MALICIOUS
120
Risk Score
Malware Insights
MITRE ATT&CK
T1566.002 Spearphishing Attachment
T1059.001 PowerShell
The PDF contains a link to a known malicious redirector, ttraff.club, which is likely used to funnel users to phishing sites or malware. The document also exhibits characteristics of a PDF link farm, embedding numerous links to external PDFs, many hosted on static.usrfiles.com. This suggests a campaign focused on driving traffic through deceptive links, potentially for SEO manipulation or to distribute further payloads.
Heuristics 3
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://ttraff.club/wix?keyword=project+implementation+timeline+template
- https://static.usrfiles.com/ugd/87ad98_b26213222d6341628870fa50731a9f68.pdf
- https://static.usrfiles.com/ugd/824332_406ef99f652d41c5850431e8b65ea0dd.pdf
- https://static.usrfiles.com/ugd/3b7182_077a5a5cd11a4eb4a540bff3c23016de.pdf
- https://static.usrfiles.com/ugd/430cb2_da441f91706447abacf46304d69829ea.pdf
- https://static.usrfiles.com/ugd/205ae4_c1d6e216adcc48b58e1dacae860b5749.pdf
- https://static.usrfiles.com/ugd/b8c837_55e7767d0cdd483a97363b0b4daa3e13.pdf
- https://static.usrfiles.com/ugd/64db51_9a8278680cce4c45bf3fd073ef34c6de.pdf
- https://static.usrfiles.com/ugd/238140_816ab685d7b6450abb97d49e270934fb.pdf
- https://static.usrfiles.com/ugd/b7306e_c2363eefb0f348569e4f202f69e39203.pdf
- https://static.usrfiles.com/ugd/bfbc46_db40ca4bbf65493c9e35747ca2344b56.pdf
- https://static.usrfiles.com/ugd/b48b60_e2419ad5ec1445e4b4b9814e984ec1e2.pdf
- https://cdn.shopify.com/s/files/1/0432/1899/3320/files/79857642409.pdf
- https://cdn.shopify.com/s/files/1/0435/1574/0314/files/palirinuzuvot.pdf
- https://cdn.shopify.com/s/files/1/0437/1428/1625/files/55409449409.pdf
- https://cdn.shopify.com/s/files/1/0434/6727/6454/files/79237378650.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off000072b1.binf7f9dccb08606976351d70e3eab9f5312ebdee9a9a594051ee8b1d15a8fe5725 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x72B1 | 4976 bytes |
font_01_sfnt_off00008388.bin6f46eeb320f27638f97ca68e9d9c3fc30197d7332eb3a84ee21dcb0c7ff3a615 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x8388 | 10216 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.