MALICIOUS
172
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1204.002 User Execution: Malicious File
This PDF file exhibits characteristics of a malicious document, including a high ML classifier score and ClamAV detection as 'Pdf.Phishing.TtraffRobotInstall-7605656-0'. The document body contains a lure instructing the user to enable content, a common tactic for malware droppers. The numerous embedded URLs suggest an attempt to host or link to malicious content, likely for downloading a secondary payload.
Machine Learning
- Nyx PDF Classifier malicious score 0.9998
Heuristics 4
-
ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Macro/content-enable lure medium SE_ENABLE_LUREDocument instructs the user to enable macros or editing — a common technique used by malware droppers to bypass Office macro security settings
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL http://kevangoble.com/uploads/1/3/0/6/130621958/bokaw.pdf In PDF document text
- http://alexantic.com/uploads/1/3/0/7/130775762/guxezuxuno_lamuxapan.pdfIn PDF document text
- http://portlandharborwatertaxi.com/uploads/1/3/0/3/130379181/nelivajov.pdfIn PDF document text
- http://k9designwarroad.com/uploads/1/3/0/8/130874289/dadebe.pdfIn PDF document text
- http://nytsattui.com/uploads/1/3/0/6/130603983/ae421c.pdfIn PDF document text
- http://stgeorgestucco.com/uploads/1/3/0/5/130545565/fenavabirumafiwugat.pdfIn PDF document text
- http://metdonuts.com/uploads/1/3/0/2/130272414/3075613.pdfIn PDF document text
- http://nycmedicalmarijuana.com/uploads/1/3/0/5/130539325/8645203.pdfIn PDF document text
- http://mommasblingthing.shop/uploads/1/3/0/6/130620955/2052505.pdfIn PDF document text
- http://alloexo.com/uploads/1/3/0/5/130538862/600d1e1e1.pdfIn PDF document text
- http://lets-split.com/uploads/1/3/0/5/130540146/mideve.pdfIn PDF document text
- http://writing-raven.com/uploads/1/3/0/7/130740393/getumuli.pdfIn PDF document text
- http://bishophomeservices.com/uploads/1/3/0/6/130605237/9543160.pdfIn PDF document text
- http://sonomacountyhardmoneyloans.com/uploads/1/3/0/6/130621850/rapasatidil_xowagikanen.pdfIn PDF document text
- http://strengthsgrid.com/uploads/1/3/0/4/130483513/387614f662bb6f.pdfIn PDF document text
- http://oliverapps.net/uploads/1/3/0/7/130776865/e952a8ca02ff13.pdfIn PDF document text
- http://humpysbarandgrill.com/uploads/1/3/0/9/130969405/vevepinelob.pdfIn PDF document text
- http://web5.pleasingfood.com/uploads/1/3/0/6/130604354/130604354.html#how+to+copy+pdf+to+microsoft+wordIn PDF document text
- https://savannah.gnu.org/projects/freefont/In PDF document text
- http://www.gnu.org/licenses/In PDF document text
- http://www.gnu.org/copyleft/gpl.htmlIn PDF document text
- http://dejavu.sourceforge.netIn PDF document text
- http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text
Extracted artifacts 3
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00003e87.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x3E87 | 6412 bytes |
SHA-256: efe41cb4757344bda3dd1affbfa1d1fc6d539c0708bc1541b179df59fdef8392 |
|||
font_01_sfnt_off00004dcd.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x4DCD | 16440 bytes |
SHA-256: 21e1b98dceec3e7b35dd2e2921961b3b1dfa48b804fe521582c9abeaaf9b26e9 |
|||
font_02_sfnt_off00006692.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x6692 | 8260 bytes |
SHA-256: 753d5b36cae22fb6ea25c93100d9ce1a9c09ba3feb9ce7a487dc51efdc7fe8da |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.