MALICIOUS
152
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
The PDF contains a large number of embedded external links, disguised as information about acid reflux, which is characteristic of a link farm or SEO spam. The ClamAV detection as 'Pdf.Phishing.TtraffRobotInstall-7605656-0' and the ML classifier's high confidence score further indicate malicious intent. The embedded links likely lead to further malicious content or phishing sites.
Machine Learning
- Nyx PDF Classifier malicious score 1.0000
Heuristics 3
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL http://sophisticatedpreserves.com/uploads/1/3/0/2/130288926/7214242.pdf
- http://mrsmichelebrown.com/uploads/1/3/0/6/130603772/sopowalikajirulopufe.pdf
- http://bughunters.eu/uploads/1/3/0/2/130287960/981bb9.pdf
- http://gelottiicecream.com/uploads/1/3/0/3/130313111/8072693.pdf
- http://flowinaction.net/uploads/1/3/0/7/130738537/zidoxedutobawaxi.pdf
- http://innerfish.com/uploads/1/3/0/5/130551756/dewogalib.pdf
- http://deerparktreeservices.com/uploads/1/3/0/7/130740166/woriwomakis_xavulu.pdf
- http://thingsome.com/uploads/1/3/0/3/130379824/karawe_mumubigizo_zinofovadegu_nirimitaveriz.pdf
- http://balisurftours.info/uploads/1/3/0/6/130621020/c5becf60.pdf
- http://thetipewax.store/uploads/1/3/0/3/130323222/45610d205.pdf
- http://bayesianupdate.com/uploads/1/3/0/2/130271043/keruwaramatexu-rutinuwixif-gisubuw-xifopa.pdf
- http://bouldenscience.com/uploads/1/3/0/3/130323462/tipalunuwexawi-ridupek.pdf
- http://teamgrowcle.com/uploads/1/3/0/7/130739635/c5ebf5809a6d2d5.pdf
- http://vreedy.shop/uploads/1/3/0/2/130272254/ad3f81.pdf
- http://mydetailguyinc.com/uploads/1/3/0/8/130814863/vomonibuxaxur.pdf
- http://dedicated-20.pleasingfood.com/uploads/1/3/0/7/130738525/130738525.html#list+of+foods+that+don%27t+cause+acid+reflux
Extracted artifacts 1
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00002da0.bin95c62798d14c3beba2f02c4c0ebcc6f3572e3c5125c37d872371dd18346aa7fb |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x2DA0 | 7192 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.