MALICIOUS
120
Risk Score
Malware Insights
MITRE ATT&CK
T1566.002 Spearphishing Attachment
T1204.002 Malicious Link
The PDF file contains a significant number of embedded links, with one heuristic specifically identifying it as a PDF link farm. The primary malicious URL, https://ttraff.com/wix?keyword=john+f.+reynolds, is flagged as a known malicious redirector. The document body contains garbled text and what appears to be metadata from the wkhtmltopdf tool, suggesting it was programmatically generated to host these links.
Heuristics 3
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://ttraff.com/wix?keyword=john+f.+reynolds
- https://cdn.shopify.com/s/files/1/0431/5657/0266/files/90052473983.pdf
- https://cdn.shopify.com/s/files/1/0431/7754/1787/files/zitupapadudiredofovajik.pdf
- https://cdn.shopify.com/s/files/1/0437/9095/8752/files/brio_dinner_menu.pdf
- https://cdn.shopify.com/s/files/1/0448/8734/3271/files/32233847595.pdf
- https://cdn.shopify.com/s/files/1/0432/7574/7484/files/auxin_biosynthesis_pathway.pdf
- https://cdn.shopify.com/s/files/1/0432/2931/5229/files/81703350197.pdf
- https://cdn.shopify.com/s/files/1/0429/9587/5989/files/should_shouldnt_exercises_agenda_web.pdf
- https://static.usrfiles.com/ugd/5fd5c1_cd0cbc3683ab4f46ba519ec3950210bc.pdf
- https://static.usrfiles.com/ugd/b8c837_aa232c00dec347458a860aaa1b17f07f.pdf
- https://static.usrfiles.com/ugd/b8c837_857fd19f984e4c0fa702c7e3211b0246.pdf
- https://cdn.shopify.com/s/files/1/0433/5920/7582/files/50815331128.pdf
- https://cdn.shopify.com/s/files/1/0429/7375/7603/files/eclipse_oxygen_64_bit_exe_file.pdf
- https://cdn.shopify.com/s/files/1/0469/0296/8482/files/naruto_shippuden_apk_offline_game.pdf
- https://cdn.shopify.com/s/files/1/0431/8009/7687/files/jopok.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Extracted artifacts 3
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off000081a1.bin115a90d5df7f1a08ec65c1c0c5eeb363e7af8e1ab5f7ad4c5866874c484625af |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x81A1 | 4568 bytes |
font_01_sfnt_off00009116.bin600e2c9bf2b89557bc84261a4677893e6abe9526b3ca165d19eb3070119fa775 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x9116 | 14112 bytes |
font_02_sfnt_off0000bceb.binff5f0ef16caf3e97cd1984b3a03ea88e11eab8cf63d2ee006085a4b9995833f3 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xBCEB | 4324 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.