Malware Insights
The PDF contains a critical heuristic firing for a malicious redirector link, pointing to 'https://ttraff.ru/wix?keyword=probabilidad+frecuentista+ejemplos+resueltos'. Additionally, another critical heuristic indicates a PDF link farm, with the first URL being 'https://cdn.shopify.com/s/files/1/0432/5657/8212/files/gapabedawoxukesobubomev.pdf'. The document body, though heavily obfuscated, contains the same malicious URL. This suggests the primary goal is to redirect the user to a malicious site, likely for phishing or malware distribution.
Heuristics 3
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://ttraff.ru/wix?keyword=probabilidad+frecuentista+ejemplos+resueltos
- https://cdn.shopify.com/s/files/1/0432/5657/8212/files/gapabedawoxukesobubomev.pdf
- https://cdn.shopify.com/s/files/1/0432/6499/9588/files/23182499971.pdf
- https://cdn.shopify.com/s/files/1/0436/4717/2768/files/97537833444.pdf
- https://cdn.shopify.com/s/files/1/0429/8529/1937/files/contra_la_pareja_agustin_garcia_calvo.pdf
- https://static.usrfiles.com/ugd/b8c837_6da63428f93e4d8aa7d384ada091b80b.pdf
- https://static.usrfiles.com/ugd/b8c837_972a347c37134841bd889e0d19d56688.pdf
- https://static.usrfiles.com/ugd/b8c837_1daae5ef48cc4cb38a6d1549906b7854.pdf
- https://cdn.shopify.com/s/files/1/0431/0702/5056/files/verb_gerund_infinitive_or_participle_worksheet_answers.pdf
- https://cdn.shopify.com/s/files/1/0428/8688/9639/files/dufamidefutiketixizoze.pdf
- https://cdn.shopify.com/s/files/1/0433/4632/9750/files/xajomurilix.pdf
- https://cdn.shopify.com/s/files/1/0433/1926/3397/files/pazabepozuzisubokigususim.pdf
- https://cdn.shopify.com/s/files/1/0429/1588/9305/files/37098119224.pdf
- https://cdn.shopify.com/s/files/1/0464/5286/7240/files/estrategias_de_aprendizaje_visual_pd.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000788d.binc43664f55612b1e65799c3f6b1038a2a936d39446a9c388fd25a549d393e1418 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x788D | 5516 bytes |
font_01_sfnt_off00008b33.bin487a1aa56a7c329125e96a37e8233d19b37ebe06477483fdc895d5b1aeb9f094 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x8B33 | 16824 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.