MALICIOUS
120
Risk Score
Malware Insights
MITRE ATT&CK
T1566.002 Spearphishing Attachment
T1059.001 PowerShell
The PDF contains a heuristic firing for a malicious redirector link, specifically pointing to 'https://ttraff.ru/wix?keyword=kakshi+amminipilla+malayalam+songs'. This URL is presented within the document body, suggesting a social engineering lure. The PDF also exhibits characteristics of a link farm, with numerous embedded URLs, many pointing to Shopify domains, likely for SEO manipulation or to host further malicious content. No scripts were extracted from this sample.
Heuristics 3
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://ttraff.ru/wix?keyword=kakshi+amminipilla+malayalam+songs
- https://static.usrfiles.com/ugd/3aca14_b0235ada3122491ca638f8f07e8ecc37.pdf
- https://static.usrfiles.com/ugd/b8c837_c23f1188a5154b8980cb8176da2cb52b.pdf
- https://static.usrfiles.com/ugd/90423f_281f84a66667461fa0f78e6a67c6c75f.pdf
- https://static.usrfiles.com/ugd/ae059d_f7556886925e44b39539b1d8a7648a19.pdf
- https://static.usrfiles.com/ugd/269bb8_a1a026ea1c1840e2a8a01afb9a7539ef.pdf
- https://static.usrfiles.com/ugd/b8c837_165fb73706fe412c814ff61381b9a175.pdf
- https://static.usrfiles.com/ugd/cc14e4_863d18566f3f49cfa909275384f172c2.pdf
- https://cdn.shopify.com/s/files/1/0433/3849/8206/files/probability_and_statistical_inference_9th_edition_download.pdf
- https://cdn.shopify.com/s/files/1/0440/6811/0488/files/52358531638.pdf
- https://cdn.shopify.com/s/files/1/0428/2885/7503/files/vunusisajerid.pdf
- https://cdn.shopify.com/s/files/1/0434/3519/6578/files/aranegui_santiago_la_cabala_el_conocimiento_completo.pdf
- https://cdn.shopify.com/s/files/1/0462/2883/2405/files/frog_dissection_student_answer_sheet.pdf
- https://cdn.shopify.com/s/files/1/0440/7522/1157/files/cpr_guidelines_2018_uk.pdf
- https://cdn.shopify.com/s/files/1/0431/8996/0865/files/db_annual_report_2017.pdf
- https://cdn.shopify.com/s/files/1/0435/2727/4645/files/belajar_bahasa_jepang_otodidak.pdf
- https://cdn.shopify.com/s/files/1/0437/2119/5669/files/sofia_the_first_scrambled_pets.pdf
- https://cdn.shopify.com/s/files/1/0434/3519/65
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00006bdf.bin54088d5b0d33156ff84e0d5587f8d105cef14b54f6a8928e295d3ba238be5f16 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x6BDF | 5272 bytes |
font_01_sfnt_off00007db6.bin49330ff702e9b454e26c255ad48ce3b97764322227cd8f05c5eb22ccbe8f9be4 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x7DB6 | 15116 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.