MALICIOUS
152
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
This PDF file was flagged by multiple heuristics, including a critical rule for a large external PDF link farm and a ClamAV detection for 'Pdf.Phishing.TtraffRobotInstall'. The embedded URLs point to numerous PDF files hosted on unrelated domains, suggesting a tactic to distribute malicious content or manipulate search engine results. No scripts were extracted from this sample, and the document body contained mostly obfuscated or corrupted text.
Machine Learning
- Nyx PDF Classifier malicious score 1.0000
Heuristics 3
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL http://hostmaster.pipart.com.au/uploads/1/3/0/5/130546244/2a9780e4427.pdf
- http://boutiqueaubelumiere.com/uploads/1/3/0/4/130435673/zepita.pdf
- http://autodiscover.briggsquarterhorses.com/uploads/1/3/0/9/130968921/suluzurofisak_jeduvego_rufobevikaxema.pdf
- http://ballerweekly.com/uploads/1/3/0/5/130543685/3573323.pdf
- http://agentrh.com/uploads/1/3/0/7/130775879/6785328.pdf
- http://acloudsolutionsarchitect.com/uploads/1/3/0/7/130740590/masugiteduwivazojug.pdf
- http://kmdmoney.com/uploads/1/3/0/3/130379098/wizebexibigabebowi.pdf
- http://obrothersdetailing.com/uploads/1/3/0/6/130603884/5c3601d397.pdf
- http://tmsmllc.com/uploads/1/3/0/8/130814345/1319047.pdf
- http://metzrwesleyan.com/uploads/1/3/0/5/130544437/bitijajiminevoji.pdf
- http://sarahstrasser.org/uploads/1/3/0/6/130621665/kimefaj.pdf
- http://www.chazstyles.com/uploads/1/3/0/3/130379274/2876406.pdf
- http://oleanderpress.co.uk/uploads/1/3/0/5/130588565/lifabima.pdf
- http://blairkhartman.com/uploads/1/3/0/6/130604386/0e53c5a170d0.pdf
- http://backes-olli.com/uploads/1/3/0/5/130588261/pilugurofavo.pdf
- http://babywhoopsie.com/uploads/1/3/0/6/130620897/limubo-nebitewetonuf.pdf
- http://aicphr.org/uploads/1/3/0/6/130639856/417633.pdf
- http://plr4.us/uploads/1/3/0/5/130543837/mobix.pdf
- http://exfdainspector.com/uploads/1/3/0/2/130272636/dezatixapeliket.pdf
- http://myholisticskinclinic.com/uploads/1/3/0/6/130603822/vimux_dabawuwuxal.pdf
- http://wcd-4k4esn.mgh-r.ch/uploads/1/3/0/6/130639765/130639765.html#hip+abductor+exercises+knee+pain
Extracted artifacts 1
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off000031d4.binfa15d7c1bdc4a1dfe071b782f055aba036cd64dca5d0cfd01ff79f471002da76 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x31D4 | 7728 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.