MALICIOUS
152
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1204.002 Malicious Link
The PDF file was flagged by multiple heuristics, including a critical alert for a large number of external PDF links, indicating a link farm. The ML classifier and ClamAV also identified it as malicious, specifically as a phishing or traffic-generating PDF. The document body contains numerous URLs pointing to PDF files hosted on various domains, suggesting a campaign to drive traffic or distribute malicious content through these links.
Machine Learning
- Nyx PDF Classifier malicious score 0.9999
Heuristics 3
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL http://thingstodoambercove.com/uploads/1/3/0/4/130435902/fisad_soxiku.pdf
- http://nsuxa.net/uploads/2020/01/27/b0600.pdf
- http://nolamadef.vipiski-online8.icu/uploads/2020/01/28/gotumapetukudaxo.pdf
- http://cathyhepworth.com/uploads/1/3/0/5/130589313/zeminudenenolaref.pdf
- http://8760athletics.fit/uploads/1/3/0/6/130621330/pubekige.pdf
- http://teachinggeographybusinesscommerceaustralia.com/uploads/1/3/0/4/130476573/3888169.pdf
- http://sgdpress.com/uploads/1/3/0/4/130490378/nasegader.pdf
- http://joni.girls23.pro/uploads/2020/01/28/vomiwop_nakizoduzakix.pdf
- http://mpedotaclan.weebly.com/uploads/1/3/0/6/130621082/sabomumivodaj.pdf
- http://tasurupate.xalat24.ru/uploads/2020/01/29/402a8.pdf
- http://vinylatm4ud.com/uploads/1/3/0/6/130621702/mowaredomaju.pdf
- http://gratisguidelanzarote.weebly.com/uploads/1/3/0/6/130621248/kalaju_jojewigipipawus_detevafu.pdf
- http://siphc.net/uploads/1/3/0/6/130604147/nopirunuxa.pdf
- http://witwtravel.com/uploads/1/3/0/6/130620916/bitozigudulizok_fawome_mufofika_wogigazibe.pdf
- http://clean-cooling.org/uploads/1/3/0/6/130621374/130621374.html#aristotle%27+s+metaphysics+pdf
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off000012fd.binfe9243626eb0829ef3ff4c6659ee53a5e741665fa619820249d0161411ef59ac |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x12FD | 8292 bytes |
font_01_sfnt_off0000ab6d.bin561064ce3700ea4d9ffcd2917595f4c53fc3fa74aa0a111772fa3db381b922e9 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xAB6D | 3360 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.