MALICIOUS
120
Risk Score
Malware Insights
MITRE ATT&CK
T1566.002 Spearphishing Attachment
T1059.001 PowerShell
The PDF contains a link farm designed to redirect users to malicious infrastructure, specifically advertising 'clash of clans apk indir android club'. The primary malicious URL identified is https://ttraff.me/wix?keyword=clash+of+clans+apk+indir+android+club. This indicates a social engineering tactic to trick users into downloading potentially harmful content.
Heuristics 3
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://ttraff.me/wix?keyword=clash+of+clans+apk+indir+android+club
- https://static.usrfiles.com/ugd/b8c837_d92458ecee1c45c6b35af5bffbd129bb.pdf
- https://static.usrfiles.com/ugd/b8c837_bc4b5000d7e140c89d5fb2220bad0f8b.pdf
- https://static.usrfiles.com/ugd/b8c837_a25d2ea2402347baa32c25210f26d2f1.pdf
- https://cdn.shopify.com/s/files/1/0434/7274/8710/files/demivatogatosoreletarod.pdf
- https://static.usrfiles.com/ugd/b8c837_e7163694d3c2420f8f09a255e1cdfa80.pdf
- https://static.usrfiles.com/ugd/b8c837_1f2190803f6a4aa79018dbb087649e63.pdf
- https://static.usrfiles.com/ugd/b8c837_a2df443e51294c52aa94d176184f0e2f.pdf
- https://static.usrfiles.com/ugd/b8c837_ef128a29ee2e463791f3e75dc0f01e77.pdf
- https://static.usrfiles.com/ugd/de65f7_7028f2796c394b8d90980f6528ee331d.pdf
- https://static.usrfiles.com/ugd/b8c837_1cbf32c67fcd438ebdac23d0626f80df.pdf
- https://static.usrfiles.com/ugd/b8c837_6902fd47bee947a9aeb8e43c9f1216b1.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000480e.bin0864b695fa45df05df14aca37ff4e2819e46f958004064a85dbf531eab82bb4e |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x480E | 5352 bytes |
font_01_sfnt_off00005a27.binf0208024b8da0b5ebf88d4b2013112dd612b39518e81ccc820eea171335fab24 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x5A27 | 9864 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.