MALICIOUS
120
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.001 PowerShell
The PDF file contains a large number of embedded links to external PDF files hosted on various domains, indicating a link farm or redirection scheme. The ClamAV detection 'Pdf.Phishing.TtraffRobotInstall-7605656-0' further supports a phishing or traffic redirection intent. No scripts were extracted from this sample, limiting the ability to determine specific payload delivery mechanisms.
Heuristics 3
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL http://belleajai.com/uploads/1/3/0/5/130541846/bipuvem_tobajejibiji_fekuru.pdf
- http://www.prodbyq.com/uploads/1/3/0/3/130313289/bozofikekulelasezuka.pdf
- http://www.katarinatuffvesonjensen.com/uploads/1/3/0/5/130590548/sadum.pdf
- http://www.explore-create.com/uploads/1/3/0/5/130550960/novugoregojigug.pdf
- http://rickyzheng.net/uploads/1/3/0/8/130814040/d0576ed2196c.pdf
- http://streamboxtv.com/uploads/1/3/0/5/130589342/kiluzowaladu.pdf
- http://myezpzpay.com/uploads/1/3/0/3/130313826/6426012.pdf
- http://munciearts.net/uploads/1/3/0/4/130490117/1286022.pdf
- http://cleaningclinic.shop/uploads/1/3/0/7/130775688/6905661.pdf
- http://natashadoulabirthmarks.com/uploads/1/3/0/7/130738564/dezapaf.pdf
- http://nongress.org/uploads/1/3/0/4/130478106/3452428.pdf
- http://doctorberrycoaching.com/uploads/1/3/0/2/130289424/8535438.pdf
- http://rickandjudy.net/uploads/1/3/0/4/130483147/9b07e31.pdf
- http://sweetwillowsoap.com/uploads/1/3/0/7/130739155/bufarufokeben.pdf
- http://lovebirthlondon.com/uploads/1/3/0/5/130543038/674b4a4a0.pdf
- http://millymop.co.uk/uploads/1/3/0/4/130488503/8338891.pdf
- http://thebusinesstip.com/uploads/1/3/0/4/130476502/130476502.html#lower+abdominal+cramps+from+gas
- http://sweetwillowsoap.com/uploads/1/3/0/7/130739155/bufarufoke
Extracted artifacts 1
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00002cf8.bin60a2a7fd2fb9ee17aa89f07e7ab5174ef9604a4c67468f898853b0abc2bdb9ca |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x2CF8 | 7700 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.