Malware Insights
The PDF contains a link farm designed to appear as a technical document, likely to trick users into clicking. The primary malicious link, https://ttraff.ru/wix?keyword=aws+cloudformation+template+format+error+unsupported+structure, is identified as a malicious redirector. The document body, though heavily obfuscated, contains references to the same technical error, reinforcing the lure. The presence of numerous benign-looking Shopify links suggests an attempt to mask the malicious redirector within a larger, seemingly legitimate link farm.
Heuristics 3
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://ttraff.ru/wix?keyword=aws+cloudformation+template+format+error+unsupported+structure
- https://cdn.shopify.com/s/files/1/0436/8151/3622/files/2425270092.pdf
- https://cdn.shopify.com/s/files/1/0436/8665/8213/files/jitadajezikopimugebigar.pdf
- https://cdn.shopify.com/s/files/1/0431/8907/6117/files/jelimutifezep.pdf
- https://static.usrfiles.com/ugd/3aca14_128df964369a44639d68f19865712238.pdf
- https://static.usrfiles.com/ugd/61f964_3564ce980d64424ba80b143707162428.pdf
- https://static.usrfiles.com/ugd/ca300b_303cdb77ad1d49158045ad8573150f4e.pdf
- https://static.usrfiles.com/ugd/f46427_56314b1286a946c38e7ff23fc3d96cc2.pdf
- https://static.usrfiles.com/ugd/b8c837_46b65b3cbfeb4ae888fd58478a344f59.pdf
- https://cdn.shopify.com/s/files/1/0433/0687/7080/files/60801944673.pdf
- https://cdn.shopify.com/s/files/1/0428/0470/7491/files/biochemistry_by_h_stephen_stoker.pdf
- https://cdn.shopify.com/s/files/1/0430/5004/1495/files/xupizuvulagojanonazutowag.pdf
- https://cdn.shopify.com/s/files/1/0438/2621/7120/files/high_voltage_breakdown_tester.pdf
- https://cdn.shopify.com/s/files/1/0432/9373/7110/files/histologie_de_l_appareil_urinaire.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00005556.bine44a3d47b74470afa9f75d7266ea92d367f441439e154c4d82e06cf18f678b4e |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x5556 | 5384 bytes |
font_01_sfnt_off000067a0.binef087ead9a8a95c5eb689fb39b1a1a07aad7700edf4225ac9ca27fccdc71ee99 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x67A0 | 12456 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.