MALICIOUS
120
Risk Score
Malware Insights
MITRE ATT&CK
T1566.002 Spearphishing Attachment
T1059.001 PowerShell
The PDF file contains a critical heuristic firing for a malicious redirector link, pointing to 'https://ttraff.me/wix?keyword=bosch+guide+rail+system'. Additionally, it exhibits characteristics of a PDF SEO link farm, with numerous external links, including one to 'https://cdn.shopify.com/s/files/1/0432/1440/5793/files/personal_finance_tracker_template.pdf'. The document body, though heavily obfuscated, contains references to these URLs, suggesting an attempt to trick users into clicking through to malicious infrastructure.
Heuristics 3
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://ttraff.me/wix?keyword=bosch+guide+rail+system
- https://cdn.shopify.com/s/files/1/0432/1440/5793/files/personal_finance_tracker_template.pdf
- https://cdn.shopify.com/s/files/1/0432/5625/0525/files/32275506292.pdf
- https://cdn.shopify.com/s/files/1/0432/2118/8763/files/capital_letters_and_small_letters.pdf
- https://cdn.shopify.com/s/files/1/0429/8188/4067/files/rivotetebavawexix.pdf
- https://cdn.shopify.com/s/files/1/0431/0410/8711/files/beneliduvuwejuvale.pdf
- https://cdn.shopify.com/s/files/1/0440/3943/8486/files/56734693028.pdf
- https://cdn.shopify.com/s/files/1/0429/4665/8463/files/carbon_footprint_of_electric_vehicle_vs_gas.pdf
- https://adcd8694-2803-40af-b108-9d34f2c2dea3.filesusr.com/ugd/a771bd_6b25884310c0450794d04e6345cd3a64.pdf?index=true
- https://6150d36c-6ec5-48f9-b335-a7be464bcf9d.filesusr.com/ugd/696117_b1609a2db5314a87bd2552a78d58d7ed.pdf?index=true
- https://cdn.shopify.com/s/files/1/0434/6707/9830/files/minecraft_fallout_texture_pack.pdf
- https://cdn.shopify.com/s/files/1/0434/3093/6733/files/outlook_for_mac_latest_version.pdf
- https://cdn.shopify.com/s/files/1/0431/4546/1909/files/guardian_rank_borderlands_3.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00004448.bin6440d9f1d6209bd128fd480fb070d3ef71116a9e523f8e66efaa4b25b015b759 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x4448 | 5504 bytes |
font_01_sfnt_off000056e2.binf611f83822f0898b57ff10b7fbe771f571595328676716ee261654d189eed0a2 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x56E2 | 9796 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.