MALICIOUS
120
Risk Score
Malware Insights
MITRE ATT&CK
T1566.002 Spearphishing Attachment
T1059.001 PowerShell
The PDF contains a link to a known malicious redirector, ttraff.com, which is disguised as a search result for 'Utorrent movies sites quora'. The document also contains a large number of embedded links to static.usrfiles.com, likely part of a link farm to improve search engine ranking for malicious content. No scripts were extracted, and the document body was heavily obfuscated, limiting further analysis of the exact payload.
Heuristics 3
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://ttraff.com/pify?keyword=utorrent+movies++sites+quora
- https://static.usrfiles.com/ugd/7198c1_612d7dc66ccd4b4ab22ff8228d9a6701.pdf
- https://static.usrfiles.com/ugd/b8c837_c69011b469df45fc8f67f5be9037acaf.pdf
- https://static.usrfiles.com/ugd/0d9a50_9a466718e29248d598ead7fc5d715132.pdf
- https://static.usrfiles.com/ugd/d4da64_815eccccb8604c9696764f99377a78b3.pdf
- https://static.usrfiles.com/ugd/191a6d_808a01cd980149238cb94b4becbeacb0.pdf
- https://static.usrfiles.com/ugd/87d215_34e2a6447ef849fc8bc05df332756a30.pdf
- https://static.usrfiles.com/ugd/409ca8_cd14439a370747be8ba3d48a9d63ffef.pdf
- https://static.usrfiles.com/ugd/8e1900_9c5a2bfb09404b36bd6f2320a95af8fc.pdf
- https://static.usrfiles.com/ugd/930050_c0e9978ae6ed4e96bd545116f488fc32.pdf
- https://static.usrfiles.com/ugd/1e32c2_5a65c85ffd894e2ea8b20a2de91779cd.pdf
- https://static.usrfiles.com/ugd/f1780b_cd81a8d436bd442692430e17bd16a586.pdf
- https://static.usrfiles.com/ugd/f0f215_3ad44f19b371438b898f92b789f6b3df.pdf
- https://static.usrfiles.com/ugd/b8c837_7430bd5b64ba4af181249ef819609fc0.pdf
- https://static.usrfiles.com/ugd/20d83a_c1f9cafc3f0645db891f7ab9f10631ab.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00009aa8.binee00d63c593e1718975b91229effc8f3f9eab73fab7112b0d0fd8003464e341a |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x9AA8 | 4976 bytes |
font_01_sfnt_off0000ab87.bin32884439c1307179eceda7befdc6336232ac46707a9c1b7ebdeb44eaa4a55230 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xAB87 | 10624 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.