MALICIOUS
94
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
The file was detected as malicious by multiple engines, including ClamAV, which identified it as Pdf.Phishing.TtraffRobotInstall. The embedded URLs suggest a phishing attempt where the user is directed to download a malicious PDF. Although no scripts were explicitly extracted, the PDF structure and embedded URIs are indicative of a malicious document designed to trick users into downloading further malware.
Machine Learning
- Nyx PDF Classifier malicious score 0.9705
Heuristics 3
-
ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
-
External URI info PDF_URIPDF contains an external URL action
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL http://longlifetherapy.com/uploads/1/3/0/6/130620670/ac02f.pdf PDF link annotation
- http://enfieldcollectables.store/uploads/1/3/0/8/130814459/2572230.pdfIn PDF document text
- http://mytjscatering.com/uploads/1/3/0/5/130590531/suvuj.pdfIn PDF document text
- http://www.dwtsetx.com/uploads/1/3/0/8/130814245/7588059.pdfIn PDF document text
- http://perfectionsyards.com/uploads/1/3/0/7/130776734/dikepape.pdfIn PDF document text
- http://hostmaster.watersgreendental.co.uk/uploads/1/3/0/6/130604519/gidumik_toxed.pdfIn PDF document text
- http://consultupstate.com/uploads/1/3/0/5/130551433/b81713cc866f6b.pdfIn PDF document text
- http://www.dadfinitely.com/uploads/1/3/0/6/130620964/6818649.pdfIn PDF document text
- http://naifalouisiana.net/uploads/1/3/0/6/130620544/3c0a7437b.pdfIn PDF document text
- http://zionbasketball.com/uploads/1/3/0/3/130313102/xubifetogemisiw.pdfIn PDF document text
- http://mywnydreamhome.com/uploads/1/3/0/7/130740117/duwagozose.pdfIn PDF document text
- http://triosimplantdentallab.com/uploads/1/3/0/6/130604048/solasuf.pdfIn PDF document text
- http://mybluejeansbookkeeping.com/uploads/1/3/0/2/130273733/zejamavovevu-tabasiv-salukevu.pdfIn PDF document text
- http://www.christianwomenunited.org/uploads/1/3/0/6/130604009/67b303a374.pdfIn PDF document text
- http://elpasoborderyouth.org/uploads/1/3/0/7/130775746/1306329.pdfIn PDF document text
- http://romelocaltourguides.com/uploads/1/3/0/6/130639368/rezarapewusil.pdfIn PDF document text
- http://nexts-lab.com/uploads/1/3/0/9/130969639/fijebusubebefu.pdfIn PDF document text
- http://paxinter.net/uploads/1/3/0/6/130622042/5daf2.pdfIn PDF document text
- http://nomadic-chris.com/uploads/1/3/0/3/130323767/4559771.pdfIn PDF document text
- http://phonic88.com/uploads/1/3/0/2/130288630/raxuparuxedosidepizo.pdfIn PDF document text
- http://eltonsherwin.com/uploads/1/3/0/7/130776022/kutalazujewanaw-sidofirepazom.pdfIn PDF document text
- http://www.tinytreasurespreschoolinfo.org/uploads/1/3/0/6/130603945/lowuzenek.pdfIn PDF document text
- http://www.iamimagemusic.com/uploads/1/3/0/7/130775688/2125671.pdfIn PDF document text
- http://www.e-learninglight.com/uploads/1/3/0/6/130605162/e21b25d6ab4d38.pdfIn PDF document text
- http://thesoarmethod.com/uploads/1/3/0/2/130291724/117039.pdfIn PDF document text
- http://joshleephotojournalist.org/uploads/1/3/0/6/130639784/130639784.html#icao+airport+code+excelIn PDF document text
Extracted artifacts 1
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00003c31.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x3C31 | 8024 bytes |
SHA-256: 277989b016ab652bde580c38ef7d0636652f50664fbf66575dcc6ecf70713d35 |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.