Malware Insights
The PDF file contains a large number of embedded links, many of which are designed to redirect users to potentially malicious sites, as indicated by the PDF_MALICIOUS_REDIRECTOR_LINK and PDF_SEO_LINK_FARM heuristics. The primary redirector URL identified is https://ttraff.cc/pify?keyword=monster+hunter+world+gunlance+weapon+guide. While many linked Shopify PDFs are benign, the presence of the malicious redirector and the sheer volume of links suggest a link farm or redirection attack. No scripts were extracted, limiting the analysis of direct payload delivery.
Heuristics 3
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://ttraff.cc/pify?keyword=monster+hunter+world+gunlance+weapon+guide
- http://files.jessicawestphotography.net/uploads/1/3/1/8/131856626/0325d285.pdf
- https://cdn.shopify.com/s/files/1/0441/1791/7848/files/56203239941.pdf
- https://cdn.shopify.com/s/files/1/0431/0990/8637/files/list_of_animals_in_french.pdf
- https://cdn.shopify.com/s/files/1/0434/6544/1445/files/catalyzing_change.pdf
- https://cdn.shopify.com/s/files/1/0429/7788/6367/files/64791808919.pdf
- https://cdn.shopify.com/s/files/1/0433/3672/8735/files/atomic_habits_journal.pdf
- https://cdn.shopify.com/s/files/1/0430/6976/7842/files/bovozogipanasuxaneb.pdf
- https://cdn.shopify.com/s/files/1/0432/3305/0779/files/bamidajoga.pdf
- https://cdn.shopify.com/s/files/1/0435/5053/9940/files/19245005082.pdf
- https://cdn.shopify.com/s/files/1/0433/0687/7080/files/gaxasukazojolivuf.pdf
- https://cdn.shopify.com/s/files/1/0431/9235/2931/files/corporals_course_tactical_tools_answers.pdf
- https://cdn.shopify.com/s/files/1/0430/0531/3177/files/pisuseb.pdf
- https://cdn.shopify.com/s/files/1/0431/6761/3077/files/tadezuwagigijalizasofetap.pdf
- https://cdn.shopify.com/s/files/1/0429/8178/5753/files/disodiwageronubo.pdf
- https://cdn.shopify.com/s/files/1/0429/4764/1511/files/26047845018.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Extracted artifacts 4
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00006214.bin43b3b9075250611ae48ed62242c0c2f37f2c60aaf3aa9a1ac84982e976f6dc60 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x6214 | 5312 bytes |
font_01_sfnt_off00007430.bin8bc5e38d4e9b6878d827c977a23053179a18d6e188e0fb7dba266356e2deebab |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x7430 | 10000 bytes |
font_02_sfnt_off000096b4.bind8a1a34de14a7b8fce5e51635835121d353d188f9ac9ce1e11538509fd4c5cdc |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x96B4 | 16060 bytes |
font_03_sfnt_off0000ab4c.bin9f355172d696dda274cac500966718f112ce76951f19577ac4888987ea6471b2 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xAB4C | 4324 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.