MALICIOUS
120
Risk Score
Malware Insights
MITRE ATT&CK
T1566.002 Spearphishing Attachment
T1204.002 Malicious Link
The PDF file contains multiple embedded links, with one critical heuristic firing indicating a link to a known malicious redirector. The document body, though heavily obfuscated, contains text related to 'Zootopia' and a URL that aligns with the malicious redirector. The presence of a large number of external PDF links, many hosted on static.usrfiles.com, suggests a link farm or SEO poisoning tactic to distribute malicious content.
Heuristics 3
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://ttraff.ru/wix?keyword=zootopia+1080p+izle
- https://static.usrfiles.com/ugd/b8c837_17995a2bf20845c4b2eb9345ba82413d.pdf
- https://static.usrfiles.com/ugd/4d935e_613d575d3d804349b68a52978802e232.pdf
- https://static.usrfiles.com/ugd/41a0b6_7cf70137e2144142b2ac17f9bd592c86.pdf
- https://static.usrfiles.com/ugd/badafb_6a292e2263ca4d43a91b01fb60bf57f9.pdf
- https://static.usrfiles.com/ugd/83b1b3_ed313b77cff9499586b84256bc25cfc7.pdf
- https://cdn.shopify.com/s/files/1/0440/7335/3381/files/ejercicios_numeros_primos_y_compuestos_5_primaria.pdf
- https://cdn.shopify.com/s/files/1/0433/4567/4389/files/avatar_musik_teamobi.pdf
- https://cdn.shopify.com/s/files/1/0435/2563/6248/files/kipewatupog.pdf
- https://cdn.shopify.com/s/files/1/0434/2513/6792/files/plant_biochemistry_notes.pdf
- https://cdn.shopify.com/s/files/1/0440/8462/5558/files/teliva.pdf
- https://static.usrfiles.com/ugd/6846fe_4f419b452dc34b7aa67f502d58dcdf92.pdf
- https://static.usrfiles.com/ugd/0cd3a8_c2877ee5027e456a923464dc5d23f539.pdf
- https://static.usrfiles.com/ugd/5926b4_105bf1555cd943d3a3fd5fb8483e032f.pdf
- https://static.usrfiles.com/ugd/b8c837_e4a94a6ddf6d452cbc41c039b8f8e669.pdf
- https://static.usrfiles.com/ugd/362633_4dd3b93b80394e4ca91d4e9f99552904.pdf
- https://static.usrfiles.com/ugd/e3ed1f_f92217a88313410c93ea02616bb24dea.pdf
- https://static.usrfiles.com/ugd/77d535_4b5f462607354bee9f0a28d761bad8b6.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off000052b8.bin3f980012cc4a2db0e8799c67b52637f08ffa11efa57298fb6b875ed8e2f6d054 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x52B8 | 4932 bytes |
font_01_sfnt_off0000639c.bin307799bd283c1c8002e41b14b6c2fd49068d0526b54cef6c37891bb916e32569 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x639C | 9936 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.