MALICIOUS
120
Risk Score
Malware Insights
MITRE ATT&CK
T1566.002 Spearphishing Attachment
T1204.002 Malicious Link
The PDF contains a link that redirects to a malicious URL, disguised as a user guide. The PDF also contains a large number of external links, many of which point to the same domain, suggesting a link farm or redirection strategy. No scripts were extracted, but the primary attack vector is the malicious link embedded within the document.
Heuristics 3
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://ttraff.cc/wix?keyword=bmc+remedy+user+guide
- https://static.usrfiles.com/ugd/b8c837_fcf3dfdbe8d142f7a2f21ac2f973041f.pdf
- https://static.usrfiles.com/ugd/51c472_c38d51f8d6c84056bf5134555c39b26e.pdf
- https://static.usrfiles.com/ugd/69b86f_c1f64770681148c181c00563fa0e4137.pdf
- https://static.usrfiles.com/ugd/b8c837_85a02cd4e13f44c7a75ca7189ebe6650.pdf
- https://static.usrfiles.com/ugd/b8c837_eeeec7059f2c46c69f5ad0e5a6696a2e.pdf
- https://static.usrfiles.com/ugd/158fb9_7f143c3dfaeb472994b0b8691e4d9601.pdf
- https://static.usrfiles.com/ugd/1c8c6c_b90001813d6a4c04b8e0656f02bfeb6f.pdf
- https://static.usrfiles.com/ugd/cf14a4_e62e8d7f10fe46788e13574747f128a9.pdf
- https://static.usrfiles.com/ugd/63d3ad_6030c6acf7d2420d829e0565442e0420.pdf
- https://static.usrfiles.com/ugd/b98abb_e9c18d81ab5f4fef8e2d9dc203ff7705.pdf
- https://static.usrfiles.com/ugd/79cb75_6640339f2795445cab363ef33e59b52f.pdf
- https://static.usrfiles.com/ugd/b8c837_a298b9fff0e5401a90c99f4ffc6a79e5.pdf
- https://cdn.shopify.com/s/files/1/0433/8457/0019/files/looping_through_excel_sheets_in_vba.pdf
- https://cdn.shopify.com/s/files/1/0433/1339/7924/files/vixujidijakiriv.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off000053e3.bin8c745ea4c69961ff051345171c58fedfd2a5e7c7bfbd1a99934271a3e3d25e1a |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x53E3 | 5168 bytes |
font_01_sfnt_off00006568.bin89ad2e97c2c6b71a4f2349175626a9d16f1c6313811e75144d04967296692f4b |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x6568 | 10456 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.