MALICIOUS
160
Risk Score
Malware Insights
MITRE ATT&CK
T1566.002 Spearphishing Attachment
T1059.001 PowerShell
The PDF contains a mass of external links, many of which point to a redirector URL, indicating a link farm designed to obscure the final destination. The document body, though heavily obfuscated, contains a URL that appears to be part of a lure for an advance-fee scam, specifically referencing 'crosswords and pics answers'. The presence of numerous PDF links and a malicious redirector suggests an attempt to drive traffic to potentially malicious content or phishing sites.
Heuristics 4
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Advance-fee lottery/parcel scam lure high SE_ADVANCE_FEE_SCAM_LUREDocument contains lottery/beneficiary or prize language together with large-value draft/funds wording and parcel/courier delivery requirements. This is a classic advance-fee fraud document shape.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://ttraff.cc/wb?keyword=crosswords%20and%20pics%20answers%20in%20the%20answerbank
- https://251dd6d0-d664-4d81-a362-bd7aa1ad01d4.filesusr.com/ugd/8a4248_698d1b218cd24e64ae14c7b8a42724bd.pdf?index=true
- https://7cb8d2e8-c737-47ea-8f43-5e891e0e3916.filesusr.com/ugd/09c3c7_c69eee5d4da1457fb2a1c32d3388b038.pdf?index=true
- https://73fc5ee3-3945-4c10-8135-d990b56a8cc3.filesusr.com/ugd/70e7d4_0531b1b9eda746bb99ffc799bc5cf86c.pdf?index=true
- https://d81432f3-da4a-4296-b9e5-8a40197172c8.filesusr.com/ugd/1e8759_0bf414c1e65547c5af55a8cc1068f240.pdf?index=true
- https://ca3c3080-12ef-4d33-a806-e11907da62e8.filesusr.com/ugd/9d7ad9_5791eaf9d4df4438859b3323ff69a657.pdf?index=true
- https://128a29b3-5b4b-41a4-8b99-a4ae18c3ff01.filesusr.com/ugd/917232_f7a7841c333340d0982c1b7a1b841101.pdf?index=true
- https://916c4c9c-ecc9-411e-be04-2af964ab56c3.filesusr.com/ugd/451a43_3e9b5248d60a448c9a1799ee58e918f9.pdf?index=true
- https://eb3eb498-6035-49b2-aed9-0107cae295b9.filesusr.com/ugd/8b2c09_51d10005019f4ec99c55e36faa6906ff.pdf?index=true
- https://a4a1b02b-14c6-4094-9ce8-75a2930fcf3e.filesusr.com/ugd/4dbf3f_104833a6ceff47a783f0644ea2070824.pdf?index=true
- https://bab3394d-c630-43d3-a77c-8284b0462111.filesusr.com/ugd/c88839_c3d1259cb0444aab968965d706532908.pdf?index=true
- https://b251f0b5-8635-4460-8fae-7737eaa697f7.filesusr.com/ugd/e33828_dc48c43c108a40e78d37e67f4f8a3a82.pdf?index=true
- https://c8440812-399e-41de-8b17-0f37feca38ee.filesusr.com/ugd/48bf55_c07eda8fdccb4062aa3a491ccc68db22.pdf?index=true
- https://d37c8c7d-87c0-463f-b0c1-c5eeb145268c.filesusr.com/ugd/1e52da_a86036318c3f4d59938ff92a3862b9e5.pdf?index=true
- https://b5d16fe2-a9e6-4d1a-a936-bfee557f16e9.filesusr.com/ugd/7836c9_810e46e231f3426eaa935d7102581972.pdf?index=true
- https://c6766b61-d1eb-4f83-9c40-7b0ed4568102.filesusr.com/ugd/a382ee_4b4cba851ab149ea8e655ca325442c64.pdf?index=true
- https://f21cce68-2462-40f4-8ad2-aef064580a79.filesusr.com/ugd/f46427_91dc7f96a3414f57873da424951e2775.pdf?index=true
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00016ca6.bindf682882df8c59cb4a2b914fb61edc25ec5deadc7ecb98738b59091629eaf743 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x16CA6 | 5328 bytes |
font_01_sfnt_off00017ec8.binb363630878809c186e14b21c370625ff8b6f022778b5528e8da92820f33b45cd |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x17EC8 | 15480 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.