MALICIOUS
120
Risk Score
Malware Insights
MITRE ATT&CK
T1566.002 Spearphishing Attachment
T1204.002 Malicious Link
The PDF file contains a critical heuristic firing for a malicious redirector link, pointing to 'https://ttraff.cc/wix?keyword=blockchain+basics+a+non+technical+in'. It also exhibits characteristics of a PDF link farm, with numerous external links, many hosted on cdn.shopify.com. The document body, though heavily obfuscated, contains the same malicious URL and references to 'blockchain basics', suggesting a social engineering lure to drive clicks to malicious infrastructure.
Heuristics 3
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://ttraff.cc/wix?keyword=blockchain+basics+a+non+technical+in
- https://cdn.shopify.com/s/files/1/0434/7500/9686/files/bobukudekexotelavuv.pdf
- https://cdn.shopify.com/s/files/1/0437/0723/6503/files/statistical_digital_signal_processing_and_modeling.pdf
- https://cdn.shopify.com/s/files/1/0429/7018/5879/files/wallpaper_the_last_of_us.pdf
- https://cdn.shopify.com/s/files/1/0431/3799/0818/files/widipeguvasalekodoj.pdf
- https://cdn.shopify.com/s/files/1/0431/8212/9320/files/hungry_shark_evo_mod_apk_revdl.pdf
- https://cdn.shopify.com/s/files/1/0430/7956/5465/files/eyebrow_raised_emoticon.pdf
- https://cdn.shopify.com/s/files/1/0431/1007/2481/files/61688903316.pdf
- https://cdn.shopify.com/s/files/1/0468/9883/9714/files/livro_augusto_cury_voc__insubstituvel.pdf
- https://cdn.shopify.com/s/files/1/0432/0873/6928/files/arabian_nights_book_of_tales.pdf
- https://static.usrfiles.com/ugd/b8c837_236f357a6a844886b6b9d1d0f9d061e1.pdf
- https://static.usrfiles.com/ugd/77941b_d7b7e5cd03d14c93a5a3df21cae6237d.pdf
- https://cdn.shopify.com/s/files/1/0434/5010/6018/files/fanukixelaxu.pdf
- https://cdn.shopify.com/s/files/1/0440/8960/6294/files/tunok.pdf
- https://cdn.shopify.com/s/files/1/0434/7589/4422/files/pojebujixim.pdf
- https://cdn.shopify.com/s/files/1/0436/6571/9449/files/sefikulepejenusipub.pdf
- https://cdn.shopify.com/s/files/1/0436/1709/1744/files/najojatusefanajemon.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00005389.bin9441f71dc2d9732b64686ca1015ba843a01b5c7174c2eb8eeb2fd2b601b0858d |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x5389 | 5044 bytes |
font_01_sfnt_off0000649d.bind159a9dc7b8bafa1c4fc638ea3a756ea58ae217c46dafd87c5428ac95b8e1129 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x649D | 9944 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.