MALICIOUS
120
Risk Score
Malware Insights
MITRE ATT&CK
T1566.002 Spearphishing Attachment
T1059.001 PowerShell
T1204.002 Malicious Link
The PDF file contains a mass of external links, many pointing to what appears to be a link farm. One prominent URL, 'https://ttraff.cc/pify?keyword=mathematically+correct+answers', is identified as a malicious redirector. The document body, though heavily obfuscated, contains references to this URL and other PDF links, suggesting a social engineering attempt to direct users to malicious content. No scripts were extracted, limiting the analysis of direct payload execution.
Heuristics 3
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://ttraff.cc/pify?keyword=mathematically+correct+answers
- https://static.usrfiles.com/ugd/e3ed1f_25c21beb5ce24a44ad71a3266289f507.pdf
- https://static.usrfiles.com/ugd/f8de3e_92d86ddb43ff45b987070815f171d9c4.pdf
- https://static.usrfiles.com/ugd/60933b_49c7fa51ef7241649c17fa1ec6d7c7e9.pdf
- https://static.usrfiles.com/ugd/63022f_ce2a5531021d43368316f99dde099fea.pdf
- https://static.usrfiles.com/ugd/0789d5_94a8792e40f045de84c73adb5a0bb9e7.pdf
- https://cdn.shopify.com/s/files/1/0439/2599/5688/files/sepijajovade.pdf
- https://cdn.shopify.com/s/files/1/0440/7004/3813/files/moviescounter_pro_tv_series.pdf
- https://cdn.shopify.com/s/files/1/0432/2931/5229/files/79758935653.pdf
- https://cdn.shopify.com/s/files/1/0434/6288/5541/files/govugavakofevodu.pdf
- https://cdn.shopify.com/s/files/1/0427/7446/2631/files/lijupisofeluguko.pdf
- https://cdn.shopify.com/s/files/1/0431/4628/1120/files/19205884403.pdf
- https://cdn.shopify.com/s/files/1/0434/0744/2072/files/46248288297.pdf
- https://cdn.shopify.com/s/files/1/0429/3292/8671/files/kuzediwenita.pdf
- https://cdn.shopify.com/s/files/1/0438/2271/0941/files/4588926285.pdf
- https://cdn.shopify.com/s/files/1/0440/3471/9909/files/41083619271.pdf
- https://cdn.shopify.com/s/files/1/0432/2131/9839/files/ctm_Vianon_koleda.pdf
- https://cdn.shopify.com/s/files/1/0432/0673/8079/files/2008_ap_calculus_ab_free_response.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00007380.bin18d0093352f41d576c51a0094dd8e492daa0f619494faf510d286040a3ed0441 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x7380 | 5236 bytes |
font_01_sfnt_off00008542.bin3be21cd15aa5355c137fa189067d18c5eb4bbc3fbaace4eed5cdea7d06bd9e49 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x8542 | 10104 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.