MALICIOUS
150
Risk Score
Malware Insights
MITRE ATT&CK
T1566.002 Spearphishing Attachment
T1204.002 Malicious File
The PDF contains a large number of external links, a common technique for phishing and malware distribution. The ClamAV detection and ML classifier strongly indicate malicious intent, specifically identified as 'Pdf.Phishing.TtraffRobotInstall-7605656-0'. The document body, though heavily corrupted, appears to be a lure, attempting to present itself as a legitimate PDF download for medical procedures, while the embedded URLs lead to a link farm of other PDF files, likely serving as a distribution mechanism for further malicious content.
Machine Learning
- Nyx PDF Classifier malicious score 0.9997
Heuristics 3
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL http://riotthink.com/uploads/1/3/0/5/130538946/litelopapuk.pdf
- http://addycakescookies.com/uploads/1/3/0/5/130541402/sarokobixamagafar.pdf
- http://quaternityoga.com/uploads/1/3/0/2/130272609/vebatuzepemarufuj.pdf
- http://thebynumagency.com/uploads/1/3/0/5/130590535/1a1399d4bd.pdf
- http://abcofscotland.com/uploads/1/3/0/7/130738831/fa0283f8c97def.pdf
- http://isecmitigationgroupllc.com/uploads/1/3/0/3/130313262/wojita-tomiki.pdf
- http://ctmpropertymanagementsc.com/uploads/1/3/0/7/130740318/5574841.pdf
- http://adisera.com/uploads/1/3/0/6/130640074/559e117923.pdf
- http://namyangitaly.com/uploads/1/3/0/5/130588473/zonebopabopeji.pdf
- http://winecountryreclaimedfurniture.com/uploads/1/3/0/6/130639309/tikeferazep.pdf
- http://flashissuemail.net/uploads/1/3/0/3/130313471/b9fd91ffb78f9b.pdf
- http://host59.carmichaelnl.com/uploads/1/3/0/6/130604344/130604344.html#roberts+and+hedges%E2%80%99+clinical+procedures+in+emergency+medicine+and+acute+care+pdf
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00002bf7.bin83459e82cebe561b9e65dda6a09953c9e35f75e5df0fa62a624e1833cc5b8086 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x2BF7 | 1708 bytes |
font_01_sfnt_off00003713.bincb50fd0330f67f9721fa99bbd13bd4763f4534bcc46d0ab3e08462ebad18238a |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x3713 | 7932 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.