MALICIOUS
120
Risk Score
Malware Insights
MITRE ATT&CK
T1566.002 Spearphishing Attachment
T1204.002 Malicious Link
The PDF file contains a heuristic firing for a malicious redirector link pointing to 'ttraff.com'. The document body, though heavily obfuscated, contains the same URL. This URL is likely used to redirect the user to a malicious site, possibly for phishing or malware distribution. The PDF also contains a link farm heuristic, indicating it's part of a larger SEO manipulation effort.
Heuristics 3
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://ttraff.com/wix?keyword=cambridge+igcse+computer+science+book+answers
- https://static.usrfiles.com/ugd/432b07_224757a7e6e2446a9d22d5a1e882dad6.pdf
- https://static.usrfiles.com/ugd/66c878_3f8cfd805df049ed8a81cc8dd58a8606.pdf
- https://static.usrfiles.com/ugd/b8c837_f3f4a0e144e5436d86d7252bc50e2254.pdf
- https://static.usrfiles.com/ugd/0511f5_96e16c88eee94d5996ce4059d51e45d3.pdf
- https://static.usrfiles.com/ugd/d7ba0f_bccda798fe4e4c4aab0c7c0b61e04c4f.pdf
- https://cdn.shopify.com/s/files/1/0457/6336/2980/files/seven_nation_army_trombone_sheet_music.pdf
- https://cdn.shopify.com/s/files/1/0432/2865/9880/files/tonapexopopa.pdf
- https://cdn.shopify.com/s/files/1/0433/8873/1543/files/how_to_broil_ribeye.pdf
- https://cdn.shopify.com/s/files/1/0434/2022/1596/files/bramman_tamil_movie_video_song.pdf
- https://static.usrfiles.com/ugd/63d3ad_56aaf447844040ca8e46c68321977b47.pdf
- https://static.usrfiles.com/ugd/82d61e_fd40aefb34b24f0c940da1bed6f7782d.pdf
- https://static.usrfiles.com/ugd/008e52_7e7c1fe17910418991c3ae3722faab90.pdf
- https://static.usrfiles.com/ugd/eaf48f_f3d3e5229f9a4c7e9fc14287ba9f67e7.pdf
- https://static.usrfiles.com/ugd/ea2f88_82b25dc54cc448d690d163d40b097f38.pdf
- https://cdn.shopify.com/s/files/1/0430/7111/1330/files/36581029544.pdf
- https://cdn.shopify.com/s/files/1/0431/0679/5686/files/zadususesafupulufuno.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000f09e.bin2c67b1462617c61a6899e929d7132880e94395a89fd6e8f7bcf74526eadde95b |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xF09E | 5564 bytes |
font_01_sfnt_off00010379.bin11d46402b7a16405264b22c11677a0de7a306ef4df47e74767719e1e4bea3f33 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x10379 | 11080 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.