Malware Insights
The PDF file contains a heuristic firing for a malicious redirector link, directing users to 'https://ttraff.ru/wix?keyword=opera+browser+for+win+xp'. Additionally, it exhibits characteristics of a PDF link farm, containing numerous external links, with a significant portion pointing to Shopify-hosted PDFs. The document body, though heavily corrupted, contains fragments suggesting a lure for a browser update or extension, aligning with the 'SE_BROWSER_INSTALL_LURE' heuristic. The primary malicious IOC is the redirector URL, which likely leads to further malicious content or exploits.
Heuristics 4
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Browser extension / update installation lure high SE_BROWSER_INSTALL_LUREDocument tells the user to install a browser extension, plugin, viewer, or browser update to view content — a common social-engineering path for credential theft and malware installation
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://ttraff.ru/wix?keyword=opera+browser+for+win+xp
- https://static.usrfiles.com/ugd/6df952_baef509c5e7744c28b8f321ac7f7e047.pdf
- https://static.usrfiles.com/ugd/e2c250_b59c010aa13b411492eb96a9f9538919.pdf
- https://static.usrfiles.com/ugd/b42fd6_f1a7a7b0b74143e7bb9cacc21e3cc5bd.pdf
- https://static.usrfiles.com/ugd/b8c837_7f825cf65625495496c79e78b526030c.pdf
- https://cdn.shopify.com/s/files/1/0434/6744/0294/files/make_list_targets.pdf
- https://cdn.shopify.com/s/files/1/0431/7632/9373/files/xarev.pdf
- https://cdn.shopify.com/s/files/1/0428/5782/4419/files/75797564991.pdf
- https://cdn.shopify.com/s/files/1/0429/5658/7174/files/frga_p_annat_fordon.pdf
- https://cdn.shopify.com/s/files/1/0437/0595/8553/files/website_psd_templates_2018.pdf
- https://cdn.shopify.com/s/files/1/0441/2227/5992/files/hospital_management_system_database_project_report.pdf
- https://cdn.shopify.com/s/files/1/0466/2856/9253/files/tera_gender_locked_classes.pdf
- https://cdn.shopify.com/s/files/1/0429/6690/9081/files/business_models_examples.pdf
- https://cdn.shopify.com/s/files/1/0439/4283/8427/files/topesepawefo.pdf
- https://static.usrfiles.com/ugd/b8c837_c6c43a1de9d949f5ad10a1b366588b14.pdf
- https://static.usrfiles.com/ugd/6260fe_14b61a9bb515438487020c11fd4212e6.pdf
- https://static.usrfiles.com/ugd/b8c837_f1a4742eb5d045ea850a6c93b6a45d7b.pdf
- https://static.usrfiles.com/ugd/d9d1f5_0021a7eb2e594cabbbb06e35196c4437.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Extracted artifacts 3
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000663a.bin4350bb5e7dfe41ba156a6a0338dc129d5355d8e2754f2ce0eeccb4706c842246 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x663A | 4896 bytes |
font_01_sfnt_off000076ed.bin8063d19c894e691b8ab674a4e73dca1545d69a01df2a9941eed6272d3d3fef2f |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x76ED | 10680 bytes |
font_02_sfnt_off00009aec.bin4fcfa7c68d76e23b667942a3ac892d2d5d88346478daafc61479ad4df4af3dd3 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x9AEC | 4324 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.