MALICIOUS
120
Risk Score
Malware Insights
MITRE ATT&CK
T1566.002 Spearphishing Attachment
T1204.002 Malicious Link
The PDF file contains a heuristic firing for a malicious redirector link, pointing to 'https://ttraff.cc/wix?keyword=tales+from+the+floating+vagabond+pdf'. This URL is likely used to lure the user into downloading further malware or visiting a phishing site. The document also contains a large number of embedded links to Shopify domains, which is flagged as a link farm, potentially for SEO manipulation or to obscure the malicious redirector. The document body contains obfuscated text and the malicious URL.
Heuristics 3
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://ttraff.cc/wix?keyword=tales+from+the+floating+vagabond+pdf
- https://cdn.shopify.com/s/files/1/0437/0409/0777/files/15217613117.pdf
- https://cdn.shopify.com/s/files/1/0430/6822/7737/files/45287305479.pdf
- https://cdn.shopify.com/s/files/1/0428/1332/5471/files/64662705821.pdf
- https://cdn.shopify.com/s/files/1/0437/7729/4498/files/phonics_flashcards_free.pdf
- https://cdn.shopify.com/s/files/1/0431/5499/7402/files/16515885664.pdf
- https://cdn.shopify.com/s/files/1/0439/1731/2168/files/nusisebijoluwen.pdf
- https://cdn.shopify.com/s/files/1/0435/7318/2625/files/inductive_deductive_reasoning.pdf
- https://cdn.shopify.com/s/files/1/0431/7403/5607/files/21891606149.pdf
- https://cdn.shopify.com/s/files/1/0439/8972/9438/files/bise_lahore_9th_class_gazette_2020.pdf
- https://cdn.shopify.com/s/files/1/0438/4748/3552/files/58283058004.pdf
- https://static.usrfiles.com/ugd/77941b_96a237f29209403fb7afb68599002027.pdf
- https://static.usrfiles.com/ugd/70c1f8_1aaa83b3a3af46a1b9bb64d22bbd2f9d.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00006513.bin9d0dcf86ea10d1719ec477296e78d8ca44b994baf893e4860d381c899e92a201 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x6513 | 5604 bytes |
font_01_sfnt_off000077fb.binc8fc6ec1c22de646308fea098ed98e4b0921ab45df6e923bcb4cf3b8aecd1729 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x77FB | 10292 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.