Malware Insights
The PDF contains a large number of embedded links, many of which point to a link farm hosted on Shopify. One critical heuristic identified a link to a known malicious redirector, ttraff.cc, which is used to obscure the final destination. The document body, though heavily corrupted, contains the text 'Comprehensive gynecology 7th pdf' and the malicious URL, suggesting a lure to download or view a document. The presence of multiple unknown URLs and the redirector link indicate a malicious intent to direct users to potentially harmful content.
Heuristics 3
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://ttraff.cc/wb?keyword=comprehensive%20gynecology%207th%20pdf
- http://mukafu.esqstp.com/uploads/1/3/0/7/130775639/3f666201ba025db.pdf
- http://tofema.mccormickqwik.com/uploads/1/3/0/8/130814174/birige_lojiparorozafo_rufigom.pdf
- https://cdn.shopify.com/s/files/1/0434/2149/9548/files/incident_reporting_form_kkm.pdf
- https://cdn.shopify.com/s/files/1/0431/5106/5243/files/burijijuribukujari.pdf
- https://cdn.shopify.com/s/files/1/0431/0702/5056/files/lemaf.pdf
- https://cdn.shopify.com/s/files/1/0431/4107/1016/files/40048504628.pdf
- https://cdn.shopify.com/s/files/1/0436/8728/0790/files/constituio_do_estado_de_alagoas_atualizada_2020.pdf
- https://cdn.shopify.com/s/files/1/0437/7955/5486/files/ruzab.pdf
- https://cdn.shopify.com/s/files/1/0431/0063/5290/files/ford_860_tractor.pdf
- https://cdn.shopify.com/s/files/1/0434/1317/6469/files/balutoduvulibizulirex.pdf
- https://cdn.shopify.com/s/files/1/0451/3605/2389/files/variable_frequency_drive_working_principle.pdf
- https://cdn.shopify.com/s/files/1/0447/5823/7333/files/completing_the_square_problems.pdf
- https://cdn.shopify.com/s/files/1/0427/9438/5575/files/automann_suspension_catalogue.pdf
- https://cdn.shopify.com/s/files/1/0435/4818/0634/files/autocad_2020_shortcut_keys_list.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00006582.bin42ab85f7ad7c3ad6c4b8f9579af25d71b0f4175a0c5ec58d87de4e708b934f89 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x6582 | 5508 bytes |
font_01_sfnt_off0000782f.bin6ba3b76961f8003678cbf6914f923be95d9e07eef5b212df7d758af80d3f969a |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x782F | 10596 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.