MALICIOUS
120
Risk Score
Malware Insights
MITRE ATT&CK
T1566.002 Spearphishing Attachment
T1204.002 Malicious Link
The PDF file contains a heuristic firing for a malicious redirector link, which is also present in the document body. This link, 'https://ttraff.cc/wix?keyword=forscore+user+guide', is likely intended to lead the user to a malicious site. The file also exhibits characteristics of a PDF link farm, with numerous embedded links to external PDFs, suggesting an attempt to manipulate search engine results or distribute further malicious content.
Heuristics 3
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://ttraff.cc/wix?keyword=forscore+user+guide
- https://static.usrfiles.com/ugd/5bb01c_5975e8a292ed437fafc6484cd5dcf53d.pdf
- https://static.usrfiles.com/ugd/3e0cb9_eefa00c051eb4964999ee77204b3559e.pdf
- https://static.usrfiles.com/ugd/c1de29_0eb2c0b0bdf8400aa42ce3d3491cb745.pdf
- https://cdn.shopify.com/s/files/1/0437/6838/1591/files/topamabis.pdf
- https://cdn.shopify.com/s/files/1/0432/5058/1662/files/80247544978.pdf
- https://static.usrfiles.com/ugd/269bb8_9ee08641534c481c98f4bd9eed5a4114.pdf
- https://static.usrfiles.com/ugd/1c8c6c_8964d1feaa4b44d6a33514b6bba3c3f3.pdf
- https://static.usrfiles.com/ugd/9c43ec_883f9d6ff29f484691d08543bf73f549.pdf
- https://static.usrfiles.com/ugd/69695d_583023f260cd42f7a2c2379db7394661.pdf
- https://static.usrfiles.com/ugd/b8c837_d1945de8c2834e48916708e4aeb9e4e6.pdf
- https://static.usrfiles.com/ugd/b8c837_84be0dd07e9441c8ba4c6d17d03b8329.pdf
- https://static.usrfiles.com/ugd/de02f3_7817aa6874994cd081b952e7d9e42dc6.pdf
- https://static.usrfiles.com/ugd/430cb2_51b1ebddf25c427da8e9d473405405e3.pdf
- https://static.usrfiles.com/ugd/1f2646_9474d6a151ca4bf8bfe466b974212ed8.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00006ba8.bin3eac4724bb55475c63d66650607b1c4b20870e8cfc6d9ede376b41b90e987a04 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x6BA8 | 4820 bytes |
font_01_sfnt_off00007c19.bincb95be17bb712aa8bf7d708b1c13890c06c61fd862ebb273442bb806bc45f680 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x7C19 | 10136 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.