MALICIOUS
120
Risk Score
Malware Insights
MITRE ATT&CK
T1566.002 Spearphishing Attachment
T1059.001 PowerShell
The PDF file contains embedded links that point to a known malicious redirector infrastructure. The document body, though heavily obfuscated, contains a URL that appears to be the same as the one identified by the heuristic. This suggests the document's primary purpose is to redirect the user to a malicious site, likely for further exploitation or phishing.
Heuristics 3
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://ttraff.ru/wix?keyword=atv312+user+manual
- https://static.usrfiles.com/ugd/b8c837_ac3a5eb38d6e415b821e0b443141cc46.pdf
- https://static.usrfiles.com/ugd/29c71c_241d8d3d660042949dd269c024dc3a9d.pdf
- https://static.usrfiles.com/ugd/4c1554_e6d1f9f4504e4dc29226d42008ab3d99.pdf
- https://static.usrfiles.com/ugd/b8bbd7_aed3333184a64ee790218245f0a52010.pdf
- https://static.usrfiles.com/ugd/ce5d00_96262a8c7ceb4f23a4d3e814fe39bc47.pdf
- https://static.usrfiles.com/ugd/07625c_716a686122f8450491f353f0b5cf84b3.pdf
- https://static.usrfiles.com/ugd/b8c837_192c92c0d559484dac893d6c930670a3.pdf
- https://static.usrfiles.com/ugd/b8c837_5f8358369e3c4c76b7e1d3a4c201b95e.pdf
- https://cdn.shopify.com/s/files/1/0439/5335/6955/files/46523667919.pdf
- https://cdn.shopify.com/s/files/1/0429/8365/3527/files/barometer_aneroid.pdf
- https://static.usrfiles.com/ugd/409ca8_29bec79ca87840b98f72b302f1972eaf.pdf
- https://static.usrfiles.com/ugd/b8c837_03e7ce6df96048598ab3c47108988558.pdf
- https://static.usrfiles.com/ugd/6846fe_f356582b4a6f42438eb9ea8fa227e00a.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00016f3a.bin59dd4aa5906dfd596538f54da8b4ddffd7bc4479d865710fb8d6d5b36e929bf6 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x16F3A | 5228 bytes |
font_01_sfnt_off000180f9.bine560899b5b363423fb555b68aad49ea483d5756f0eb8a7957be1e19aa7648747 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x180F9 | 17580 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.