MALICIOUS
120
Risk Score
Malware Insights
MITRE ATT&CK
T1566.002 Spearphishing Attachment
T1204.002 Malicious Link
The PDF contains a critical heuristic firing for a malicious redirector link, pointing to 'https://ttraff.cc/wix?keyword=benim+konu%25C5%259Fan+tom+apk+indir+cepde'. This URL is embedded within the document body, disguised as a search result for an APK download. The document also contains a large number of external PDF links, suggesting a link farm for SEO poisoning or traffic redirection. The primary malicious IOC is the redirector URL, which is likely used to lead the user to a malicious site.
Heuristics 3
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://ttraff.cc/wix?keyword=benim+konu%25C5%259Fan+tom+apk+indir+cepde
- https://cdn.shopify.com/s/files/1/0434/2494/0184/files/sample_project_closeout_report_construction.pdf
- https://cdn.shopify.com/s/files/1/0438/6629/2389/files/vexiwubakuzagam.pdf
- https://cdn.shopify.com/s/files/1/0454/2513/1676/files/lafunupikupasepi.pdf
- https://cdn.shopify.com/s/files/1/0460/2075/5615/files/nosuzixotelo.pdf
- https://static.usrfiles.com/ugd/b8c837_910ca1f853d14bbd9914e32619b9fbc3.pdf
- https://static.usrfiles.com/ugd/b8c837_5f8021d585d54564b8246edea1919694.pdf
- https://static.usrfiles.com/ugd/b8c837_cfdc32b0b66e476689a6d2f217995cc9.pdf
- https://static.usrfiles.com/ugd/b8c837_d43c93516a0849f0b9d79c0f08777172.pdf
- https://static.usrfiles.com/ugd/b8c837_b4b2e687be3540d99d19a2a5fd6e3dc3.pdf
- https://static.usrfiles.com/ugd/b8c837_70871d3d0f7e48c7a2680046aef1b088.pdf
- https://static.usrfiles.com/ugd/b8c837_33ed2aa250824ee2b529c83309b153c1.pdf
- https://static.usrfiles.com/ugd/b8c837_dadd785551d54c5bbdd663f2063914f0.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00005948.binadbd882d4fd2d81203194acc0c69137c836b81f63996a0e8243b537ac32f7f71 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x5948 | 5372 bytes |
font_01_sfnt_off00006b6c.bincfc9501df3bc54ed905c1d3b2be3247efc3d757421b976d506547eb3514f44d1 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x6B6C | 11240 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.