MALICIOUS
68
Risk Score
Malware Insights
MITRE ATT&CK
T1566.002 Spearphishing Attachment
T1059.001 PowerShell
T1204.002 Malicious Link
The PDF contains a link to a known malicious redirector, https://cctraff.ru/mozel?keyword=possessive+pronouns+exercise+pdf, which is a strong indicator of malicious intent. The presence of a visual download button further supports a lure-based attack. While no scripts were extracted, the embedded link and the heuristic firing for a malicious redirector suggest the document is designed to lead the user to a harmful destination.
Heuristics 3
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTONDocument contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://cctraff.ru/mozel?keyword=possessive+pronouns+exercise+pdf
- https://site-1036637.mozfiles.com/files/1036637/864054393.pdf
- https://site-1036923.mozfiles.com/files/1036923/80807366755.pdf
- https://site-1037059.mozfiles.com/files/1037059/jimogevun.pdf
- https://site-1037274.mozfiles.com/files/1037274/50144301972.pdf
- https://site-1036864.mozfiles.com/files/1036864/2994178054.pdf
- http://files.colinbergmusic.com/uploads/1/3/2/3/132302780/pewobilobibexejo.pdf
- https://site-1036884.mozfiles.com/files/1036884/didowipipa.pdf
- https://site-1037283.mozfiles.com/files/1037283/35408126082.pdf
- https://site-1036982.mozfiles.com/files/1036982/90013272277.pdf
- https://site-1036962.mozfiles.com/files/1036962/lapowobiferogimuralomege.pdf
- https://d53a1988-72aa-4ceb-9f10-53238813e393.filesusr.com/ugd/31593d_cb019dc1f19947f3ac15ab1ce4b57a63.pdf?index=true
- https://a5820e90-7c55-49e5-90db-282d7462b1cb.filesusr.com/ugd/60ffa2_fbbce2a806d94419b1c5b8d22d37303e.pdf?index=true
- https://c175abd7-4154-4c5c-b084-e2991f922332.filesusr.com/ugd/b52961_beb1e6dd2f7f41acacdbf33e8fe33b82.pdf?index=true
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00004c4c.bin678865b6a37408f06cddc784fa859fcd158032783afcdda3946bfc4cc3a99d80 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x4C4C | 5036 bytes |
font_01_sfnt_off00005d90.binc755875b93c35ba1c8aeb618124925b979c8c1dfe85880d333bfe3054b7ab7b5 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x5D90 | 12376 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.