MALICIOUS
120
Risk Score
Malware Insights
MITRE ATT&CK
T1566.002 Spearphishing Attachment
T1204.002 Malicious Link
The PDF file contains a malicious redirector link disguised as a manual for a "Neslab m75 chiller". The document body, though heavily obfuscated, contains the target URL and references to the wkhtmltopdf tool, suggesting it was programmatically generated. The presence of a link farm heuristic further indicates a malicious intent to redirect users to potentially harmful content.
Heuristics 3
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://ttraff.club/wix?keyword=neslab+m75+chiller+manual
- https://cdn.shopify.com/s/files/1/0434/3801/4616/files/clasificacion_de_conductores_semiconductores_y_aislantes.pdf
- https://cdn.shopify.com/s/files/1/0431/2354/0124/files/59732370800.pdf
- https://cdn.shopify.com/s/files/1/0433/3250/1656/files/dukusaxitomit.pdf
- https://c2365840-d475-4c66-ad73-98b527d2fb93.filesusr.com/ugd/948cea_73d8fc3391ae41da8b984872e3f3a262.pdf?index=true
- https://fe4c9c8d-c2f2-4ae8-9e53-7eec50c502f4.filesusr.com/ugd/277b62_c70ec0c622f6463daeeacb160a2a7fc0.pdf?index=true
- https://7d9f1a32-e83b-47a7-a2f7-aac3bc89a056.filesusr.com/ugd/dcc11b_848f46d7ef9e4090993e02602683ce21.pdf?index=true
- https://5ebf5e07-de7d-4e23-8d8c-8ff95306c733.filesusr.com/ugd/55e2c6_f40852917ebb4f35b5d45526fb7a571e.pdf?index=true
- https://32e9fe89-2825-4f60-a972-6c24d050fcd6.filesusr.com/ugd/d1c05f_f0b50568823f4e03a5b006e58dee0960.pdf?index=true
- https://1e82a57c-1692-490b-9078-7a7270272a92.filesusr.com/ugd/d7d6cd_57cd1876b48e4500939c462f01d9bd97.pdf?index=true
- https://31e04b9b-935e-4e02-9782-9ad0aeb8cea4.filesusr.com/ugd/e2b09b_73b2266e73564f8fba01f9c992064da6.pdf?index=true
- https://ab564635-aa6e-4ed9-aad8-fca31d38a5e9.filesusr.com/ugd/1decf9_bd6a2342c13047e6834d21c34835a977.pdf?index=true
- https://972bb2ec-1b00-4bfe-b0b1-7b89fcdd5e18.filesusr.com/ugd/b1b3ad_c2f7a6704b3047df89c61044a52cbcfe.pdf?index=true
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000510c.bin36c870bbfe5221739ad7190c1ade950fedc7fd01d258e6e40fe4203df10ae2f9 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x510C | 5352 bytes |
font_01_sfnt_off00006329.bin7ba689435a96ca1fa96baa2ed7e49904b5e49a1954a2b88fbfc28e56f5565a79 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x6329 | 10156 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.