MALICIOUS
120
Risk Score
Malware Insights
MITRE ATT&CK
T1566.002 Spearphishing Attachment
T1204.002 Malicious Link
The PDF file contains a large number of embedded links, many of which point to Shopify domains hosting other PDFs, suggesting a link farm for SEO manipulation. Crucially, one embedded URL, 'https://ttraff.me/wix?keyword=escape+room+answer+level+22', is flagged as a malicious redirector. The document body, though heavily obfuscated, contains this malicious URL and appears to be a lure related to 'escape room answers'. This indicates a social engineering attack aiming to redirect users to malicious infrastructure.
Heuristics 3
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://ttraff.me/wix?keyword=escape+room+answer+level+22
- https://cdn.shopify.com/s/files/1/0463/1858/3973/files/genel_muhasebe_1_vize_sorular.pdf
- https://cdn.shopify.com/s/files/1/0431/2665/3090/files/72476016496.pdf
- https://cdn.shopify.com/s/files/1/0428/9999/6839/files/ssrs_report_builder_iif_expression.pdf
- https://cdn.shopify.com/s/files/1/0435/7275/6648/files/iron_backpack_upgrades.pdf
- https://cdn.shopify.com/s/files/1/0429/4223/4791/files/50355771774.pdf
- https://cdn.shopify.com/s/files/1/0428/1267/0111/files/salt_shaker_classic_wow.pdf
- https://cdn.shopify.com/s/files/1/0428/7224/2342/files/60121720283.pdf
- https://cdn.shopify.com/s/files/1/0435/3612/2008/files/moxamemopoxas.pdf
- https://cdn.shopify.com/s/files/1/0433/1310/2998/files/jurusexe.pdf
- https://static.usrfiles.com/ugd/b8c837_9c2b4949788c4213a65bdd99df67cc4b.pdf
- https://static.usrfiles.com/ugd/b8c837_2514bf244c0642bd965e8c4b80d22643.pdf
- https://static.usrfiles.com/ugd/e3ff21_0d2e37ed384c47cb906912421211fffc.pdf
- https://static.usrfiles.com/ugd/b8c837_feeda288822742148fcb0f58dd7efac9.pdf
- https://static.usrfiles.com/ugd/21e6f2_0341558b01fc415eb3a22f074fda298c.pdf
- https://static.usrfiles.com/ugd/4dd980_133a0eeb5616430c9655a984ee888743.pdf
- https://static.usrfiles.com/ugd/b8c837_79534306ddc0417b8f14e12d062df2a6.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00004a30.bin199e313a8bc1d8a06bbb6d6baa56dbc1a398b7e90aabb696a0582c1971d6d574 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x4A30 | 5320 bytes |
font_01_sfnt_off00005c50.bin6e7530037c5135ae40fb6dc94834ed67847b5b2d522a26d8a5c2e68250cdffed |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x5C50 | 9608 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.