MALICIOUS
120
Risk Score
Malware Insights
MITRE ATT&CK
T1566.002 Spearphishing Attachment
T1204.002 Malicious Link
The PDF file contains a large number of embedded links, many of which point to external PDF files hosted on various domains. One critical heuristic identified a link to a known malicious redirector, 'https://ttraff.cc/pify?keyword=adpcm+file+format'. This suggests the document is designed to lure users into clicking these links, potentially leading to further compromise. The presence of a link farm and a malicious redirector indicates a social engineering attack aimed at driving traffic to malicious infrastructure.
Heuristics 3
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://ttraff.cc/pify?keyword=adpcm+file+format
- http://zejukusi.weddingplansnicosia.com/uploads/1/3/1/1/131164250/2954888.pdf
- http://files.anglemidwest.com/uploads/1/3/2/8/132815019/80a593a.pdf
- http://files.alertdriving.co.nz/uploads/1/3/0/7/130775633/8799309.pdf
- http://files.dancelabnicosia.com/uploads/1/3/2/6/132681694/zepikisuj.pdf
- https://cdn.shopify.com/s/files/1/0429/9633/4753/files/isotopes_worksheet_answers.pdf
- https://cdn.shopify.com/s/files/1/0429/9508/9559/files/mastering_algorithms_in_c.pdf
- https://cdn.shopify.com/s/files/1/0429/7634/6266/files/58312084279.pdf
- https://cdn.shopify.com/s/files/1/0434/0737/6534/files/xobodubezoj.pdf
- https://cdn.shopify.com/s/files/1/0432/1427/4720/files/43038454987.pdf
- https://cdn.shopify.com/s/files/1/0435/3458/1911/files/20486185264.pdf
- https://cdn.shopify.com/s/files/1/0436/3649/0398/files/applications_of_laser_in_engineering.pdf
- https://cdn.shopify.com/s/files/1/0433/8673/2707/files/gitumijupizifujewetodete.pdf
- https://cdn.shopify.com/s/files/1/0432/7692/7141/files/feromarimozoruwizaguwu.pdf
- https://cdn.shopify.com/s/files/1/0432/6660/5209/files/zazebobaliku.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00009492.bin988b0ad72d8ca58f4f2e9b6b33bd96ab5c78a26634a53d3079f88a15974bc978 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x9492 | 5112 bytes |
font_01_sfnt_off0000a5d8.bin81bc5fd00be5f1beb371f4db2893dcb4902e00cde37923af1f4bf399f742a687 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xA5D8 | 11024 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.