MALICIOUS
120
Risk Score
Malware Insights
MITRE ATT&CK
T1566.002 Spearphishing Attachment
T1204.002 Malicious Link
The PDF file contains a significant number of embedded links, with one heuristic specifically identifying it as a PDF link farm. The primary malicious link, 'https://ttraff.me/wix?keyword=farm+household+allowance+guidelines', is flagged as a known malicious redirector. The document body, though heavily obfuscated, also contains this URL and other Shopify URLs, suggesting a lure to external content.
Heuristics 3
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://ttraff.me/wix?keyword=farm+household+allowance+guidelines
- https://cdn.shopify.com/s/files/1/0434/0449/2950/files/bisection_method_numerical_analysis.pdf
- https://cdn.shopify.com/s/files/1/0430/5112/2842/files/mebixaba.pdf
- https://cdn.shopify.com/s/files/1/0459/1924/0341/files/87940281454.pdf
- https://cdn.shopify.com/s/files/1/0435/5381/6728/files/ruwinawo.pdf
- https://cdn.shopify.com/s/files/1/0433/6268/0984/files/1214378167.pdf
- https://static.usrfiles.com/ugd/b8c837_669cf7f73d7d47788a173a295d4e4d50.pdf
- https://cdn.shopify.com/s/files/1/0434/2746/3324/files/24268669764.pdf
- https://cdn.shopify.com/s/files/1/0433/7801/6406/files/cacti_rrdtool_windows.pdf
- https://cdn.shopify.com/s/files/1/0433/9476/0862/files/wotezoxa.pdf
- https://static.usrfiles.com/ugd/f63f29_51763a5a94fe4d83b3909daaea4b453f.pdf
- https://static.usrfiles.com/ugd/6cf0f5_67826293f77d4f7d87141d08bdbc23d1.pdf
- https://static.usrfiles.com/ugd/b8c837_d3e1e33ee8e147dd8f8349ff164afa72.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00005082.binee677d9ac0cc4e2d341148b6ec57401c97bebf1e914c161e33ee7681d931bea1 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x5082 | 5400 bytes |
font_01_sfnt_off000062c5.bin7b8a0dffde2a2b55bb1f03eb6cabb2d8a3c40b10f0b949e4adc0183f1922f70e |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x62C5 | 9852 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.