MALICIOUS
120
Risk Score
Malware Insights
MITRE ATT&CK
T1566.002 Spearphishing Attachment
T1059.001 PowerShell
The PDF file contains numerous embedded links, with a critical heuristic firing indicating a malicious redirector. One of the primary URLs, 'https://ttraff.club/wix?keyword=abeja+haragana+imagenes', is flagged as malicious. The document body, though heavily obfuscated, contains this URL and other links pointing to external PDF files, suggesting a link farm or redirection scheme. No scripts were extracted, but the PDF structure and embedded links strongly indicate a malicious redirection attempt.
Heuristics 3
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://ttraff.club/wix?keyword=abeja+haragana+imagenes
- https://static.usrfiles.com/ugd/9219f8_11205179d4fd436587877c44478b7cf8.pdf
- https://static.usrfiles.com/ugd/b8c837_c44f3fd8d7484c5a90e2b946249492ac.pdf
- https://static.usrfiles.com/ugd/756799_c10f1c98e9264d1eab9856573e6ccc4f.pdf
- https://static.usrfiles.com/ugd/4b7290_f99dba5c66b7442d9469c09c907e94e4.pdf
- https://cdn.shopify.com/s/files/1/0438/9833/9496/files/47589145623.pdf
- https://cdn.shopify.com/s/files/1/0432/7243/7910/files/48503576004.pdf
- https://cdn.shopify.com/s/files/1/0432/5172/8546/files/4665177819.pdf
- https://cdn.shopify.com/s/files/1/0440/5297/1685/files/pdf_converter_command_line.pdf
- https://cdn.shopify.com/s/files/1/0434/0465/6790/files/92912528614.pdf
- https://cdn.shopify.com/s/files/1/0429/5111/4908/files/best_psp_games.pdf
- https://cdn.shopify.com/s/files/1/0433/3341/9160/files/20389753066.pdf
- https://cdn.shopify.com/s/files/1/0429/8833/9354/files/10978823387.pdf
- https://cdn.shopify.com/s/files/1/0431/1931/3053/files/cerfa_2020_rici.pdf
- https://cdn.shopify.com/s/files/1/0433/1339/7924/files/lubosawulojo.pdf
- https://cdn.shopify.com/s/files/1/0431/6879/2733/files/619149609.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off000060ac.binab204741f8674327f93380bf8a533c5d2707f3fd9842527c6767dc17d1ca963d |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x60AC | 5272 bytes |
font_01_sfnt_off00007272.binf2749c8199746ddead91bde52d87002978dc32206f3c74426da307a046bee27a |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x7272 | 9804 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.