MALICIOUS
152
Risk Score
Malware Insights
MITRE ATT&CK
T1566.002 Spearphishing Attachment
T1059.001 PowerShell
The PDF file contains a large number of external links, many of which point to suspicious domains. The document body, though containing some obfuscated text, also includes these links, suggesting a phishing or redirection attempt. The ClamAV detection and ML classifier strongly indicate malicious intent, likely related to phishing or malware distribution via these links.
Machine Learning
- Nyx PDF Classifier malicious score 1.0000
Heuristics 3
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://lekelidoka.weebly.com/uploads/1/3/0/2/130289377/jelupop-xotaz.pdf
- http://mylaurabelle.com/uploads/1/3/0/2/130291975/4700412.pdf
- http://shumaisakhan.com/uploads/1/3/0/5/130548070/birunefakexanajifu.pdf
- http://donttakemysunshine.com/uploads/1/3/0/3/130323315/6041542.pdf
- http://amd11z.com/uploads/1/3/0/6/130620490/fadadejelusa_xeguv.pdf
- http://2019taiwancvcforum.com/uploads/1/3/0/7/130738652/nizebajivifew-faruvawedefawa-bojusejelagaf.pdf
- http://tereoongatiaukiwa.com/uploads/1/3/0/3/130323723/5409266.pdf
- http://marcapromocionales.com/uploads/1/3/0/5/130551775/97d33ad.pdf
- http://reednewday.com/uploads/1/3/0/5/130588231/5766022.pdf
- http://mychirosense.com/uploads/1/3/0/4/130483487/piloxigis_jiwikunal.pdf
- http://angelamaxfield.com/uploads/1/3/0/2/130287896/tezuliz.pdf
- http://cwcphysio.com/uploads/1/3/0/5/130542734/8115268.pdf
- http://rebeccalaplacaattia.com/uploads/1/3/0/2/130273626/130273626.html#honda+gc160+pressure+washer+manual
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000130f.bin031f1dfc681158f3f1c6ec669fa6a0d94eb1880efef1062d461ebf633149d70a |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x130F | 8320 bytes |
font_01_sfnt_off00005fbd.bind28a72c9259095c75412c3f2ed6f31e12a8a2af1384cf654c2d29f4d56f2b8aa |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x5FBD | 1592 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.