Malware Insights
The PDF contains a critical heuristic firing for a malicious redirector link, directing users to a URL that appears to offer cracked software. It also contains a high heuristic for a password-protected archive lure, suggesting the PDF itself is a decoy to facilitate the download of a password-protected malicious payload. The document body, though heavily obfuscated, contains the same lure URL and references to other PDF files hosted on static.usrfiles.com, which are likely part of a link farm to improve search engine ranking for the malicious lure.
Heuristics 4
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Password-protected archive handoff high SE_PASSWORD_ARCHIVE_LUREDocument gives password instructions for an archive or attachment — often used to keep payloads encrypted until after gateway scanning
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://ttraff.ru/wix?keyword=abbyy+finereader+free++with+crack
- https://static.usrfiles.com/ugd/b8c837_03c0f31937d141bfbe664aea726c2791.pdf
- https://static.usrfiles.com/ugd/8acad3_7f8fb43447a04629aaed01cc712a22e1.pdf
- https://static.usrfiles.com/ugd/dc98cc_d7400a1b159a479aa3f8314fbb4a4a1b.pdf
- https://static.usrfiles.com/ugd/b8c837_17deed89015940d9a6f183a05e92f7a5.pdf
- https://static.usrfiles.com/ugd/5899d5_2470b344e3184e55aeb528a4475e5c47.pdf
- https://static.usrfiles.com/ugd/b3bc21_a14816db084441fd86e4b6429e82901b.pdf
- https://static.usrfiles.com/ugd/9c43ec_374d5f9d01b34b10899494b8fef84c7d.pdf
- https://static.usrfiles.com/ugd/277b62_424d3e3367ec4a3f888c81c73f265a5e.pdf
- https://static.usrfiles.com/ugd/2f8cea_8a84288a052b4559af4304c9b3a0dc76.pdf
- https://static.usrfiles.com/ugd/f459ea_bc8d47f56b554e93b66dc195f48e9b0a.pdf
- https://static.usrfiles.com/ugd/b8c837_3bd5f229bb2d4ace8ce9d91a1189196a.pdf
- https://static.usrfiles.com/ugd/b8c837_bf72fc765e04470a8f2e65bb3ff3554b.pdf
- https://static.usrfiles.com/ugd/b8c837_0855aecdad9f4b0aa0a1147d93c609aa.pdf
- https://static.usrfiles.com/ugd/225520_d3776d3181684732a05b160fe03614b0.pdf
- https://static.usrfiles.com/ugd/21e6f2_4ef6c1bf5c29431fb3e439fc5204dfba.pdf
- https://static.usrfiles.com/ugd/80bfa9_15d0737085c640aba2d67206d93f2929.pdf
- https://static.usrfiles.com/ugd/3e9e83_1e037c880b9f4218ac1fcf5630ad07e5.pdf
- https://static.usrfiles.com/ugd/b8c837_31acf244f30c48d9ba84016a7ceea100.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000670d.bin689270508267ebdc9a05817f5fa5f94033bebdbc3890921d3b45e7eb9bb720b9 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x670D | 5288 bytes |
font_01_sfnt_off0000791c.binc4556c23752d3dba02e3ea78bc707dce48812a3f0a5b35226079b2bac9e86b65 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x791C | 10204 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.