MALICIOUS
120
Risk Score
Malware Insights
MITRE ATT&CK
T1566.002 Spearphishing Attachment
T1059.001 PowerShell
The PDF contains a malicious redirector link that, when clicked, leads to a URL designed to appear as a search result for 'strength of materials objective type questions pdf'. This URL is a known malicious redirector. The PDF also contains a large number of external links, many hosted on Shopify, which is indicative of a link farm used for SEO poisoning or to obscure the final malicious destination. No scripts were extracted from this sample.
Heuristics 3
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://ttraff.cc/pify?keyword=strength+of+materials+objective+type+questions+pdf
- http://puzanijo.theoutstandingguides.com/uploads/1/3/0/7/130776031/c84c3d9.pdf
- http://files.gowersartclass.com/uploads/1/3/1/3/131380687/diroxewulemixom_mopoke.pdf
- http://files.destinationdesignreunion.com/uploads/1/3/1/3/131379540/5c3f34c.pdf
- http://files.twiceheroes.com/uploads/1/3/0/7/130775310/9187f3962.pdf
- http://xavob.cayugalakehouse.net/uploads/1/3/1/1/131164312/91ee0543.pdf
- https://cdn.shopify.com/s/files/1/0431/7147/9713/files/jupijimefunokalonox.pdf
- https://cdn.shopify.com/s/files/1/0438/5207/1074/files/12579637025.pdf
- https://cdn.shopify.com/s/files/1/0428/8544/7833/files/31037463446.pdf
- https://cdn.shopify.com/s/files/1/0435/8730/5629/files/wegekiji.pdf
- https://cdn.shopify.com/s/files/1/0437/8794/4096/files/relao_entre_sade_e_meio_ambiente.pdf
- https://cdn.shopify.com/s/files/1/0439/3231/9899/files/scp_containment_breach_nine_tailed_fox_mod.pdf
- https://cdn.shopify.com/s/files/1/0432/4042/3592/files/pulse_width_modulation_principle.pdf
- https://cdn.shopify.com/s/files/1/0428/4012/9692/files/92836110380.pdf
- https://cdn.shopify.com/s/files/1/0437/6385/9617/files/minecraft_save_command.pdf
- https://cdn.shopify.com/s/files/1/0428/9835/8432/files/69440205977.pdf
- https://cdn.shopify.com/s/files/1/0429/7241/4106/files/10276139727.pdf
- https://cdn.shopify.com/s/files/1/0433/0687/7080/files/93867881616.pdf
- https://cdn.shopify.com/s/files/1/0433/7329/7822/files/rivezola.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000a37b.bin25ff0b48c1a15a7ad4371a0336a29143c6d4dba2b385cd189a761404b1765374 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xA37B | 6176 bytes |
font_01_sfnt_off0000b85d.bin0b026a4186e4fb03492e824633b253a3dd398f63ed2bb3ac7b3f5044c28bd97e |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xB85D | 10540 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.