MALICIOUS
120
Risk Score
Malware Insights
MITRE ATT&CK
T1566.002 Spearphishing Attachment
T1204.002 Malicious Link
The PDF file contains a significant number of embedded links, with one pointing to a known malicious redirector. The document body and embedded artifacts suggest a potential SEO manipulation or link farm tactic. The presence of a malicious redirector URL indicates an attempt to lead the user to a harmful destination.
Heuristics 3
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://ttraff.com/wix?keyword=stocker+musique+en+ligne+gratuit
- https://cdn.shopify.com/s/files/1/0433/0687/7080/files/90262961418.pdf
- https://cdn.shopify.com/s/files/1/0429/1313/6799/files/wopiganufu.pdf
- https://cdn.shopify.com/s/files/1/0436/6375/3369/files/canara_bank_atm_card_application_form_download.pdf
- https://cdn.shopify.com/s/files/1/0432/5595/5613/files/silepunomegeseg.pdf
- https://cdn.shopify.com/s/files/1/0432/5376/0162/files/nawusiwerowiwalewopitomup.pdf
- https://cdn.shopify.com/s/files/1/0464/6944/7830/files/borghese_gallery_guided_tour_or_not.pdf
- https://cdn.shopify.com/s/files/1/0435/1596/9688/files/executor_guide_saskatchewan.pdf
- https://cdn.shopify.com/s/files/1/0466/5897/7957/files/active_and_passive_verbs_worksheets_with_answers.pdf
- https://cdn.shopify.com/s/files/1/0427/6820/3942/files/los_angeles_freeway_map.pdf
- https://cdn.shopify.com/s/files/1/0440/0765/3526/files/2938058240.pdf
- https://cdn.shopify.com/s/files/1/0436/3059/2160/files/81298467077.pdf
- https://cdn.shopify.com/s/files/1/0462/9014/1344/files/linking_stylesheet_to_html_page.pdf
- https://static.usrfiles.com/ugd/6908d7_799ba7714fa14383b3c6de99922e36b0.pdf
- https://static.usrfiles.com/ugd/3bca44_1d7a9084a03142f5b0d7026175af5c31.pdf
- https://static.usrfiles.com/ugd/934fc3_7cf35b8c55a1486596b14ec07d2dd612.pdf
- https://static.usrfiles.com/ugd/e4bc37_6683b1de80694bad9918c141daa5a200.pdf
- https://static.usrfiles.com/ugd/b8c837_f76e49bd4db54925b40a48ba9ca7779d.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00008467.bine95683245c5ef0080693c55c1cc4f96034cffde374fe44af6a353383ca71493c |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x8467 | 5412 bytes |
font_01_sfnt_off000096a9.binb8e880f512b8ea34b76086062e0fd92b47c1ad36274f47e9d369a25d6cc3b603 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x96A9 | 12236 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.