Malware Insights
The PDF file contains a critical heuristic firing indicating it links to known malicious redirector infrastructure. The embedded URL `https://ttraff.com/wix?keyword=chicago+journal+citation+format` is the primary indicator of malicious intent. Additionally, the file contains a mass external PDF link farm, with many links pointing to `static.usrfiles.com`, suggesting a potential SEO poisoning or link farm tactic. No scripts were extracted, and the document body is heavily obfuscated, but the presence of the malicious redirector is sufficient for a high-confidence assessment.
Heuristics 3
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://ttraff.com/wix?keyword=chicago+journal+citation+format
- https://static.usrfiles.com/ugd/ed64d2_7cf20b2588154be3983258e970cd5ee3.pdf
- https://static.usrfiles.com/ugd/6240f8_a12b915cae054f3eb6be2112447d1b91.pdf
- https://static.usrfiles.com/ugd/3d514e_1d56553b24bf4890b6cf7c001dd09f28.pdf
- https://static.usrfiles.com/ugd/2f7815_4d5e8b9c7b8f4db1a5c2ac98a2994714.pdf
- https://static.usrfiles.com/ugd/b8c837_9a2c7ab771be4782bb82ef33e6564db6.pdf
- https://cdn.shopify.com/s/files/1/0429/0415/8375/files/sivakawiganusavubofov.pdf
- https://cdn.shopify.com/s/files/1/0439/7246/0702/files/editorial_cartooning_tutorial.pdf
- https://static.usrfiles.com/ugd/5de1df_665d6e85fe4d4cd68e899ad955af2c28.pdf
- https://static.usrfiles.com/ugd/e4f6f0_5b86c1d6144c4fadb55b6245240e699f.pdf
- https://static.usrfiles.com/ugd/63f22d_3a1487c8c9c64d77a191b486bef5b5e1.pdf
- https://static.usrfiles.com/ugd/b8c837_1ba49b58ce7449a587958b952fcb2dcc.pdf
- https://cdn.shopify.com/s/files/1/0434/6455/6710/files/81198296860.pdf
- https://cdn.shopify.com/s/files/1/0432/5844/5979/files/business_analysis_skills.pdf
- https://cdn.shopify.com/s/files/1/0437/1991/7719/files/carbonization_of_wood.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off000061ac.bin638e010b695003a7052ccb2d302a4ca6b5323ef206aabf5555e8bf0d78c51e28 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x61AC | 5100 bytes |
font_01_sfnt_off000072e0.binf1f5afe1af935c638af8c5d51f5d3116ed7ca7f794ea4f213b386e62cf1bf808 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x72E0 | 9848 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.