MALICIOUS
152
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
The PDF contains a large number of embedded URLs pointing to other PDF files hosted on various domains, indicating a link farm or distribution mechanism. ClamAV identified this as 'Pdf.Phishing.TtraffRobotInstall-7605656-0', and a critical heuristic detected a 'PDF_SEO_LINK_FARM'. The ML classifier also flagged it with high confidence. No scripts were extracted, and the document body was heavily corrupted, preventing analysis of its direct content.
Machine Learning
- Nyx PDF Classifier malicious score 0.9998
Heuristics 3
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL http://aleriongames.us/uploads/1/3/0/6/130639410/8111a4d9a35d9c.pdf
- http://plainenglishfordoctors.com/uploads/1/3/0/6/130639263/bupapuke.pdf
- http://mta-sts.mail.artisticreteleesburg.com/uploads/1/3/0/6/130603743/adbbea9be1d7b5e.pdf
- http://becker-energie.fr/uploads/1/3/0/7/130738512/xivupasunenasujobab.pdf
- http://indysponsors.com/uploads/1/3/0/6/130621142/zesalo-tonijomej-nekuzu.pdf
- http://colinaway.com/uploads/1/3/0/6/130639563/nuzusakamiparaziwow.pdf
- http://sublimepainting.net/uploads/1/3/0/6/130621003/kezujutipag.pdf
- http://ecuadoroscuro.com/uploads/1/3/0/7/130775129/pelexojorubi.pdf
- http://quillicus.com/uploads/1/3/0/5/130539479/3ab3e8f0.pdf
- http://shop.technicalapexx.org/uploads/1/3/0/5/130550803/xegibuzipek_fexupolixubupot.pdf
- http://5toolgroup.com/uploads/1/3/0/6/130621048/8700339.pdf
- http://michaeljamesvocals.com/uploads/1/3/0/7/130740598/gogevuwelitix.pdf
- http://www.jaiersoccer.com/uploads/1/3/0/6/130622009/zexezoti.pdf
- http://bitcoinserv.co.uk/uploads/1/3/0/7/130775649/rupofufona.pdf
- http://staceyphillips.online/uploads/1/3/0/7/130776439/wopitejon.pdf
- http://blackdogsocialconsultants.com/uploads/1/3/0/5/130546971/81eb7f341c948.pdf
- http://igutyria.com/uploads/1/3/0/6/130621061/zuwikirofed-vipefudotenawo.pdf
- http://yogaandasianbodytherapy.com/uploads/1/3/0/7/130739875/130739875.html#rectangular+to+polar+coordinates+calculator
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- http://dejavu.sourceforge.net
- http://dejavu.sourceforge.net/wiki/index.php/License
- https://fedoraproject.org/wiki/Licensing/LiberationFontLicense
Extracted artifacts 3
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00003334.bin3e9a9dfb40a01f9f7c9c545b28ba37f1de74591f2b47bc69a9983f40f3f3ebd7 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x3334 | 16080 bytes |
font_01_sfnt_off00004796.bin4fa858b82b445805eff69b872cfcae0b273ce6c644f001a2365b71733efe32ff |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x4796 | 2988 bytes |
font_02_sfnt_off00005549.bine8efb42091048696e3feaf334f216ae0bfa51b80202236c1257d007bd4b62943 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x5549 | 9332 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.