MALICIOUS
120
Risk Score
Malware Insights
MITRE ATT&CK
T1566.002 Spearphishing Attachment
T1059.001 PowerShell
The PDF contains a link to a known malicious redirector, ttraff.com, disguised as a calendar PDF. This indicates a phishing or malware delivery attempt. The document body and embedded links suggest a lure related to 'Kalnirnay 2019 marathi calendar pdf online'. The PDF also contains a link farm pointing to multiple Shopify-hosted PDFs, likely to improve search engine ranking and distribute the malicious link.
Heuristics 3
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://ttraff.com/pify?keyword=kalnirnay+2019+marathi+calendar+pdf+online
- http://tefanubum.talamofood.net/uploads/1/3/1/4/131437089/66161.pdf
- http://files.bronxleadershipacademy.org/uploads/1/3/0/9/130969054/882463.pdf
- https://cdn.shopify.com/s/files/1/0427/7318/4678/files/folojekufufobadopawuwevat.pdf
- https://cdn.shopify.com/s/files/1/0435/6400/7583/files/19925411067.pdf
- https://cdn.shopify.com/s/files/1/0431/1701/9292/files/31952581226.pdf
- https://cdn.shopify.com/s/files/1/0435/9441/6290/files/english_grammar_book_2020.pdf
- https://cdn.shopify.com/s/files/1/0429/7441/2949/files/zoxefitabepekaxajawoja.pdf
- https://cdn.shopify.com/s/files/1/0431/5650/4744/files/1273069039.pdf
- https://cdn.shopify.com/s/files/1/0430/8421/8521/files/48749812701.pdf
- https://cdn.shopify.com/s/files/1/0436/9698/0136/files/5966739091.pdf
- https://cdn.shopify.com/s/files/1/0434/3057/6278/files/15734923378.pdf
- https://cdn.shopify.com/s/files/1/0434/1137/4230/files/fepuri.pdf
- https://cdn.shopify.com/s/files/1/0434/0645/9029/files/54358721864.pdf
- https://cdn.shopify.com/s/files/1/0436/0568/8483/files/5309702239.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Extracted artifacts 4
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off000051df.bin0bdc5d32c17a7ab9f79057e8694c1f02302349fdb63c515e2c2b41205d05b03b |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x51DF | 5772 bytes |
font_01_sfnt_off00006567.binfdb60f59b576a43bb8c21d93a92b7504ef310cdd721b4a471a38e26206c607bf |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x6567 | 10076 bytes |
font_02_sfnt_off0000880a.binead7fd593d7f5feef6f283420e9b55f8fa4552f107c64b0063d474dd3355abd8 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x880A | 16164 bytes |
font_03_sfnt_off00009d5f.bina0237da2ba6f7d0b862c21bbba5b6eb9f46d0a62d33dbf6d93c3da7886ced467 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x9D5F | 5112 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.