MALICIOUS
120
Risk Score
Malware Insights
MITRE ATT&CK
T1566.002 Spearphishing Attachment
T1059.001 PowerShell
T1204.002 Malicious Link
The PDF contains a link farm with multiple embedded URLs, including a critical redirector link to ttraff.ru. The document body, though heavily obfuscated, contains the same malicious URL, suggesting a lure to a malicious site. The presence of numerous links, many pointing to benign Shopify files, indicates an attempt to manipulate search engine results or distribute malicious content through a seemingly legitimate platform. No scripts were extracted, but the primary attack vector appears to be social engineering via a malicious link.
Heuristics 3
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://ttraff.ru/pify?keyword=certificate+of+participation+template+publisher
- http://files.education4fun.net/uploads/1/3/1/4/131438423/lugelizufedap_sezogibidubez_tukabuj.pdf
- http://files.windowsofatlanta.com/uploads/1/3/1/3/131398177/sisomim_pipixexiki_rokalipuk.pdf
- https://cdn.shopify.com/s/files/1/0436/9353/9478/files/81232105262.pdf
- https://cdn.shopify.com/s/files/1/0436/1817/3086/files/56098971062.pdf
- https://cdn.shopify.com/s/files/1/0449/1480/2855/files/colouring_sheets_animals_hard.pdf
- https://cdn.shopify.com/s/files/1/0432/1778/0896/files/4709146513.pdf
- https://cdn.shopify.com/s/files/1/0434/3152/6557/files/zezijal.pdf
- https://cdn.shopify.com/s/files/1/0432/3550/8381/files/14500205720.pdf
- https://cdn.shopify.com/s/files/1/0431/0709/0581/files/theory_of_automata_mcqs_with_answers_free_download.pdf
- https://cdn.shopify.com/s/files/1/0435/0102/7493/files/welanoguwajozowo.pdf
- https://cdn.shopify.com/s/files/1/0438/3804/6365/files/21143649305.pdf
- https://cdn.shopify.com/s/files/1/0429/6628/6490/files/kevexekaw.pdf
- https://cdn.shopify.com/s/files/1/0434/7055/3250/files/xekizarekuwaviz.pdf
- https://cdn.shopify.com/s/files/1/0430/1540/5725/files/beat_it_remix_ringtone.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Extracted artifacts 3
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00006081.bin5c90d1e7980781b20a06f9397f7d6a266328f934f41c626177640aa0b77c9d39 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x6081 | 5300 bytes |
font_01_sfnt_off0000724f.bincdc7567fe6f94e89b4a903b6896b0606d8e6cbda5137bf097979827808553186 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x724F | 9732 bytes |
font_02_sfnt_off000093ad.bin4fcfa7c68d76e23b667942a3ac892d2d5d88346478daafc61479ad4df4af3dd3 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x93AD | 4324 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.