Malware Insights
The PDF contains a critical heuristic firing for a malicious redirector link, pointing to 'https://ttraff.me/wix?keyword=anderson+county+detention+center+clinton+tn'. Additionally, another critical heuristic indicates a PDF link farm, with the first URL being 'https://1a8cb9ba-da36-4a69-86a4-14be0fd86702.filesusr.com/ugd/9d869b_90e1b64c70cf44dbbd3007db56b9cfd5.pdf?index=true'. The document body, though heavily obfuscated, also contains these URLs, reinforcing the malicious intent. The presence of a callback lure heuristic further suggests a phishing or scam context.
Heuristics 4
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Callback phishing phone lure medium SE_CALLBACK_LUREDocument asks the user to call a phone number in billing, refund, subscription, fraud, or security context — consistent with callback phishing or tech-support scam patterns
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://ttraff.me/wix?keyword=anderson+county+detention+center+clinton+tn
- http://simek.stjohnsmag.com/uploads/1/3/1/0/131070450/4493119.pdf
- http://rezodapeb.bellaspeechsensoryworldinc.com/uploads/1/3/0/7/130775455/21fa216e5b6.pdf
- http://files.judiculbertson.net/uploads/1/3/0/7/130740017/mozapabebiw_femunu_fekamibovijelig_pigigurob.pdf
- http://files.wobcffl.com/uploads/1/3/2/6/132681295/43296896a5.pdf
- https://1a8cb9ba-da36-4a69-86a4-14be0fd86702.filesusr.com/ugd/9d869b_90e1b64c70cf44dbbd3007db56b9cfd5.pdf?index=true
- https://d0af2e0d-e4dd-4e87-8c5a-7f810eda9133.filesusr.com/ugd/49be48_35020b2b8064462e9b22b11af6c229f3.pdf?index=true
- https://9199dbb9-139f-4f39-a0d7-03685820eac5.filesusr.com/ugd/70c1ec_dc6c56f3b79f4c10b317574c2d7161aa.pdf?index=true
- https://4d6b012e-b16d-41c9-8a5b-04ad369c5862.filesusr.com/ugd/4fea5c_4bed2ea4c9354acaba240713ad3d2d78.pdf?index=true
- https://1f298257-c138-4efe-90b2-ba3282424c11.filesusr.com/ugd/f0b6b3_f65998abce784663bc9f0b301872af78.pdf?index=true
- https://a6924d86-a752-46d7-98ec-9538ced8b26e.filesusr.com/ugd/2ac701_9fd74e86f1ca4b9d98b9af047b37f805.pdf?index=true
- https://30a7ecc5-52b5-4616-bdce-43521febf612.filesusr.com/ugd/d90490_e19472322ca44425be4e1dc1f5f473ea.pdf?index=true
- https://8927e9e6-a05c-408b-92fd-e469fb3e9630.filesusr.com/ugd/370ea2_b75b5b0212ab44979365234ac9569f88.pdf?index=true
- https://1743fb3b-aeb4-49c0-aa69-e7f6e4823a36.filesusr.com/ugd/bca722_b67d6f8ed32c43f5a1174822e45cb311.pdf?index=true
- https://2b8e1504-cc84-4a94-acf5-835e6c3aba84.filesusr.com/ugd/1b9faa_0b4f9f007dcd4cb4998de52f7040119b.pdf?index=true
- https://e6db0a3d-7b7a-41f8-83de-c11dde99efc7.filesusr.com/ugd/5a1791_73654d5b416a44ea88b766308d6cbffd.pdf?index=true
- https://9a3ea4c1-6103-47ac-8897-995125d966b6.filesusr.com/ugd/2ca22b_bc3068596c0e4916ae753cd6c737eb5e.pdf?index=true
- https://54421929-35da-4e7c-890c-55a460f49b62.filesusr.com/ugd/9bd82e_139655deab9e4741b016f43d47aebc1a.pdf?index=true
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- https://9a3ea4c1-6103-47ac-8897-995125d966b6.filesusr.com/ugd/2ca22b_bc3068596c0e4916ae753cd
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00006afa.binf93c5e8ec5b9cddee5473e0a4aa587a5a3bf0762d14e2591df4ca29de104b723 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x6AFA | 4816 bytes |
font_01_sfnt_off00007b74.bin8be143a4821dcc544a61877a9fa317df369a7708a198b92786d46e6785cce85b |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x7B74 | 10456 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.