Malware Insights
The PDF contains multiple embedded links, with one identified as a known malicious redirector. The document body, though heavily obfuscated, contains text related to 'simple past tense exercises pdf perfect english grammar' and a URL that appears to be part of a link farm designed to attract search engine traffic. The presence of a 'download button' heuristic further suggests a lure to click on these links. The primary malicious link identified is https://ttraff.ru/pify?keyword=simple+past+tense+exercises+pdf+perfect+english+grammar, which likely leads to further malicious content.
Heuristics 4
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTONDocument contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://ttraff.ru/pify?keyword=simple+past+tense+exercises+pdf+perfect+english+grammar
- http://dowesexaf.kierstenmodglinauthor.com/uploads/1/3/0/7/130739024/bavil.pdf
- http://files.delgadodesigns.co.uk/uploads/1/3/1/8/131857562/b1dc0aab5c7b2fc.pdf
- http://wimesap.5fingers.co.uk/uploads/1/3/0/8/130874431/f9bb3ff.pdf
- http://files.alliumresearch.com/uploads/1/3/1/4/131453401/gabiliwizebo-doximadeton-timirodexatezab-fuziworapobadut.pdf
- http://files.slightlysharpenterprises.com/uploads/1/3/0/8/130873983/aab6cd.pdf
- https://cdn.shopify.com/s/files/1/0431/3507/4465/files/54703745387.pdf
- https://cdn.shopify.com/s/files/1/0433/1972/2152/files/54778699199.pdf
- https://cdn.shopify.com/s/files/1/0429/5308/0991/files/83987400464.pdf
- https://cdn.shopify.com/s/files/1/0434/4299/5352/files/46925026509.pdf
- https://cdn.shopify.com/s/files/1/0434/3290/2806/files/83946999309.pdf
- https://cdn.shopify.com/s/files/1/0431/6699/0498/files/didederatodivelukapi.pdf
- https://cdn.shopify.com/s/files/1/0437/0661/3912/files/managerial_accounting_study_guide.pdf
- https://cdn.shopify.com/s/files/1/0427/4946/0636/files/26888983534.pdf
- https://cdn.shopify.com/s/files/1/0434/5964/1496/files/6148099715.pdf
- https://cdn.shopify.com/s/files/1/0433/5819/1768/files/kokeworuruwije.pdf
- https://cdn.shopify.com/s/files/1/0429/3174/9031/files/i_don_t_wanna_know_lyrics_mario.pdf
- https://cdn.shopify.com/s/files/1/0429/9672/7957/files/4791434854.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Extracted artifacts 3
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00005572.bin3f8fd5011ce6db3895ffb7cc0e450616453339095e5a6cfb3358f01a887ec7a5 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x5572 | 5416 bytes |
font_01_sfnt_off000067a3.bincb6d3b2b0bfac1fb1d8f80329251b2fabea288f98beaafad17970bb5ca59b2e3 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x67A3 | 10068 bytes |
font_02_sfnt_off000089e3.bin1158d95dac44631f497756703988ba3645251422e7ff0015d3fca430225e7c3e |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x89E3 | 4324 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.