MALICIOUS
152
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
The PDF document was flagged by multiple heuristics, including a critical finding for a link farm containing numerous external PDF URLs. The ML classifier and ClamAV also identified it as malicious, specifically as a phishing or redirector. The embedded URLs likely lead to further malicious content or phishing pages, aiming to trick users into downloading further payloads or submitting credentials.
Machine Learning
- Nyx PDF Classifier malicious score 1.0000
Heuristics 3
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL http://doodletoyshop.com/uploads/1/3/0/7/130775690/24081fb744.pdf
- http://weldamania.com/uploads/1/3/0/4/130483200/5711815.pdf
- http://staffpicked.com/uploads/1/3/0/6/130604315/344393dee34f.pdf
- http://legoutdulibre.org/uploads/1/3/0/6/130621024/bafawiwozogop.pdf
- http://vreedy.shop/uploads/1/3/0/5/130550901/761b390e9e2656.pdf
- http://e1shipperpro.com/uploads/1/3/0/3/130323765/9598281.pdf
- http://ccevenice.com/uploads/1/3/0/7/130776601/9152563.pdf
- http://myfruitsoflife.net/uploads/1/3/0/3/130323674/vopirelux_bejonatoropifu_lopodafip_temavaled.pdf
- http://imaginecaredigitalhealth.net/uploads/1/3/0/7/130739124/6941637.pdf
- http://firezoneschaumburg.com/uploads/1/3/0/4/130436282/bovizaf.pdf
- http://cephproject.org/uploads/1/3/0/2/130272636/vekinagezo_jobifamuw_tesenujulogago_zutapidawifemep.pdf
- http://advanceadvocacyandsupport.com/uploads/1/3/0/3/130379305/wuwovegobe.pdf
- http://thatclassiccarshow.com/uploads/1/3/0/4/130476628/jiziposivuw_bubezinafowob_mupavagedasoto.pdf
- http://homemodularsystems.com/uploads/1/3/0/5/130588266/nesuxinujanek.pdf
- http://resourcesforthesoul.com/uploads/1/3/0/7/130739629/7506748.pdf
- http://strengtheningfamiliesalaska.com/uploads/1/3/0/6/130639729/4fe7aaffe.pdf
- http://allamericandogexpo.com/uploads/1/3/0/5/130551457/130551457.html#conversation+starters+for+english+learners
Extracted artifacts 1
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00003726.binfac0b3f4e20c94739eec0b77841e531589b74b691efd29235058dfd530c30a00 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x3726 | 7748 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.