MALICIOUS
150
Risk Score
Malware Insights
MITRE ATT&CK
T1566.002 Spearphishing Attachment
T1204.002 Malicious Link
The PDF file was flagged by multiple heuristics, including a critical finding for a link farm containing numerous external URLs. The ClamAV detection and ML classifier further support its malicious nature. The primary attack pattern involves a large number of embedded URLs, suggesting a phishing or malware distribution campaign. No scripts were extracted from this sample.
Machine Learning
- Nyx PDF Classifier malicious score 0.9998
Heuristics 3
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL http://nyshuttleconcierge.com/uploads/1/3/0/6/130620660/pewijedijefo-suxalapezowat-retife-tolere.pdf
- http://agenttemplate.com/uploads/1/3/0/6/130605040/vized.pdf
- http://americanoverheaddoorsnewyork.com/uploads/1/3/0/2/130289663/degalawelesuxeram.pdf
- http://petalstopins.com/uploads/1/3/0/5/130589310/xexesezibivepex.pdf
- http://sinofusionrestaurant.com/uploads/1/3/0/7/130775275/ebc0b.pdf
- http://wibom.dk/uploads/1/3/0/7/130739093/fapelujuxiwi_zodiluduramoki_kulap.pdf
- http://northwesternexecutivemedicine.net/uploads/1/3/0/6/130639565/7396747.pdf
- http://netballinthecommunity.co.uk/uploads/1/3/0/2/130270823/6b4ab.pdf
- http://mmalonecelebrantservices.online/uploads/1/3/0/6/130604610/2785293.pdf
- http://tarifgo.de/uploads/1/3/0/5/130589151/tupiwugijiz_xidudupizola_samapax.pdf
- http://www.meubles-ergonomia.eu/uploads/1/3/0/5/130590666/dilojutuvopekutopoj.pdf
- http://ponomedicine.com/uploads/1/3/0/6/130603836/kasewed.pdf
- http://yinghuangguojixinyuhao.br3h.com/uploads/1/3/0/9/130969037/130969037.html#chuy%E1%BB%83n+t%E1%BB%AB+pdf+sang+word+b%E1%BB%8B+l%E1%BB%97i+font
Extracted artifacts 3
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00006f24.bin27aad4e7100ae85831cc1a9cf4859e84521ff6b1ee9ac199fa10e6c4d4b25dad |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x6F24 | 2736 bytes |
font_01_sfnt_off00007a25.binf1d1fd6529c6bbb550e4f8c94bddc80bcad9a59fd14a91f2b726b6b8179d8010 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x7A25 | 24672 bytes |
font_02_sfnt_off00009dbe.bined90583f48f830fd53b96379bc2dbcf15304365bb859cf61fa2fa0de0b1fbf64 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x9DBE | 11740 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.