MALICIOUS
120
Risk Score
Malware Insights
MITRE ATT&CK
T1566.002 Spearphishing Attachment
T1059.001 PowerShell
The PDF contains a large number of embedded links, many of which point to external PDF files, suggesting a link farm or SEO poisoning tactic. One critical heuristic identified a link to a known malicious redirector, ttraff.cc, which is used to obscure the final destination. The document body contains text related to a financial PDF download, likely a lure to encourage clicks on the malicious links. No scripts were extracted from this sample.
Heuristics 3
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://ttraff.cc/pify?keyword=corporate+finance+theory+and+practice+aswath+damodaran+pdf+download
- http://keluzujow.galwayartacademy.com/uploads/1/3/2/8/132815123/9863949.pdf
- http://files.liffordhealthcentre.com/uploads/1/3/0/8/130874284/5922e3fbe.pdf
- http://files.wanderingwildandfree.com/uploads/1/3/1/1/131164537/xatinepapelawo_xetemisewonit_zamozuw_nidolomug.pdf
- http://files.runforthefallennh.com/uploads/1/3/1/6/131606789/mabiwoxeregofajuxew.pdf
- https://cdn.shopify.com/s/files/1/0435/5850/2563/files/fexegisel.pdf
- https://cdn.shopify.com/s/files/1/0434/8094/0710/files/sublime_text_3_free_license.pdf
- https://cdn.shopify.com/s/files/1/0434/5122/0120/files/causes_of_poverty_in_rural_areas.pdf
- https://cdn.shopify.com/s/files/1/0435/2756/9576/files/annual_report_format.pdf
- https://cdn.shopify.com/s/files/1/0430/4456/9242/files/xanuwuginirifirise.pdf
- https://cdn.shopify.com/s/files/1/0439/5565/0718/files/moxepusanelivizikukadowoj.pdf
- https://cdn.shopify.com/s/files/1/0429/2411/4076/files/d_d_4e.pdf
- https://cdn.shopify.com/s/files/1/0430/9119/8112/files/89934876727.pdf
- https://cdn.shopify.com/s/files/1/0430/4060/4313/files/list_of_adjectives_a_to_z.pdf
- https://cdn.shopify.com/s/files/1/0428/7250/4483/files/56466318791.pdf
- https://cdn.shopify.com/s/files/1/0431/3546/7669/files/guwokeduvudewebosenuwet.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00006ad5.bin34bb365c1446d410f4371afee23a085911f75a7d7d14dd6a4a79c5af73c95064 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x6AD5 | 5492 bytes |
font_01_sfnt_off00007d6f.bina350eb1825ef6ed1aaafb80cd80448993d1acef67aa76f5a6b2bc90b7b5e3d5c |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x7D6F | 10052 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.