MALICIOUS
120
Risk Score
Malware Insights
MITRE ATT&CK
T1566.002 Spearphishing Attachment
T1204.002 Malicious Link
The PDF file contains numerous embedded links, a common tactic for distributing malicious content. One prominent link, 'https://ttraff.ru/pify?keyword=episode+guide+ncis+new+orleans+season+3', points to a known malicious redirector. The document body, though heavily obfuscated, also contains this URL, suggesting an attempt to disguise the malicious intent. The presence of a link farm heuristic further supports the malicious nature of the document.
Heuristics 3
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://ttraff.ru/pify?keyword=episode+guide+ncis+new+orleans+season+3
- http://files.feedthewobbegong.com/uploads/1/3/2/8/132814073/2052547.pdf
- http://lobimis.pro4uk.com/uploads/1/3/1/3/131398455/7138037.pdf
- http://wavev.areyoureallybringinghim.com/uploads/1/3/1/3/131398091/xejamupexirim.pdf
- https://cdn.shopify.com/s/files/1/0444/4500/8039/files/caracteristicas_de_los_aditivos_alimentarios.pdf
- https://cdn.shopify.com/s/files/1/0433/0687/7080/files/zimupumunilojoduwa.pdf
- https://cdn.shopify.com/s/files/1/0427/4801/8855/files/54251228993.pdf
- https://cdn.shopify.com/s/files/1/0437/4839/3112/files/solegakejegari.pdf
- https://cdn.shopify.com/s/files/1/0438/8651/0232/files/gobukubetuzamenaxixojasav.pdf
- https://cdn.shopify.com/s/files/1/0430/2965/9805/files/46760537924.pdf
- https://cdn.shopify.com/s/files/1/0433/9017/3349/files/37991682226.pdf
- https://cdn.shopify.com/s/files/1/0432/3131/4077/files/44107217735.pdf
- https://cdn.shopify.com/s/files/1/0441/4029/8392/files/evan_moor_daily_phonics_grade_2.pdf
- https://cdn.shopify.com/s/files/1/0430/7261/8657/files/folona.pdf
- https://cdn.shopify.com/s/files/1/0430/9850/5377/files/target_cashier_training_manual.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00004bc8.bin698c77fe2d79f108354a48d4a58c8dacda3e5ada82199e341448a5ee90ef2d7b |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x4BC8 | 5456 bytes |
font_01_sfnt_off00005e6f.bin770e5d0794da333df86336312e208e5cade15db661d9b9b83d63de6c49b35dc7 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x5E6F | 9628 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.