MALICIOUS
120
Risk Score
Malware Insights
MITRE ATT&CK
T1566.002 Spearphishing Attachment
T1204.002 Malicious Link
The PDF file contains multiple embedded links, with one specifically identified as a malicious redirector. The document body text, though partially corrupted, includes the URL 'https://ttraff.club/wix?keyword=pro+evolution+soccer+2017+apk+data+offline' which is presented as a lure for a game download. This indicates a phishing or social engineering attack aimed at redirecting users to malicious infrastructure.
Heuristics 3
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://ttraff.club/wix?keyword=pro+evolution+soccer+2017+apk+data+offline
- http://files.randygachet.com/uploads/1/3/2/6/132682905/vomububugataled_tarojifubixeses.pdf
- http://files.lakesidepresnurseryschool.com/uploads/1/3/0/9/130969659/regigege.pdf
- http://files.silvertonnaz.com/uploads/1/3/1/4/131483445/890322aedb.pdf
- https://6b78ae51-ba56-48c6-b631-97fef13ae88b.filesusr.com/ugd/b222ea_6b47b856ff7d4fd6a09f30d7ef1bab35.pdf?index=true
- https://ff2157e6-9eac-4192-8d44-8c9826740088.filesusr.com/ugd/eaf48f_4c25538574e4411eb03e489d507fd630.pdf?index=true
- https://89c8f6cc-c674-4952-953a-c151319104ec.filesusr.com/ugd/668a47_71dd9d2cecee4c3a83d058493e9cc6b6.pdf?index=true
- https://be01a467-36da-4d15-bb34-e1a830b33b72.filesusr.com/ugd/e4ff69_80e2109126224376ada16c320e1a7c64.pdf?index=true
- https://702f19bc-dd68-4516-a7ce-a88919b9a436.filesusr.com/ugd/516793_198ebfb32bd3449fb5aed0c7daa98e3c.pdf?index=true
- https://5f086eea-45fe-4c1f-aea4-3a97db07e35c.filesusr.com/ugd/38955b_bd2fff7f1622467180b21b90852579e3.pdf?index=true
- https://da7d321f-ec99-4c69-bc4e-4f10e0b2e158.filesusr.com/ugd/035627_bbd122f19f12416b81397f23e53279a2.pdf?index=true
- https://cdn.shopify.com/s/files/1/0432/4976/2459/files/16136954889.pdf
- https://cdn.shopify.com/s/files/1/0431/2363/8426/files/tesivojo.pdf
- https://cdn.shopify.com/s/files/1/0439/3821/8152/files/datapi.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off000066f3.bin24ea524a7b83d3a7c23a65845392734ab16605436213803e4d250143e60253b1 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x66F3 | 5680 bytes |
font_01_sfnt_off00007a6b.bin3df83dd821cb54d910ed26f7c177eb4a1fdf83917f1f04161381b432a5ec8a84 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x7A6B | 9896 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.