MALICIOUS
120
Risk Score
Malware Insights
MITRE ATT&CK
T1566.002 Spearphishing Attachment
T1204.002 Malicious Link
The PDF was flagged for containing a malicious redirector link and a link farm. The primary malicious URL, https://ttraff.club/pify?keyword=joanne+carole+schieble+simpson, is likely used to direct users to a phishing page or a malware download site. The presence of numerous other links suggests an attempt to game search engine results or distribute content widely.
Heuristics 3
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://ttraff.club/pify?keyword=joanne+carole+schieble+simpson
- https://d565af32-312f-49c4-99cd-3b0714475e7e.filesusr.com/ugd/5ea691_ed32f1f1ead04199aee7a67a5a3eda97.pdf?index=true
- https://13c10245-e3f9-458b-8cef-9aff7dd80510.filesusr.com/ugd/c722c2_6ae7698d899b4e3582a1e6874d587443.pdf?index=true
- https://426d3ecc-d12f-48da-93fe-6c9a098a4cef.filesusr.com/ugd/9c58c5_5a71d46a86f4488292111ae57433b7e1.pdf?index=true
- https://e172543a-442d-4437-b255-ef01b33f5afc.filesusr.com/ugd/1e52da_13e7fb689f044f09a679419633bbc8ce.pdf?index=true
- https://cdn.shopify.com/s/files/1/0438/2215/3890/files/88154152913.pdf
- https://cdn.shopify.com/s/files/1/0431/8960/0414/files/5759901314.pdf
- https://cdn.shopify.com/s/files/1/0435/4444/5092/files/nusiniziwomila.pdf
- https://cdn.shopify.com/s/files/1/0432/6175/5547/files/rutusurarusomozalago.pdf
- https://cdn.shopify.com/s/files/1/0433/9875/8563/files/jogunizibedusopibirusef.pdf
- https://cb0e0d72-d89d-4d6a-a163-3c31e7583293.filesusr.com/ugd/66f3f9_ee5b5215b69b4c1cab44d4280aced3bf.pdf?index=true
- https://8b1ea2df-3184-4869-94b7-091970d6e784.filesusr.com/ugd/d2057d_839825be8e5c4e96a04418202784e90c.pdf?index=true
- https://cdn.shopify.com/s/files/1/0435/2727/4645/files/gubelujetatodemamutekekom.pdf
- https://cdn.shopify.com/s/files/1/0435/5942/0063/files/47098153864.pdf
- https://cdn.shopify.com/s/files/1/0428/1466/8959/files/38261619938.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off000095b7.bin76ca668e3022a316bc51dd8942fad29b049cbc0256d19464756816e62bd4b3b2 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x95B7 | 5300 bytes |
font_01_sfnt_off0000a78e.bin2a772470d737460d93403fa18ddcc58da97433641a6f6f3a4b65486addcf29fb |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xA78E | 10168 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.