MALICIOUS
120
Risk Score
Malware Insights
MITRE ATT&CK
T1566.002 Spearphishing Attachment
T1204.001 Malicious Link
The PDF contains a heuristic firing for a malicious redirector link, pointing to 'ttraff.ru'. This URL is presented within the document body, disguised as a search result for 'Ponyo on the cliff by the sea english dub'. The PDF also contains a heuristic for a link farm, with 19 external PDF links, many hosted on 'static.usrfiles.com'. The primary malicious IOC is the redirector URL, which likely leads to further malicious content.
Heuristics 3
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://ttraff.ru/wix?keyword=ponyo+on+the+cliff+by+the+sea+english+dub
- https://static.usrfiles.com/ugd/b77b08_a72550397fdd4fe2b7bafc62bba90493.pdf
- https://static.usrfiles.com/ugd/b8c837_f7ab4f29fb2a47d6b67267b97015b512.pdf
- https://static.usrfiles.com/ugd/f523c3_138d9cb4a5f24ca8b49d71fb3474926b.pdf
- https://static.usrfiles.com/ugd/b7ab08_a8a244fa1bd74dc683912edb3dfcc4fe.pdf
- https://static.usrfiles.com/ugd/b8c837_e861cdc6299c4cf8adb30d40da9b057c.pdf
- https://static.usrfiles.com/ugd/8b2c09_de0b83adff02441ab9f13adb7979fa64.pdf
- https://static.usrfiles.com/ugd/04e6f9_6c8d9606692240458bdf4bcbb5ca95b4.pdf
- https://static.usrfiles.com/ugd/d2cc1f_0f546505430a4212a3f9491c22370593.pdf
- https://static.usrfiles.com/ugd/dd4472_6e051a161a774fddaf427fc25020c37a.pdf
- https://cdn.shopify.com/s/files/1/0432/2865/9874/files/alter_ego_a1_archive.pdf
- https://cdn.shopify.com/s/files/1/0434/2166/3397/files/balance_ton_quoi_partition_piano.pdf
- https://cdn.shopify.com/s/files/1/0428/9835/8432/files/nagexonulelaxefirulilona.pdf
- https://cdn.shopify.com/s/files/1/0432/1578/2048/files/rosol.pdf
- https://cdn.shopify.com/s/files/1/0430/7386/3842/files/similarity_report_essay.pdf
- https://static.usrfiles.com/ugd/b8c837_0675bf0d342c4dc788b86726e2943cd5.pdf
- https://static.usrfiles.com/ugd/fb83f1_3acc6d6eb80f4a4fb63bf440310a2d3b.pdf
- https://static.usrfiles.com/ugd/d775a9_48cb428f460d44b3875d0efb2d2ae795.pdf
- https://static.usrfiles.com/ugd/b8c837_356230d3c3694ca8af539d8cba9a1ce1.pdf
- https://static.usrfiles.com/ugd/b0b521_0a366a2599cd4115b62a6ba80886226a.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Extracted artifacts 3
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000a471.binda0ca4baf0047c1df5881b4ab189fd41462be209d6dd0b019313072b9a2ffe8d |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xA471 | 26224 bytes |
font_01_sfnt_off0000f71f.bin047eca59303707bf7b903b132b82a7db92256805134865340bd4140e425a263b |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xF71F | 5432 bytes |
font_02_sfnt_off00010992.bindbc95a7ec315ccc018b9eed963accd1246c607a9607e7556c0025e3886e16760 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x10992 | 10888 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.