MALICIOUS
68
Risk Score
Malware Insights
MITRE ATT&CK
T1204.002 Malicious Link
The PDF file contains a critical heuristic firing indicating it is a malicious redirector link. The document body, though heavily obfuscated, contains text that suggests a lure, and the embedded URL points to a known malicious redirector. The heuristic 'SE_URGENCY_LURE' further supports the social engineering aspect of this attack.
Heuristics 3
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Urgency / deadline lure low SE_URGENCY_LUREDocument contains urgency or deadline language ('account will be terminated', 'action required within 24 hours', etc.) — useful context, but low-signal without other findings
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://ttraff.cc/pify?keyword=starter+cross+reference+guide
- http://files.itechtutoring.com/uploads/1/3/1/4/131453543/f364f0ca.pdf
- http://fakukudek.rhinedesign.org/uploads/1/3/0/8/130873851/befepu-fenev.pdf
- http://lixin.bfvh.com/uploads/1/3/0/8/130813528/mipikudaka.pdf
- http://files.evincarter.org/uploads/1/3/1/4/131437477/wanasiritizedel.pdf
- https://cdn.shopify.com/s/files/1/0427/5296/6812/files/vidiponifunugataxop.pdf
- https://cdn.shopify.com/s/files/1/0430/5331/8306/files/popaledegele.pdf
- https://cdn.shopify.com/s/files/1/0440/2960/8101/files/jipexusaxeremolenugo.pdf
- https://cdn.shopify.com/s/files/1/0428/9550/7622/files/kusadabaxe.pdf
- https://cdn.shopify.com/s/files/1/0432/1961/5901/files/fulton_county_mugshots.pdf
- https://cdn.shopify.com/s/files/1/0430/7920/5013/files/25560922939.pdf
- https://cdn.shopify.com/s/files/1/0430/7304/4647/files/abcdee_calibri-_normal_font_free.pdf
- https://cdn.shopify.com/s/files/1/0427/9864/5404/files/pazurumojuk.pdf
- https://cdn.shopify.com/s/files/1/0436/2852/7776/files/capitalismo_monopolista_e_servio_social_jose_paulo_netto.pdf
- https://cdn.shopify.com/s/files/1/0432/3170/7294/files/jepowabojeg.pdf
- https://cdn.shopify.com/s/files/1/0434/2749/6087/files/downtown_baltimore_map.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Extracted artifacts 3
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off000aa238.bin9ed12c2b80b46348fc55f9712912c50b2061a1ead96c5873f11ec77c632493cc |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xAA238 | 6832 bytes |
font_01_sfnt_off000ab969.bine5c6fc585f0fc084f16b4843cd30f4e38b4775bd86d2e35793f4c109c367104a |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xAB969 | 5260 bytes |
font_02_sfnt_off000acb52.bin34f08a247352724c8058e0c77567ba7292ac34a459262c968b8cefd282afc008 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xACB52 | 16660 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.