MALICIOUS
120
Risk Score
Malware Insights
MITRE ATT&CK
T1566.002 Spearphishing Attachment
T1204.002 Malicious Link
The PDF file contains a critical heuristic firing for a malicious redirector link, pointing to 'https://ttraff.link/wix?keyword=arjuna+arjuna+hd+video+songs'. This URL is presented within the document body, disguised with keywords likely intended for SEO poisoning or clickbait. The file also exhibits characteristics of a PDF link farm, with numerous embedded URLs, many pointing to static.usrfiles.com. The primary malicious URL is the most significant IOC, suggesting a phishing or redirection attempt.
Heuristics 3
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://ttraff.link/wix?keyword=arjuna+arjuna+hd+video+songs
- https://static.usrfiles.com/ugd/cd79e3_0519c1be64a848edaa63aaf98c710972.pdf
- https://static.usrfiles.com/ugd/9fc8c3_60a193318c854b47bb9196855b07654d.pdf
- https://static.usrfiles.com/ugd/d4579c_228004df66bb4a9db3ef5dcfe9263476.pdf
- https://static.usrfiles.com/ugd/f91cf1_449ff5d28b0b4845b68aa614a5968da6.pdf
- https://static.usrfiles.com/ugd/113e89_71fbed37c0ef400ba952db1e73dd3ce6.pdf
- https://cdn.shopify.com/s/files/1/0431/8789/6480/files/bulitovasimus.pdf
- https://cdn.shopify.com/s/files/1/0431/8085/1364/files/antivirus_gratuito_para_android_tablet.pdf
- https://cdn.shopify.com/s/files/1/0469/0513/1170/files/reporters_today_show.pdf
- https://cdn.shopify.com/s/files/1/0430/0495/2735/files/attendance_management_system_project_in_android_documentation.pdf
- https://cdn.shopify.com/s/files/1/0449/9036/5864/files/batman_game_gba.pdf
- https://cdn.shopify.com/s/files/1/0428/4180/0860/files/93517559132.pdf
- https://static.usrfiles.com/ugd/a771bd_fba7f595752245afb31986183227bfaf.pdf
- https://static.usrfiles.com/ugd/9219f8_f0fcaeb2e5564c5d89cd46c4a0ed9e5f.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00005514.bin485835349dfd7b2a9d64b7390cda367916cd45555aa3369e6767d2017e226e69 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x5514 | 5180 bytes |
font_01_sfnt_off000066ba.binbf5bac185305e3dcb66aa62f388c7591ea87f71d7cc8a766dc9d2c082db8ceca |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x66BA | 10532 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.