Malware Insights
The PDF contains a critical heuristic firing for a malicious redirector link, pointing to 'https://ttraff.cc/wix?keyword=tempest+addon+download'. Additionally, it exhibits a PDF link farm heuristic, with numerous links hosted on 'static.usrfiles.com'. The document body, though partially garbled, contains text related to 'Tempest addon download' and the authoring application 'wkhtmltopdf', suggesting a lure for a software download. The presence of a visual download button heuristic further supports this. The primary malicious IOC is the redirector URL.
Heuristics 4
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTONDocument contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://ttraff.cc/wix?keyword=tempest+addon+download
- https://static.usrfiles.com/ugd/b8c837_e4166d41eb4c45269922a0a584ee03e0.pdf
- https://static.usrfiles.com/ugd/b8c837_7a34f25398c34df9b1a99cc4e235aec6.pdf
- https://static.usrfiles.com/ugd/b8c837_963a1f0ead924d0b943671f60847e9cf.pdf
- https://static.usrfiles.com/ugd/b8c837_0cbcd5cb10574ca2ac8613995d8126b2.pdf
- https://static.usrfiles.com/ugd/b8c837_aeba14b6879c43c8a61d852a8f1d1ae3.pdf
- https://static.usrfiles.com/ugd/b8c837_941cb09722124005a9a745a8750c1b6b.pdf
- https://static.usrfiles.com/ugd/b8c837_74d288e799504b99958d9226f29c1549.pdf
- https://static.usrfiles.com/ugd/238140_4fb394c47669441f9c059534ff26604d.pdf
- https://static.usrfiles.com/ugd/b8c837_21b9ebe27ef7402f87e0d0f199e9f391.pdf
- https://static.usrfiles.com/ugd/63d3ad_4ce23c760a674f0d87f51b61760a6d81.pdf
- https://static.usrfiles.com/ugd/b8c837_37cc14b2892646c79dc8fb92c192adb8.pdf
- https://static.usrfiles.com/ugd/b8c837_10bbf1f3083b4508a2fc06a12fa4fd97.pdf
- https://static.usrfiles.com/ugd/b8c837_2c1c2a3713ab43eab5e5e0d28b856f2c.pdf
- https://static.usrfiles.com/ugd/efb3f0_e8fd8ec910064eb79273dbf2d7033248.pdf
- https://static.usrfiles.com/ugd/b8c837_41e24464f143445f9a2549e235a1821d.pdf
- https://static.usrfiles.com/ugd/b8c837_c5ccd4701b2d4f4f9a250e922d0e93c1.pdf
- https://static.usrfiles.com/ugd/b8c837_8afe13fc864541279414b3f8f116622f.pdf
- https://tempest0580.github.io/
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off000078a7.bin51f39886751d87f7135747f8de26209216387fd8cb5ab5a27854fcd301598e66 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x78A7 | 5048 bytes |
font_01_sfnt_off000089d3.bin63114eb335fba6bbfb287e2480df1803d70c482c7dfe78a0cfe1ac793be911fa |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x89D3 | 10328 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.