Malware Insights
The PDF file contains a large number of embedded links, many of which point to Shopify domains hosting other PDFs, suggesting a link farm or SEO poisoning tactic. One critical heuristic identified a link to a known malicious redirector at 'https://ttraff.com/wix?keyword=anatomy+and+physiology+an+integrative+approach'. The document body, though heavily obfuscated, contains text related to 'Anatomy and physiology an integrative approach' and the redirector URL also contains a similar keyword, indicating a lure to a malicious site disguised as an academic resource.
Heuristics 3
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://ttraff.com/wix?keyword=anatomy+and+physiology+an+integrative+approach
- https://cdn.shopify.com/s/files/1/0445/4006/8004/files/vabamuw.pdf
- https://cdn.shopify.com/s/files/1/0431/7514/9719/files/75932164893.pdf
- https://cdn.shopify.com/s/files/1/0433/3689/2584/files/63391238692.pdf
- https://cdn.shopify.com/s/files/1/0428/7250/4483/files/nedowow.pdf
- https://cdn.shopify.com/s/files/1/0434/9886/4804/files/46916998432.pdf
- https://cdn.shopify.com/s/files/1/0444/4015/8374/files/bible_art_journaling.pdf
- https://cdn.shopify.com/s/files/1/0431/7482/2044/files/sovefegunikesemafifir.pdf
- https://cdn.shopify.com/s/files/1/0432/8521/7436/files/general_aptitude_questions_for_gate_exam.pdf
- https://static.usrfiles.com/ugd/7598fa_cff771cffe84489297973eabe81c464e.pdf
- https://static.usrfiles.com/ugd/4b7290_fb4fc6b00ff44340955f0a0556033ffc.pdf
- https://static.usrfiles.com/ugd/628a76_c7f04fe118e0497496a762a5d4214f8d.pdf
- https://static.usrfiles.com/ugd/b8c837_c22188a4d1874ebfb824319da811562e.pdf
- https://static.usrfiles.com/ugd/5fd5c1_3304e19c28af44cb8df336cfd79f7a3b.pdf
- https://cdn.shopify.com/s/files/1/0433/0687/7080/files/94229011204.pdf
- https://cdn.shopify.com/s/files/1/0434/3437/7372/files/light_novel_translations.pdf
- https://cdn.shopify.com/s/files/1/0450/3171/9070/files/bitevedumimegerakidixa.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00006747.bin762228d737e193c0ded0655f86745bf07db1944558564c76b68fad74750063bf |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x6747 | 5640 bytes |
font_01_sfnt_off00007a4b.bin362b9143da7495b323bf32f0da08f9c4ee463d452b57b4b5c7ae0bf6411a822e |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x7A4B | 10560 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.