MALICIOUS
160
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
The PDF contains a mass external link farm pointing to other PDFs, identified by the 'PDF_SEO_LINK_FARM' heuristic. The ClamAV detection 'Pdf.Phishing.TtraffRobotInstall-7605656-0' and the ML classifier output strongly indicate malicious intent. The document body, despite being heavily obfuscated, suggests a lure related to a 'pay commission calculator' for teachers, combined with a call-to-action phrase, likely to trick users into downloading the linked malicious content.
Machine Learning
- Nyx PDF Classifier malicious score 0.9995
Heuristics 4
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
-
Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTONDocument contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL http://down-the-block.com/uploads/1/3/0/5/130551023/wakijuz.pdf
- http://aialumassage.com/uploads/1/3/0/2/130289611/34aaed6ae.pdf
- http://www.minimalteacher.com/uploads/1/3/0/5/130551920/c3d5430a53.pdf
- http://my-zero-stress.com/uploads/1/3/0/6/130604162/pufisitif.pdf
- http://enduringlovememorials.com/uploads/1/3/0/6/130621906/2750493.pdf
- http://justgreatcareers.com/uploads/1/3/0/6/130621051/4358805.pdf
- http://nakedroots1.com/uploads/1/3/0/5/130543369/nuwakujabapaw.pdf
- http://maltaglasscreations.com/uploads/1/3/0/4/130477335/30c9a9f100e.pdf
- http://artsestate.com.au/uploads/1/3/0/6/130605094/guvotuna.pdf
- http://app5.online/uploads/1/3/0/2/130270813/lirodu.pdf
- http://bakednbonedpdx.com/uploads/1/3/0/2/130289322/kuwozesusaxed.pdf
- http://ihrtechservices.net/uploads/1/3/0/5/130589036/vonufamivigipeg_rujokuz_ramakoxadig.pdf
- http://slumber.blog/uploads/1/3/0/7/130739520/fitoranogufeletutos.pdf
- http://canopymgm.com/uploads/1/3/0/6/130604125/93e37c3610aa.pdf
- http://www.visualjunkie.co/uploads/1/3/0/4/130436173/87cfc093.pdf
- http://newcoursecompliance.com/uploads/1/3/0/5/130588627/4b162bccd1eae87.pdf
- http://driedspicedapples.com/uploads/1/3/0/2/130291441/zexogowupuzi_tonerukiwakuti_kovutuwisusa.pdf
- http://screencircus.com/uploads/1/3/0/5/130589180/bebarizapipafu-sezudugezesu-wudenuragitolog.pdf
- http://godofsea.org/uploads/1/3/0/7/130739286/somibofodulego.pdf
- http://taiyangchengyazhouxinyukoubeiruhe.f18.ebkf.org/uploads/1/3/0/2/130289669/nisuxagorekuw.pdf
- http://margeauxsplace.net/uploads/1/3/0/4/130476866/polirukukow-xewuwo.pdf
- http://battlebuilding.com/uploads/1/3/0/8/130815008/3823582.pdf
- http://democrathollow.com/uploads/1/3/0/4/130483864/3698815.pdf
- http://myeclecticyoga.com/uploads/1/3/0/7/130775732/timajizoxetisapolu.pdf
- http://graysay.tech/uploads/1/3/0/6/130621865/detivit-jovitanipege.pdf
- http://host10.carmichaelnl.com/uploads/1/3/0/3/130323506/130323506.html#wb+pay+commission+calculator
- http://fedorahosted.org/lohit
- https://savannah.gnu.org/projects/freefont/
- http://www.gnu.org/licenses/
- http://www.gnu.org/copyleft/gpl.html
Extracted artifacts 3
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off000030fa.bin1723f1ced37cc89d69e30f3df6281c5e5fb8989544fd4587aa75b00c91af2fd0 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x30FA | 1388 bytes |
font_01_sfnt_off000039ac.bin1141f4b585f7c2395d0579cd17b35ed3829783ae54df35802d59f46a7f28d5bd |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x39AC | 13356 bytes |
font_02_sfnt_off0000607a.bine57fae0141bbe740e159b2cc7940f862b0d05b866f5d67109b5706ed6c41882d |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x607A | 8236 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.