MALICIOUS
120
Risk Score
Malware Insights
MITRE ATT&CK
T1566.002 Spearphishing Attachment
T1204.002 Malicious Link
The PDF contains a critical heuristic firing for a malicious redirector link, specifically pointing to 'ttraff.com'. The document body, though partially corrupted, contains the same URL and a lure related to 'Bella's lullaby piano sheet music free'. This suggests a social engineering tactic to trick users into clicking the malicious link, which is likely part of a link farm designed for SEO poisoning to distribute malware.
Heuristics 3
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://ttraff.com/pify?keyword=bella%2527+s+lullaby+piano+sheet+music+free
- http://files.ahistoryofno.com/uploads/1/3/1/4/131437733/10413.pdf
- http://ledusotez.lakesuperiorsanctuary.org/uploads/1/3/1/4/131453060/wuxowusi_ponilax_fowekadewegi.pdf
- https://cdn.shopify.com/s/files/1/0435/1708/3803/files/39828837580.pdf
- https://cdn.shopify.com/s/files/1/0432/0329/7437/files/68472347084.pdf
- https://cdn.shopify.com/s/files/1/0437/6972/5085/files/calculus_of_variations_by_a_s_gupta.pdf
- https://cdn.shopify.com/s/files/1/0428/4514/3206/files/benjamin_graham_o_investidor_inteligente.pdf
- https://cdn.shopify.com/s/files/1/0428/9835/8432/files/totavari.pdf
- https://cdn.shopify.com/s/files/1/0436/4143/8366/files/95179047880.pdf
- https://cdn.shopify.com/s/files/1/0428/3714/7811/files/93984344257.pdf
- https://cdn.shopify.com/s/files/1/0438/4869/5958/files/divinity_2_face_ripper.pdf
- https://cdn.shopify.com/s/files/1/0431/3497/6157/files/20875879382.pdf
- https://cdn.shopify.com/s/files/1/0440/5841/1158/files/nba_live_97.pdf
- https://cdn.shopify.com/s/files/1/0430/8677/4436/files/nikagozolunegalobeninemi.pdf
- https://cdn.shopify.com/s/files/1/0437/3990/6197/files/panasonic_dv_x_100.pdf
- https://cdn.shopify.com/s/files/1/0427/9212/4572/files/ata_100_chapters_complete_list.pdf
- https://cdn.shopify.com/s/files/1/0433/0687/7080/files/24863128440.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off000069a0.bin3927dac804e125ab93c8c3c99f859c868d1e9dac2b9b34c230816d9e71fb11ea |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x69A0 | 5580 bytes |
font_01_sfnt_off00007c7a.binda6ff80d9e0e7a1ce5a1c236b0cf04924d6a4c1d9e8719bb8f8b9356fac1f7ba |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x7C7A | 15400 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.