MALICIOUS
152
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
The PDF contains a large number of embedded URLs pointing to external PDF files, a technique often used for SEO spam or to distribute further malicious content. ClamAV identified this as 'Pdf.Phishing.TtraffRobotInstall-7605656-0', indicating a phishing or traffic redirection scheme. The document body is heavily obfuscated and contains no clear user-facing text, suggesting its primary purpose is to host these links.
Machine Learning
- Nyx PDF Classifier malicious score 1.0000
Heuristics 3
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL http://thebandbaltimore.com/uploads/1/3/0/7/130776174/vonifixisonema_febitizewalawi_gezuparone_zexetenubo.pdf
- http://absoluteventoparty.com/uploads/1/3/0/5/130547024/lezonagakoxames.pdf
- http://decorativeoutfitters.com/uploads/1/3/0/5/130588258/c59d7.pdf
- http://www.popupgift.shop/uploads/1/3/0/8/130874118/forepodemirekebe.pdf
- http://criticalthinkingisrequired.com/uploads/1/3/0/6/130604694/ragem-resatenev-lipefupofuf-riwakediwaxe.pdf
- http://shoprubyowl.com/uploads/1/3/0/8/130874509/2389078.pdf
- http://jennaluna.com/uploads/1/3/0/2/130288419/886291.pdf
- http://vilagetulio.com/uploads/1/3/0/6/130640028/3394070.pdf
- http://gruppit.net/uploads/1/3/0/8/130814783/lewevaperigefe.pdf
- http://bakingwithlisey.com/uploads/1/3/0/6/130639935/720218.pdf
- http://bluefinsushichatham.com/uploads/1/3/0/2/130287881/peragekazubakugovi.pdf
- http://colacotwayartstrail.com/uploads/1/3/0/4/130435755/4893593.pdf
- http://mokka.app/uploads/1/3/0/6/130640006/wirekezavadako_xatudepotawuku_buzorawuvodare_xudopimekaxine.pdf
- http://www.oilbalance.com/uploads/1/3/0/7/130740209/nanavuwifomorejax.pdf
- http://meudinheiro.info/uploads/1/3/0/4/130477719/dekidifo_rubojiluroz_zinukojekepib.pdf
- http://thegirlsareallright.com/uploads/1/3/0/7/130775775/wapine.pdf
- http://neisweets.com/uploads/1/3/0/4/130436068/4116764.pdf
- http://malonegroupdesign.com/uploads/1/3/0/9/130969403/694643.pdf
- http://kjtravels714.voyagerwebsites.com/uploads/1/3/0/2/130289508/130289508.html#sinuses+and+eustachian+tube
Extracted artifacts 1
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off000039d3.bin0e32135e30c13ceb4bf8bafd090f4012b7663bb8db88ac6c6eb35206e753b215 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x39D3 | 7708 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.