Malware Insights
The PDF file contains a heuristic firing for PDF_MALICIOUS_REDIRECTOR_LINK, indicating a link to known malicious infrastructure. The document body, though heavily obfuscated, contains text referencing 'It ends with us colleen hoover' and a URL that matches the malicious redirector. The presence of a PDF_SEO_LINK_FARM heuristic suggests the PDF was generated as part of a larger scheme to create numerous links, likely for SEO manipulation or to host malicious content. The primary malicious IOC is the redirector URL, which likely leads to a phishing page or malware download.
Heuristics 3
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://ttraff.cc/wix?keyword=it+ends+with+us+colleen+hoover
- https://cdn.shopify.com/s/files/1/0432/8721/6293/files/dukutipekusazilemogexel.pdf
- https://cdn.shopify.com/s/files/1/0430/7602/6522/files/natenixolepofumozixurizu.pdf
- https://cdn.shopify.com/s/files/1/0432/0333/0209/files/kutam.pdf
- https://cdn.shopify.com/s/files/1/0431/3337/0522/files/69891599531.pdf
- https://static.usrfiles.com/ugd/ca300b_c026222052e74eb79ac66aabb5913284.pdf
- https://static.usrfiles.com/ugd/7d1dc9_e2a7da5eae2e4760b3aa254b04b28878.pdf
- https://static.usrfiles.com/ugd/8b49c6_f93b6c2235364df48463a35ff9a64f0f.pdf
- https://static.usrfiles.com/ugd/b8c837_0d1d84749b9b4daea2dd28eda70ef5c2.pdf
- https://static.usrfiles.com/ugd/0adedf_787a364e9c064db79202edeef2a9d782.pdf
- https://static.usrfiles.com/ugd/b914b5_70276cf599b741708142a88b516bdd68.pdf
- https://static.usrfiles.com/ugd/d3758e_deed45dee5434bc7b2d6eae3e68e606c.pdf
- https://static.usrfiles.com/ugd/7ff653_07a6476640a6456cadec10633f4779d6.pdf
- https://static.usrfiles.com/ugd/b8c837_65373540caa0459fa6610c8336131adb.pdf
- https://static.usrfiles.com/ugd/b8c837_fe0c71f602e84a35953333d0cf281f1d.pdf
- https://cdn.shopify.com/s/files/1/0451/3444/6746/files/wevogixinitebojepoxomo.pdf
- https://cdn.shopify.com/s/files/1/0429/5370/3590/files/kapebire.pdf
- https://cdn.shopify.com/s/files/1/0434/2736/5031/files/sanikaxawegosanizeludi.pdf
- https://cdn.shopify.com/s/files/1/0429/6392/7206/files/driver_easy_pro_key.pdf
- https://cdn.shopify.com/s/files/1/0460/3281/4244/files/90503539050.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Extracted artifacts 4
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00006a75.bina31aa0ddafeb9a962bd6e101c87b9e10ffa374807752983b3046273b2ddf2097 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x6A75 | 4908 bytes |
font_01_sfnt_off00007b27.bineffbe71fc2bda33438baa1f1b0195ba1f0100ccdb21d2503bfa36d6bc2c79a80 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x7B27 | 4696 bytes |
font_02_sfnt_off000087d3.bine7102ef3ea05f6b0e1f288c391e401c4d2a82219b42541b243d9954c40449c07 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x87D3 | 10688 bytes |
font_03_sfnt_off0000ac4e.binb8cc7a504cf66560b94d223e267bb3dcc59ac8ab0b9f1803ed70ad2ab27ccf34 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xAC4E | 16456 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.