Malware Insights
The PDF file contains a large number of embedded external links, as indicated by the PDF_SEO_LINK_FARM heuristic. The ClamAV detection of 'Pdf.Phishing.TtraffRobotInstall-7605656-0' further supports a malicious intent, likely related to phishing or traffic redirection. The document body, though partially corrupted, contains text related to learning Spanish and includes several of the extracted URLs, suggesting a lure to engage the user. The primary attack pattern involves directing users to a network of external PDF documents hosted on various domains.
Heuristics 3
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL http://gadazeju.debretagnevirtu.com/uploads/2020/01/28/5892370.pdf
- http://jixeru.panda-opt.ru/uploads/2020/01/28/75e1352140d.pdf
- http://steercrazyquarterhorses.com/uploads/1/3/0/4/130435622/kubevu.pdf
- http://jumexo.flowers38.ru/uploads/2020/01/28/1374212.pdf
- http://raj.asolar.shop/uploads/2020/01/27/jelelani.pdf
- http://staywiththeproblems.com/uploads/1/3/0/6/130620390/6713989.pdf
- http://mepo.promyvkapto.ru/uploads/2020/01/27/mireferubunur-lewejoleranu-vinezalibemuza-regibe.pdf
- http://datuvi.rangoro.pro/uploads/2020/01/28/1174731.pdf
- http://menosuxesi.russtin.com/uploads/2020/01/28/3cb0f4.pdf
- http://annotalegal.com/uploads/1/3/0/4/130489253/130489253.html#book+for+learning+spanish
Extracted artifacts 1
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00001218.bin5668a4a30459d91626e7a4ff801e155e5328180eb42ae3dda2d8dcede5ae5de5 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x1218 | 8796 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.