Malware Insights
The PDF file contains a critical heuristic firing for a malicious redirector link, pointing to 'https://ttraff.cc/wix?keyword=student+guide+to+the+frog+dissection'. This URL is likely part of a phishing or malware distribution scheme. The file also exhibits characteristics of a link farm, with numerous external PDF links, suggesting an attempt to manipulate search engine results or distribute content through a network of linked documents. No scripts were extracted, but the presence of the malicious redirector is sufficient evidence of malicious intent.
Heuristics 3
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://ttraff.cc/wix?keyword=student+guide+to+the+frog+dissection
- https://static.usrfiles.com/ugd/b8c837_e539bbfe78914fbab4a9c90ac0b02868.pdf
- https://static.usrfiles.com/ugd/b8c837_4646e54ddc0649e38460ee08418bcde8.pdf
- https://static.usrfiles.com/ugd/83f04e_805ac061bfd64863ab18437dd8e41a21.pdf
- https://static.usrfiles.com/ugd/a467d2_196a5e2a8db94a8abe0e2f93a68e6459.pdf
- https://static.usrfiles.com/ugd/b8c837_f1c71de0f6774347905c42513b28b317.pdf
- https://static.usrfiles.com/ugd/078c79_578bc39dac8e48f4808765445f4c6b58.pdf
- https://static.usrfiles.com/ugd/f80014_c08dc273d0eb4aa29f6d8ed5992920c7.pdf
- https://static.usrfiles.com/ugd/c4ccc4_01af0b16759f4e0e967cb02212f781a2.pdf
- https://static.usrfiles.com/ugd/b8c837_f50b206fa1be453daddc425694672898.pdf
- https://cdn.shopify.com/s/files/1/0433/9594/0519/files/97513494885.pdf
- https://cdn.shopify.com/s/files/1/0438/3775/1453/files/encyclopedia_download_free.pdf
- https://cdn.shopify.com/s/files/1/0436/7450/1285/files/zotiwubizozozomepuzupo.pdf
- https://cdn.shopify.com/s/files/1/0453/6093/9163/files/sotegumapelanazagot.pdf
- https://cdn.shopify.com/s/files/1/0436/2780/6883/files/90560098096.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00006444.bind7050c62a0234982c0fafbf4ab1fc8c65758502ffbd34af40069ab85d41c5fca |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x6444 | 5144 bytes |
font_01_sfnt_off000075bc.bin47e1ad01dd3e16d632ba71c4ac94a5af8ddb9340bbc199982fc3b4250e7cfc46 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x75BC | 10036 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.