MALICIOUS
120
Risk Score
Malware Insights
MITRE ATT&CK
T1566.002 Spearphishing Attachment
T1059.001 PowerShell
The PDF file contains numerous embedded links, with one specifically pointing to a known malicious redirector at `ttraff.ru`. The document body, though heavily obfuscated, contains text that appears to be a lure for an internship report. The presence of a malicious redirector suggests an attempt to lead the user to a malicious site, likely for further exploitation or credential harvesting.
Heuristics 3
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://ttraff.ru/wix?keyword=rapport+de+stage+bafd
- https://static.usrfiles.com/ugd/71fd01_2afc4ab386d24f17bb542c3f875ad003.pdf
- https://static.usrfiles.com/ugd/b8c837_020fe300be4e4cbbadafe8ae2b3033d0.pdf
- https://static.usrfiles.com/ugd/b8c837_622fb092c81a4dcaa75e32c6b5e78e1a.pdf
- https://static.usrfiles.com/ugd/b3bc21_613ecb3cd1524af1a1b6cd69bd4554d9.pdf
- https://static.usrfiles.com/ugd/80bfa9_e3a2887ba166449f9d9e16937c7f40af.pdf
- https://cdn.shopify.com/s/files/1/0431/4310/2618/files/11696666167.pdf
- https://cdn.shopify.com/s/files/1/0431/1993/5655/files/mosisovadawawuki.pdf
- https://cdn.shopify.com/s/files/1/0432/0142/9662/files/73493822873.pdf
- https://static.usrfiles.com/ugd/8c0e65_caec13dd44ec478f8f3e6420272c80da.pdf
- https://static.usrfiles.com/ugd/b8c837_1e31b88086104db29415b86c1fade428.pdf
- https://static.usrfiles.com/ugd/0ad6c7_070b30288e32432c8faf0e29941b4d09.pdf
- https://static.usrfiles.com/ugd/50de67_bf8cac3562c746479e4ccd8864e25e86.pdf
- https://cdn.shopify.com/s/files/1/0431/3740/0999/files/statistical_methods_for_the_analysis_of_biomedical_data.pdf
- https://cdn.shopify.com/s/files/1/0435/0168/2843/files/aminoacidos_definicion.pdf
- https://cdn.shopify.com/s/files/1/0428/9635/9580/files/borofaragogik.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00006bc3.bin943b1dd6308693b71b300330151a2b895847ed17f9811cebfa9d54b20ff463c2 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x6BC3 | 5324 bytes |
font_01_sfnt_off00007df4.bineaf48768b82feb0998e523d067555ed531db3a75086559ee3951730e08d23757 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x7DF4 | 10036 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.