MALICIOUS
152
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
The PDF contains a mass external link farm with 31 links, indicating a likely SEO manipulation or content distribution scheme. The embedded URLs point to numerous domains, suggesting a broad campaign. ClamAV detection as 'Pdf.Phishing.TtraffRobotInstall-7605656-0' and the ML classifier's high confidence further support the malicious nature of this document.
Machine Learning
- Nyx PDF Classifier malicious score 0.9999
Heuristics 3
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL http://74-123-72-69.mgwnet.com/uploads/1/3/0/6/130604305/5943428.pdf
- http://shiweiyulechengxinyuzenmeyang.jhamrick.com/uploads/1/3/0/6/130604733/6244086.pdf
- http://weddingproct.com/uploads/1/3/0/5/130543941/d9b0babe.pdf
- http://www.hockessinwalkintubs.com/uploads/1/3/0/5/130550972/rexewixixonu.pdf
- http://nuancetravelacademy.com/uploads/1/3/0/7/130776158/dejesewuzepi.pdf
- http://campbellreither.com/uploads/1/3/0/5/130590778/f119f87d7.pdf
- http://rodiermail.com/uploads/1/3/0/8/130813658/remekobufavu_juduvodipurabob.pdf
- http://aerogreen.solutions/uploads/1/3/0/5/130544063/jotepofalujosadawu.pdf
- http://xinaobotianshangrenjianyule.br3h.com/uploads/1/3/0/5/130542965/c08df8de61.pdf
- http://innerfish.com/uploads/1/3/0/7/130739827/4322934.pdf
- http://iqseries.de/uploads/1/3/0/2/130289546/delosimupetigirut.pdf
- http://www.temmasbatmitzvahproject.com/uploads/1/3/0/7/130775056/dinajokuzi.pdf
- http://www.lebanon2025.com/uploads/1/3/0/7/130738684/galolekipajepovu.pdf
- http://trailofhumanity.com/uploads/1/3/0/8/130873914/bec8aeb5.pdf
- http://priyabery.com/uploads/1/3/0/4/130478106/vojabixigeves_rutaxilab.pdf
- http://mta-sts.scituatefarmersmarket.com/uploads/1/3/0/6/130621511/f9ce32940847709.pdf
- http://fella-ship.com/uploads/1/3/0/7/130739727/48551933.pdf
- http://salvosurfboards.com/uploads/1/3/0/8/130814774/bonija.pdf
- http://zingcomic.com/uploads/1/3/0/6/130604258/bilojekiganomod_tupedarunirar_kawaxebusur_vosugewelo.pdf
- http://nupelicanparty.org/uploads/1/3/0/8/130814508/130814508.html#abirami+andhadhi+slokam
- https://savannah.gnu.org/projects/freefont/
- http://www.gnu.org/licenses/
- http://www.gnu.org/copyleft/gpl.html
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00003cdb.bin7f009808a9ab285e6e15363cbd235ec3f1c1bfb449760aa50ee8aeeb5c6c2052 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x3CDB | 16912 bytes |
font_01_sfnt_off00006cd9.bindc4ef140040bd9a29001019dabe614b09b306e9b13dffea837dbeac5765d7a07 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x6CD9 | 8236 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.