Malware Insights
This PDF file exhibits characteristics of a phishing or malware delivery attempt. The presence of a large number of external PDF links, identified by the PDF_SEO_LINK_FARM heuristic, suggests an attempt to manipulate search engine results or redirect users to malicious content. The SE_ENABLE_LURE and SE_CLICKFIX heuristics indicate that the document is designed to trick the user into enabling macros or executing commands, likely to download and execute a second-stage payload from one of the embedded URLs. The ClamAV detection further supports its malicious nature.
Heuristics 5
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
-
ClickFix social engineering attack high SE_CLICKFIXDocument instructs the user to press Win+R or paste a command into a terminal — consistent with ClickFix attacks that bypass macro restrictions by tricking users into running malicious commands directly
-
Macro/content-enable lure medium SE_ENABLE_LUREDocument instructs the user to enable macros or editing — a common technique used by malware droppers to bypass Office macro security settings
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL http://tateglass.com/uploads/1/3/0/6/130605426/foruvunivovaful.pdf
- http://premierdraftroofing.com/uploads/1/3/0/2/130272512/falepugudi.pdf
- http://southenddiving.co.uk/uploads/1/3/0/4/130492315/fdb0d44.pdf
- http://bangkokkettlebells.com/uploads/1/3/0/5/130542781/jexefam.pdf
- https://matuwabinuwew.weebly.com/uploads/1/3/0/5/130550800/f5bf3c8354.pdf
- http://noosalittlecove.com/uploads/1/3/0/2/130291766/nufujegexumitok_loxada_fadujidaj_xejop.pdf
- http://luxurybasketsandmore.com/uploads/1/3/0/6/130621703/wijorefisalenox.pdf
- http://quillesthon.com/uploads/1/3/0/6/130604397/kopus.pdf
- http://nuja.datingnearme.in/uploads/2020/01/28/sobozafujejur.pdf
- http://my-trg.com/uploads/1/3/0/6/130621484/7bc0b530.pdf
- http://laydenhomes.com/uploads/1/3/0/5/130543996/2113234.pdf
- http://shrinedads.com/uploads/1/3/0/2/130288811/1325867.pdf
- https://kogijidapij.weebly.com/uploads/1/3/0/6/130605017/fiwebojuzibujosibope.pdf
- http://smith-re.com/uploads/1/3/0/4/130488196/130488196.html#acrobat+crashes+when+opening+pdf
Extracted artifacts 1
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off000013b5.bin10139152865558386f274e6fbd4f8254b8d81426792b733b8e7b7ff360f2c025 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x13B5 | 8796 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.