MALICIOUS
120
Risk Score
Malware Insights
MITRE ATT&CK
T1566.002 Spearphishing Attachment
T1059.001 PowerShell
The PDF file contains a large number of embedded links, many of which point to static.usrfiles.com, but one critical link directs to a known malicious redirector at ttraff.ru. The document body, though heavily obfuscated, contains the same keywords as the malicious URL, suggesting a lure. The presence of numerous links to external PDFs indicates a link farm strategy, likely to improve search engine ranking and distribute malicious content. No scripts were extracted, but the primary attack vector appears to be the malicious URL.
Heuristics 3
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://ttraff.ru/wix?keyword=zero+first+and+second+conditional+exercises+2+eso
- https://static.usrfiles.com/ugd/a474dd_7fc73b8cfec04177b31784e372ec3cf2.pdf
- https://static.usrfiles.com/ugd/b8c837_97f6b10ce3454c0db85ad522e47a3c50.pdf
- https://static.usrfiles.com/ugd/3aee12_66720f02a6b848dd8c9cb092eb772052.pdf
- https://static.usrfiles.com/ugd/b8c837_86313ea7cb184f0ea31e33c1249df491.pdf
- https://cdn.shopify.com/s/files/1/0432/3511/5175/files/sqlite_for_windows_8.pdf
- https://cdn.shopify.com/s/files/1/0435/5273/5391/files/kindle_app_for_ipad_won_t.pdf
- https://cdn.shopify.com/s/files/1/0436/1191/4403/files/36608635171.pdf
- https://cdn.shopify.com/s/files/1/0463/2569/4619/files/dojoziboduwatebo.pdf
- https://static.usrfiles.com/ugd/b8c837_3f66f03741b147d385a27749e24f2d19.pdf
- https://static.usrfiles.com/ugd/05900a_8af76dc7a6f8459ca532ae7f2f38d3c0.pdf
- https://static.usrfiles.com/ugd/b8c837_10c165ccca2648dea3ce9a573b0be4fb.pdf
- https://static.usrfiles.com/ugd/f0e51d_c86779a1111d49d1a3a644d98066b722.pdf
- https://static.usrfiles.com/ugd/b8c837_a59e9e6d1281412fb81c0eaa903cf197.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off000043f5.bin5db55d2a2f84d173f5814be5fb56d8a335edd9071b9846090eb2633baa6fa0d0 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x43F5 | 5172 bytes |
font_01_sfnt_off00005598.bina39c84b54bb948fb8227b79c670844ff39c62f28c7d58211993f0b208e5b5cbd |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x5598 | 10176 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.