MALICIOUS
152
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
The PDF contains a large number of embedded URLs pointing to other PDF files hosted on various domains, a technique often used for SEO manipulation or to distribute further malicious content. The ClamAV detection and ML classifier strongly indicate malicious intent, specifically identified as 'Pdf.Phishing.TtraffRobotInstall-7605656-0'. No scripts were extracted, but the sheer volume of external links suggests a coordinated effort to redirect users.
Machine Learning
- Nyx PDF Classifier malicious score 0.9998
Heuristics 3
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL http://bellemeadedentalcenter.com/uploads/1/3/0/2/130289313/1966425.pdf
- http://paintinghopefoundation.com/uploads/1/3/0/6/130620868/039d1066d999.pdf
- http://southamericarealstate.com/uploads/1/3/0/6/130639236/1231154.pdf
- http://krgservicecorp.com/uploads/1/3/0/6/130620511/nubife-nalevepe-rufoxuguri-larafepurirolep.pdf
- http://americalibertyforum.com/uploads/1/3/0/2/130273801/4b866417.pdf
- http://wan.badcelebriz.fun/uploads/2020/01/29/kuvaxef.pdf
- http://lampeelife.com/uploads/1/3/0/3/130379150/jiborujulage.pdf
- http://kimbroughrehi.com/uploads/1/3/0/2/130274343/fdedcce1f7a.pdf
- http://sake.faring8.net/uploads/2020/01/29/03398be8.pdf
- http://alchemystvapes.com/uploads/1/3/0/2/130289515/pazitafibujad-sivelu-vanego-jikusomadinevuf.pdf
- http://newoutsiderart.com/uploads/1/3/0/6/130639750/fametevexuzofez_baguj.pdf
- http://victoriahunters.weebly.com/uploads/1/3/0/5/130545745/cb295d400.pdf
- http://seizediem.com/uploads/1/3/0/6/130639646/130639646.html#pmir-+report+luciferase+vector+sequence
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- http://dejavu.sourceforge.net
- http://dejavu.sourceforge.net/wiki/index.php/License
- https://fedoraproject.org/wiki/Licensing/LiberationFontLicense
Extracted artifacts 3
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off000014da.bin68e1033429f1ba8b4446e8ba0a53b648a3ce223e76f6bb4c2984ba059395d08d |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x14DA | 7532 bytes |
font_01_sfnt_off000053b1.binb3affdfdfee497c2d3230853582529cf395d265bfdbb8cde7d84ae9c33602211 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x53B1 | 16036 bytes |
font_02_sfnt_off000067ca.bin63f5e27ee3d24cc00d413e59c301cc73ab377383609796993547673f2bea898c |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x67CA | 2600 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.