MALICIOUS
168
Risk Score
Malware Insights
MITRE ATT&CK
T1566.002 Spearphishing Attachment
T1059.001 PowerShell
The PDF contains a critical heuristic firing for a malicious redirector link pointing to 'https://ttraff.ru/wix?keyword=basara+4+pc+single+link'. Additionally, it exhibits characteristics of an advance-fee scam lure, mentioning lottery/prize language and parcel delivery requirements. The document also functions as a link farm, with 22 external PDF links, many hosted on Shopify. No scripts were extracted, but the presence of a malicious redirector and the advance-fee scam lure strongly suggest a phishing or social engineering attack.
Heuristics 5
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Advance-fee lottery/parcel scam lure high SE_ADVANCE_FEE_SCAM_LUREDocument contains lottery/beneficiary or prize language together with large-value draft/funds wording and parcel/courier delivery requirements. This is a classic advance-fee fraud document shape.
-
Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTONDocument contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://ttraff.ru/wix?keyword=basara+4+pc+single+link
- https://cdn.shopify.com/s/files/1/0431/8658/5749/files/fivilelimarowonakez.pdf
- https://cdn.shopify.com/s/files/1/0435/8828/8670/files/ranesaxomenavopusilume.pdf
- https://cdn.shopify.com/s/files/1/0432/1627/3563/files/xopanoxowuforobejogan.pdf
- https://static.usrfiles.com/ugd/b8c837_f5c39ae288aa48338b4977a89dcd2e02.pdf
- https://cdn.shopify.com/s/files/1/0435/9903/6579/files/14551354037.pdf
- https://cdn.shopify.com/s/files/1/0434/4938/5126/files/connotation_and_denotation_lesson_plan.pdf
- https://cdn.shopify.com/s/files/1/0461/7230/7609/files/parulez.pdf
- https://cdn.shopify.com/s/files/1/0435/3458/1919/files/namuvigomikujelitagase.pdf
- https://cdn.shopify.com/s/files/1/0430/1383/2857/files/ways_of_seeing_book.pdf
- https://cdn.shopify.com/s/files/1/0428/4504/4892/files/bosejosepuzisivobiz.pdf
- https://cdn.shopify.com/s/files/1/0428/6477/1238/files/gelman_bayesian_data_analysis_pdf_download.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Extracted artifacts 4
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000e929.bin6e9bf3c0ee5d43a449f71e353b2177c5caf6a9cb4ed7ac222dc037a4ff065c06 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xE929 | 7192 bytes |
font_01_sfnt_off00010175.bin3c341969a2ea6e87a99f20bf0402c1aa5c988421fc750a0fd376d9c0d3b15191 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x10175 | 5300 bytes |
font_02_sfnt_off0001138a.binb402f97091250255da6c700f26eed4d55fcd2c3d63a56849eede349192be51ac |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x1138A | 8572 bytes |
font_03_sfnt_off00012b58.binfe94bc4045b4583ea9a7f9b64f8c30700d966057145d58ff32ec034bd58d6fd5 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x12B58 | 10668 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.