MALICIOUS
120
Risk Score
Malware Insights
MITRE ATT&CK
T1566.002 Spearphishing Attachment
T1059.001 PowerShell
The PDF contains a critical heuristic firing for a malicious redirector link pointing to 'ttraff.com'. The document body, though heavily obfuscated, contains the text 'Buddhist holy book tripitaka pdf' and the malicious URL, suggesting a lure to trick users into clicking the link. The PDF also contains a large number of external links, many hosted on 'cdn.shopify.com', which is flagged as a link farm. The primary malicious IOC is the redirector URL.
Heuristics 3
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://ttraff.com/pify?keyword=buddhist+holy+book+tripitaka+pdf
- http://files.eatclaylove.com/uploads/1/3/0/9/130969825/fogatusolipex-xuzorepafovoni-rupizolik.pdf
- http://files.amirajnorris.com/uploads/1/3/1/4/131438541/dokirabizevepo.pdf
- http://lirebej.oilmyworld.net/uploads/1/3/0/7/130776644/kubotilewijeval_bodoluzegimesi_fanujabujeka_jetaxuxuxovasuz.pdf
- https://cdn.shopify.com/s/files/1/0430/7845/1351/files/ontology_computer_science.pdf
- https://cdn.shopify.com/s/files/1/0433/0687/7080/files/fokadexowigexavutezirero.pdf
- https://cdn.shopify.com/s/files/1/0428/8148/2919/files/zozirejek.pdf
- https://cdn.shopify.com/s/files/1/0433/0687/7080/files/niroduwo.pdf
- https://cdn.shopify.com/s/files/1/0432/1984/5278/files/8264963821.pdf
- https://cdn.shopify.com/s/files/1/0434/4587/8950/files/68913676467.pdf
- https://cdn.shopify.com/s/files/1/0431/9074/7293/files/91077562362.pdf
- https://cdn.shopify.com/s/files/1/0431/8255/5300/files/81375793432.pdf
- https://cdn.shopify.com/s/files/1/0431/1236/6229/files/40932542539.pdf
- https://cdn.shopify.com/s/files/1/0440/4363/2805/files/walmart_cashier_application.pdf
- https://cdn.shopify.com/s/files/1/0430/6341/0839/files/bozoxoxivijawexi.pdf
- https://cdn.shopify.com/s/files/1/0432/5546/4104/files/mapinowevudamaxomu.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Extracted artifacts 11
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000a483.bin3c2648050810f586ce0102a5b24939c302035e1b5b61534558fe40907ee7af16 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xA483 | 7380 bytes |
font_01_sfnt_off0000bdba.bin622be3f7f53fa9fa28691a9a43c054807adb29ee27bf330020449a8bf67fd410 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xBDBA | 5144 bytes |
font_02_sfnt_off0000cf36.bin1060bf2d4e86c9af3de6f9f05a0006ee37e218874003c9482b55f88de196339f |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xCF36 | 2932 bytes |
font_03_sfnt_off0000db01.binbf2dc291edd9bd913f080d6ead5f729c668e8c33b84194e09990e3090c3a8fd9 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xDB01 | 4496 bytes |
font_04_sfnt_off0000e981.binbf75df115c132fe68d1d51022058d8d27e1572d1272ed0116f6ac83685479fa0 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xE981 | 5324 bytes |
font_05_sfnt_off0000f8ed.binfbc23f5b4c8ec8b4a522772817c8ab8873577ed758308134d29a2da86dbacc6c |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xF8ED | 5156 bytes |
font_06_sfnt_off00010ad0.binf25071f9398ddd7c254128f0c17a6bffae17195d9f3c4aa54d4c1e35e92e259d |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x10AD0 | 7268 bytes |
font_07_sfnt_off00011e6c.bine87407d04292281d8aa976dadcb7a0cd886c33b6b42349589ba4b888dae5faed |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x11E6C | 13596 bytes |
font_08_sfnt_off0001479b.bin05d2457133b820fa77aa358e30e9acfbad3f04c46ced9a37296d9311117db176 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x1479B | 4324 bytes |
font_09_sfnt_off0001559e.bine8829d928545eaa3710c314671794eaff13e12794608f569984ce0199d6352a4 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x1559E | 2836 bytes |
font_10_sfnt_off00016134.bin79487ce31b2698095fd0dd722bb60855664500526b63603cf1403e0391ae5408 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x16134 | 4892 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.