MALICIOUS
120
Risk Score
Malware Insights
MITRE ATT&CK
T1566.002 Spearphishing Attachment
T1204.002 Malicious Link
The PDF file contains a large number of embedded links, many of which point to a domain known for malicious redirectors. The primary malicious link, disguised as a book title, redirects to 'ttraff.com', which is flagged as a malicious redirector. This suggests a social engineering attack aimed at directing users to harmful content.
Heuristics 3
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://ttraff.com/wix?keyword=myers+social+psychology+12th+edition
- https://static.usrfiles.com/ugd/d2cc1f_9ad820f9ad4542239d15175e1557a50c.pdf
- https://static.usrfiles.com/ugd/b8c837_f65af6a0eb0446aca8d05d12e5db3907.pdf
- https://static.usrfiles.com/ugd/b8c837_ecca9774b4e14120a00f63ae7b267244.pdf
- https://static.usrfiles.com/ugd/b8c837_b4b03884629341b3828cbef30e5734d5.pdf
- https://static.usrfiles.com/ugd/b8c837_aab46271fa4b4c2c8da4aa8f71a5113e.pdf
- https://static.usrfiles.com/ugd/0a0016_4bb887d174fa46989f821c254f54a8f6.pdf
- https://static.usrfiles.com/ugd/07625c_14ce128bafd443568cd6bc24dfb2ee18.pdf
- https://static.usrfiles.com/ugd/b8c837_bb2dab041f91476bbe2e1167e20a9945.pdf
- https://static.usrfiles.com/ugd/79cb75_fba8496241e14db3a77d8430633b436c.pdf
- https://static.usrfiles.com/ugd/63022f_b0342ebe4a884d12a926ffa2ea8ba136.pdf
- https://static.usrfiles.com/ugd/b8c837_132628c7ef364e36a9117a681bf6acdf.pdf
- https://cdn.shopify.com/s/files/1/0432/7918/8118/files/35105862808.pdf
- https://cdn.shopify.com/s/files/1/0432/0378/8959/files/16152176443.pdf
- https://cdn.shopify.com/s/files/1/0434/0069/1862/files/berklee_ear_training.pdf
- https://cdn.shopify.com/s/files/1/0433/0687/7080/files/gimuwuwizarisatin.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Extracted artifacts 3
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000621e.bind5d64390172d838851d07e78f30621f46415bfc9753644638972edb2eb1844ce |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x621E | 5416 bytes |
font_01_sfnt_off00007491.binbdc369cbc2e3ecf920f3404fd2ee62f380657f0729a09d58076784086b9dd012 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x7491 | 10204 bytes |
font_02_sfnt_off00009791.bin9f355172d696dda274cac500966718f112ce76951f19577ac4888987ea6471b2 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x9791 | 4324 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.