax+range'. This indicates an attempt to direct users to a potentially harmful website. The document body, though heavily obfuscated, also contains this URL, reinforcing its presence. The file also exhibits characteristics of a link farm, with numerous embedded URLs, suggesting a broader campaign to distribute malicious content.
Heuristics 3
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://ttraff.com/wix?keyword=soprano+sax+range
- https://static.usrfiles.com/ugd/b8c837_249d48c19f4e44d79ddff24efe81c97d.pdf
- https://static.usrfiles.com/ugd/accd1f_b521f4dbda924ad58a26d35547163ca8.pdf
- https://static.usrfiles.com/ugd/374ce0_fafdecd257184fb0bf9467d63c118a2d.pdf
- https://cdn.shopify.com/s/files/1/0432/6362/3330/files/guia_consejo_tecnico_cuarta_sesion_2.pdf
- https://cdn.shopify.com/s/files/1/0432/3937/5012/files/53552924682.pdf
- https://cdn.shopify.com/s/files/1/0428/1873/2191/files/22901501907.pdf
- https://cdn.shopify.com/s/files/1/0438/1189/7504/files/16328151183.pdf
- https://cdn.shopify.com/s/files/1/0463/1232/5285/files/violence_jack_manga_completo.pdf
- https://cdn.shopify.com/s/files/1/0446/8968/6681/files/kanoxujaluba.pdf
- https://static.usrfiles.com/ugd/bf650e_877b367b138b488e81e322c9d19a2878.pdf
- https://static.usrfiles.com/ugd/a107db_4d8684470aef42fd9f74eb91f3beff6f.pdf
- https://static.usrfiles.com/ugd/b8c837_b17ce93c91c3442898b4e0ee7fd53639.pdf
- https://static.usrfiles.com/ugd/529dbf_b438c406a6404bbdba2ab02ca5c99ca8.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Extracted artifacts 3
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off000098f8.bin63acaa40b3ff3a6da72b28eeb59674d9647e21670d98fccd427d0af91b569b76 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x98F8 | 5128 bytes |
font_01_sfnt_off0000aa75.binc1bf432a375702e859eefeceb1ef97ae5156b6e8a3b95680de909d0de04033d6 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xAA75 | 10028 bytes |
font_02_sfnt_off0000ccfd.bin46d9b83afd797048ab251ddfc9ca9a6db44f3280724c231f6a80a061bcc6fc12 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xCCFD | 16120 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.