MALICIOUS
60
Risk Score
Malware Insights
MITRE ATT&CK
T1566.002 Spearphishing Attachment
T1059.001 PowerShell
The PDF file contains a heuristic firing for a malicious redirector link, pointing to 'https://ttraff.com/wix?keyword=crisi+de+1929'. The document body, though heavily obfuscated, includes this URL and text related to the 1929 crisis, suggesting a lure to a malicious site. No scripts were extracted from this sample.
Heuristics 2
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://ttraff.com/wix?keyword=crisi+de+1929
- https://cdn.shopify.com/s/files/1/0437/4197/0583/files/gowawewosiropipugolekal.pdf
- https://cdn.shopify.com/s/files/1/0439/6810/2558/files/45966673719.pdf
- https://cdn.shopify.com/s/files/1/0431/8583/2096/files/bekhayali_me_bhi_tera_ringtone_zedge.pdf
- https://cdn.shopify.com/s/files/1/0432/2109/0471/files/17901862897.pdf
- https://cdn.shopify.com/s/files/1/0431/4998/3901/files/kajutalibuxoriguxopiji.pdf
- https://static.usrfiles.com/ugd/0a0016_f3f199115b9946e2859aad3234a670d6.pdf
- https://static.usrfiles.com/ugd/f46427_d0f3d3a7be8e4924bc3b731d821d89ae.pdf
- https://static.usrfiles.com/ugd/c1108c_a496242b70cf4a45b48dc1a1964ecf12.pdf
- https://static.usrfiles.com/ugd/0cd3a8_76a3d23c3b01481caf990b706e252ad3.pdf
- https://static.usrfiles.com/ugd/41a0b6_f61d7706d36f4619a3bc3215bb2b0e08.pdf
- https://static.usrfiles.com/ugd/b8c837_4b37cb7d5ce14beebf8bb283dede45f2.pdf
- https://static.usrfiles.com/ugd/ee9d3f_fe09455ca4b8419dbba4f2ca3bab9e67.pdf
- https://static.usrfiles.com/ugd/166c09_6fabe6ab8d6543a189f7ee7b3a6e4c84.pdf
- https://static.usrfiles.com/ugd/0c8cc8_37a58a279012442aa2d9c452059334f2.pdf
- https://static.usrfiles.com/ugd/d43733_6d7b1f75cc2440e0946aa2c390eb1733.pdf
- https://static.usrfiles.com/ugd/5899d5_a7d33754afe147c6bc51948d154a9d0b.pdf
- https://static.usrfiles.com/ugd/7baf93_8ebc8c5dc0e549a881dfb3d06e3db051.pdf
- https://static.usrfiles.com/ugd/b8c837_34660902ac7545cfbb8a3f9c8db5ca92.pdf
- https://static.usrfiles.com/ugd/90c678_bf88e7c2d64f41148dac8768a71b3656.pdf
- https://static.usrfiles.com/ugd/cb5dea_b01b54849fbe4b99b65debc6cc8c1f12.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00020691.bine830e62482ea47bc4a3d6d669f5f9c5fdbc9bc9a534a24c63e12a4749e774d6e |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x20691 | 4820 bytes |
font_01_sfnt_off00021701.bincbed46f3d6c9a63eeed3b644fee9a8e21a29487b07b1a97d86436897a8a3de8d |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x21701 | 13232 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.