MALICIOUS
120
Risk Score
Malware Insights
MITRE ATT&CK
T1566.002 Spearphishing Attachment
T1059.001 PowerShell
The PDF file contains a heuristic firing for a malicious redirector link, pointing to 'https://ttraff.cc/wix?keyword=time+to+beat+hollow+knight'. This indicates an attempt to direct the user to a malicious site. The document body also contains this URL, reinforcing the lure. The presence of numerous external PDF links, while many are benign, suggests a link farm tactic, potentially to obscure the malicious destination.
Heuristics 3
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://ttraff.cc/wix?keyword=time+to+beat+hollow+knight
- https://static.usrfiles.com/ugd/b8c837_d9843def85c248e6a25c0dfb447b3b62.pdf
- https://static.usrfiles.com/ugd/b8c837_f0b5ff1970514d519f44d030132db0d9.pdf
- https://static.usrfiles.com/ugd/b8c837_fca9b70c27e743ee82280ac60cf0ac31.pdf
- https://static.usrfiles.com/ugd/b8c837_cdb8c915d5d04509a775216ffb8b7c2c.pdf
- https://cdn.shopify.com/s/files/1/0437/2067/1400/files/55878277212.pdf
- https://cdn.shopify.com/s/files/1/0439/8609/2190/files/bioplasticos_en_mexico.pdf
- https://cdn.shopify.com/s/files/1/0435/9425/2456/files/treatment_of_epilepsy_in_childhood_pdf.pdf
- https://cdn.shopify.com/s/files/1/0428/8797/0975/files/86914968919.pdf
- https://cdn.shopify.com/s/files/1/0432/4737/0402/files/kulegavu.pdf
- https://static.usrfiles.com/ugd/5cf23b_33be10b414c548f8be31123eb1c782a1.pdf
- https://static.usrfiles.com/ugd/10b11f_17a209bf0e3a45bd9b0fb0015ed09a0c.pdf
- https://static.usrfiles.com/ugd/b8c837_48d56d99f5db44099dd19650b14b9f03.pdf
- https://static.usrfiles.com/ugd/735189_264a5a96340d444b8ee908ace58aa696.pdf
- https://static.usrfiles.com/ugd/4b7290_f143fef187d841c892187f014c0a9740.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Extracted artifacts 3
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000916d.bine7dc8966f08500f6b8d41ee46874273642017a87da091c7acfd4e62aa5253b08 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x916D | 4860 bytes |
font_01_sfnt_off0000a1db.bine9cfd96d5f66ed2c8184acbdbeef8f68ceef6bd85e7d23eff83c887a6a20b63f |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xA1DB | 10360 bytes |
font_02_sfnt_off0000c54e.bin4fcfa7c68d76e23b667942a3ac892d2d5d88346478daafc61479ad4df4af3dd3 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xC54E | 4324 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.