MALICIOUS
120
Risk Score
Malware Insights
MITRE ATT&CK
T1566.002 Spearphishing Attachment
T1204.002 Malicious Link
The PDF file contains a large number of embedded external links, as indicated by the PDF_SEO_LINK_FARM heuristic. The ClamAV detection of 'Pdf.Phishing.TtraffRobotInstall-7605656-0' further supports a malicious classification. The embedded URLs are likely used to redirect users to phishing sites or to distribute further malware, aligning with a phishing or SEO-based attack pattern.
Heuristics 3
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL http://musesinthevineyard.com/uploads/1/3/0/5/130588257/c8ff2.pdf
- http://www.plenaformacenter.com/uploads/1/3/0/6/130604765/punobotaxanaxodivamu.pdf
- http://b-24-thegreenhornet.net/uploads/1/3/0/4/130489909/5071253.pdf
- http://musclealignment.com/uploads/1/3/0/4/130483983/tibofozujope_wafedobenu.pdf
- http://www.9iceguyssecuritysteward.co.uk/uploads/1/3/0/4/130483990/bafasu.pdf
- http://www.archiveauto.us/uploads/1/3/0/8/130813548/koduto.pdf
- http://www.plasticoceanproject.com/uploads/1/3/0/7/130775242/d09ed6.pdf
- http://sentinel.ai/uploads/1/3/0/2/130289429/mivotetixukalu_woravajaretow_sobizog_bogawubafeg.pdf
- http://mrmacbible.org/uploads/1/3/0/7/130740264/riniguwoduwarejasit.pdf
- http://mgdogwalking.com/uploads/1/3/0/6/130620424/5dfd9b6b01a95c.pdf
- http://masonstreettextiles.com/uploads/1/3/0/7/130739727/76b264.pdf
- http://rachelhimes.com/uploads/1/3/0/3/130312969/sakikanomufurina.pdf
- http://www.strategizeme.com/uploads/1/3/0/6/130604182/3f7f86.pdf
- http://www.clarkesblacksmithing.com/uploads/1/3/0/8/130874012/378d77946.pdf
- http://karmatax.net/uploads/1/3/0/5/130590698/vanepuwegak.pdf
- http://clarkseedsllc.com/uploads/1/3/0/6/130621055/2ef1c4ce7f4ac34.pdf
- http://tascdist4.org/uploads/1/3/0/7/130776678/f83dfab7354f4.pdf
- http://lindathelifecoach.com/uploads/1/3/0/6/130639147/ce572c1e7.pdf
- http://theporterauthority.com/uploads/1/3/0/5/130539706/1709540.pdf
- http://ilostmystuff.net/uploads/1/3/0/4/130488217/220605249933.pdf
- http://shopbelfast.info/uploads/1/3/0/4/130490193/130490193.html#how+to+use+scrabble+score+sheet
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00002e22.bind907c570f1f8f2d62f38d7529dbf77de46ca3a1917ec53aca7a78bae59874b04 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x2E22 | 2616 bytes |
font_01_sfnt_off000039bc.bin3ff8b495ad5c1f7ad6ce24a6ca17f86adbde3966b22c148069e04211737ee3ea |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x39BC | 7796 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.