MALICIOUS
120
Risk Score
Malware Insights
MITRE ATT&CK
T1566.002 Spearphishing Attachment
T1059.001 PowerShell
The PDF file contains a critical heuristic indicating it links to a known malicious redirector. The document body, though heavily obfuscated, contains text related to 'best desktop computers 2016' and the malicious URL. The file also contains a large number of external PDF links, many hosted on Shopify, suggesting a link farm or SEO poisoning attempt to drive traffic to the malicious redirector.
Heuristics 3
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://ttraff.cc/wix?keyword=best+desktop+computers+2016
- https://cdn.shopify.com/s/files/1/0430/3021/6855/files/zulof.pdf
- https://cdn.shopify.com/s/files/1/0436/6457/2569/files/alchemist_dota_2.pdf
- https://cdn.shopify.com/s/files/1/0432/8118/6971/files/18244438749.pdf
- https://cdn.shopify.com/s/files/1/0430/2117/2897/files/43851705313.pdf
- https://static.usrfiles.com/ugd/b8c837_59576f33e5104edd9ab1cbd62367a1f5.pdf
- https://static.usrfiles.com/ugd/b8c837_1b2ea211f6774780906f6e8b7e9151f7.pdf
- https://static.usrfiles.com/ugd/b8c837_0d7b570e39364345b586ef21a392c2a4.pdf
- https://static.usrfiles.com/ugd/b8c837_f09d60521aa945498fa562463d25a67d.pdf
- https://static.usrfiles.com/ugd/b8c837_bc3117f1577f416aa34490a5af1601f2.pdf
- https://static.usrfiles.com/ugd/b8c837_142d06d0d48648f5ad754cc3745b896f.pdf
- https://static.usrfiles.com/ugd/b8c837_dcb5a92ffbb44ee88f73d57a1dca71aa.pdf
- https://cdn.shopify.com/s/files/1/0429/8529/1937/files/mopipir.pdf
- https://cdn.shopify.com/s/files/1/0434/0806/4677/files/physical_science_grade_10_siyavula_textbook.pdf
- https://cdn.shopify.com/s/files/1/0434/3565/5335/files/jegejedetefego.pdf
- https://cdn.shopify.com/s/files/1/0433/2758/6472/files/vapedugorelorowudo.pdf
- https://cdn.shopify.com/s/files/1/0433/6379/5096/files/fundamentos_de_metodologia_cientfica_lakatos.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000734c.bin6d49441a5cbcb1cd0c5a018e316eb83ee3dda978a54d5d35ce00ab0cce40a09c |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x734C | 5568 bytes |
font_01_sfnt_off00008637.bin4fef27422905196d545354f5d110119e6bb0cfd356d633bb5a9d9157c07805a1 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x8637 | 10512 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.