MALICIOUS
150
Risk Score
Malware Insights
MITRE ATT&CK
T1566.002 Spearphishing Attachment
T1204.002 Malicious Link
The PDF contains a large number of embedded external links, identified by the PDF_SEO_LINK_FARM heuristic. The ClamAV detection and ML classifier strongly indicate malicious intent. The primary attack pattern involves directing users to a multitude of PDF files hosted on various domains, likely as a phishing or malware distribution scheme.
Machine Learning
- Nyx PDF Classifier malicious score 1.0000
Heuristics 3
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL http://thevivaciouslivingcompany.com/uploads/1/3/0/2/130271023/bakemorak-pubiniwekutavub-nepune-nuxugugab.pdf
- http://helpstagemyhouse.com/uploads/1/3/0/2/130288887/dutivonomigitu-sumaresonek-puxosigu-kulutakoz.pdf
- http://ateliernewstory.com/uploads/1/3/0/3/130323295/6785613.pdf
- http://www.quinordcompany.com/uploads/1/3/0/2/130272452/4824967.pdf
- http://djpoolie.com/uploads/1/3/0/5/130544190/9854407.pdf
- http://kesquakenbush.net/uploads/1/3/0/4/130477915/fubezobuze_xawopiganij_wupijidija.pdf
- http://williamledbetterfoundation.org/uploads/1/3/0/2/130273571/3240430.pdf
- http://gurzuf.taxi/uploads/1/3/0/7/130739889/bexuxuxagolid.pdf
- http://anilkonkimalla.com/uploads/1/3/0/7/130776078/5195977.pdf
- http://benkregel.com/uploads/1/3/0/5/130551303/bujilixurutekurad.pdf
- http://marianbelgray.com/uploads/1/3/0/5/130539179/5385070.pdf
- http://www.frederickmedsolutions.com/uploads/1/3/0/7/130776775/3953799.pdf
- http://bcsgrubbox.com/uploads/1/3/0/5/130589182/aa61d3.pdf
- http://shaydanielleesthetics.com/uploads/1/3/0/2/130289247/werasamavo.pdf
- http://www.elisajuncosa.com/uploads/1/3/0/6/130604459/699583db96.pdf
- http://missteendreamusa.com/uploads/1/3/0/4/130489696/fuxizaxuvi-biluva.pdf
- http://hinterlandtreeservicesbyronbay.com/uploads/1/3/0/5/130590464/130590464.html#water+cooled+chiller+preventive+maintenance+checklist
Extracted artifacts 1
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00004889.bine8bf3b20e47191eea60d47ca42fbf1d35ebca607cff5a05f94064b7ce73f80db |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x4889 | 8440 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.