MALICIOUS
150
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.001 PowerShell
The PDF contains a large number of external links, identified by the PDF_SEO_LINK_FARM heuristic, suggesting a link farm or phishing lure. The ClamAV detection as 'Pdf.Phishing.TtraffRobotInstall-7605656-0' further supports a phishing or malicious redirection intent. The embedded URLs, although individually marked as benign, contribute to the overall malicious pattern of link distribution.
Machine Learning
- Nyx PDF Classifier malicious score 1.0000
Heuristics 3
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://zupaligowilazu.weebly.com/uploads/1/3/0/5/130542924/xojexufaxikedaladew.pdf
- https://xigunolu.weebly.com/uploads/1/3/0/3/130379294/xomonuri.pdf
- https://xefepibad.weebly.com/uploads/1/3/0/3/130379237/jamewavukutokazoxak.pdf
- https://gomafego.weebly.com/uploads/1/3/0/3/130379894/jizekokaxadimena.pdf
- https://bewowoxifa.weebly.com/uploads/1/3/0/4/130477131/27e72.pdf
- https://molonunida.weebly.com/uploads/1/3/0/5/130550974/3004872.pdf
- https://nujesusapojedot.weebly.com/uploads/1/3/0/4/130483879/betejenevu-zexofijewoperaz-zivigeb.pdf
- https://texujidokurad.weebly.com/uploads/1/3/0/2/130288453/3c3319700.pdf
- https://kejifowapo.weebly.com/uploads/1/3/0/4/130488288/0a14c1c9a1.pdf
- https://rafilaluxonijew.weebly.com/uploads/1/3/0/4/130476150/130476150.html#children%27s+tylenol+22+lbs
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
stream_003_off0000538d.bina954f0f4707a7043b63eef75d3c5c66fcd48cda01c81cda12f37a0f4a74e8a31 |
decompressed-pdf-stream | PDF FlateDecoded stream at offset 0x538D | 16732 bytes |
font_00_sfnt_off000011d4.binbd62d232164882f3ba86665dc954e53fce1f86894a10a2d261f242c8f5ab637b |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x11D4 | 8556 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.