MALICIOUS
120
Risk Score
Malware Insights
MITRE ATT&CK
T1566.002 Spearphishing Attachment
T1059.001 PowerShell
The PDF file contains a critical heuristic firing indicating it links to a known malicious redirector. The document body, though heavily obfuscated, contains the string "Java tutorial apk free" and the malicious URL "https://ttraff.com/wix?keyword=java+tutorial+apk+free", suggesting a lure to a malicious site. The presence of numerous other PDF links, many pointing to Shopify, indicates a potential link farm or SEO manipulation tactic to distribute the malicious content.
Heuristics 3
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://ttraff.com/wix?keyword=java+tutorial+apk+free
- https://cdn.shopify.com/s/files/1/0430/4188/2265/files/fobia_social_en_nios.pdf
- https://cdn.shopify.com/s/files/1/0435/4693/5460/files/rujumebetekosowagobolarol.pdf
- https://cdn.shopify.com/s/files/1/0431/3494/3389/files/laleniwezir.pdf
- https://cdn.shopify.com/s/files/1/0461/7489/6281/files/fitutozofarifesubo.pdf
- https://cdn.shopify.com/s/files/1/0434/2287/5797/files/story_elements_worksheet_grade_2.pdf
- https://cdn.shopify.com/s/files/1/0430/4178/3959/files/jspdf_autotable_column_width_auto.pdf
- https://cdn.shopify.com/s/files/1/0432/8918/2376/files/wopebeguruludi.pdf
- https://cdn.shopify.com/s/files/1/0434/3542/5944/files/pugiwukelerafapugosomepo.pdf
- https://cdn.shopify.com/s/files/1/0438/0111/6833/files/cambridge_practice_test_for_pet.pdf
- https://cdn.shopify.com/s/files/1/0429/5534/1977/files/21418351882.pdf
- https://cdn.shopify.com/s/files/1/0437/6992/1688/files/kaspersky_activation_code.pdf
- https://cdn.shopify.com/s/files/1/0433/7254/4150/files/arabya_rajani_bengali.pdf
- https://cdn.shopify.com/s/files/1/0427/9838/3260/files/abstract_algebra_an_introduction.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Extracted artifacts 3
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off000102e9.bin354cec244180f0aa6c00eb76869ab3d92ba3dade5caffaed34412e4a04008e11 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x102E9 | 4828 bytes |
font_01_sfnt_off00011372.binf101fc3023143cbc24e87e2583c027b8b5ab7dfb9504abb66ff99af634bcdac9 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x11372 | 1804 bytes |
font_02_sfnt_off00011c4d.bin6a92a57510208bbdadd8025e8e23dfa49aac1fbac3fc791033a5b74bf8ef57fa |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x11C4D | 15956 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.