MALICIOUS
150
Risk Score
Malware Insights
MITRE ATT&CK
T1566.002 Spearphishing Attachment
T1059.001 PowerShell
The PDF file was identified as malicious by ClamAV and an ML classifier, with critical heuristics indicating a large number of embedded external links. The document body contains numerous URLs, such as http://microtiasurgery.net/uploads/1/3/0/6/130604140/welizixa.pdf, which are likely used to redirect users to phishing sites or download further malicious content. No scripts were extracted from this sample.
Machine Learning
- Nyx PDF Classifier malicious score 1.0000
Heuristics 3
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL http://microtiasurgery.net/uploads/1/3/0/6/130604140/welizixa.pdf
- http://ns1.shownosocks.com/uploads/1/3/0/7/130775810/3993723.pdf
- http://www.spheremh.net/uploads/1/3/0/3/130313046/720767.pdf
- http://www.funnelstrong.com/uploads/1/3/0/5/130543764/8164585.pdf
- http://ww2.thumbprintgallerysd.com/uploads/1/3/0/5/130547624/lenaj-zivabexoxage-rewatelale.pdf
- http://rachelsaitzyk.com/uploads/1/3/0/7/130739781/9942232.pdf
- http://smtfun.club/uploads/1/3/0/7/130739836/kediwikowegoxilozita.pdf
- http://tabernacleoffaithbaptistchurch.com/uploads/1/3/0/5/130590653/153258.pdf
- http://geoffcodeswebsite.com/uploads/1/3/0/5/130588733/6a995bad3.pdf
- http://mail.stop-roken-coach.nl/uploads/1/3/0/6/130605416/9442712.pdf
- http://www.nimbledevices.com/uploads/1/3/0/4/130488141/tumuxomamiwux.pdf
- http://redfishbeaufort.com/uploads/1/3/0/9/130969149/rubarobejeg_fosavaduneba.pdf
- http://happyhorsehollow.com/uploads/1/3/0/6/130604685/tiraxitelip-lakujudowovofi-wagun.pdf
- http://mcsocialelites.com/uploads/1/3/0/6/130620521/795691.pdf
- http://rx-fitnessmalaysia.com/uploads/1/3/0/5/130590654/zexopomalutoziv_mexadixarofu_wosaz.pdf
- http://dev2018.digcitinstitute.com/uploads/1/3/0/2/130289367/130289367.html#can+cardiac+tamponade+cause+cardiogenic+shock
Extracted artifacts 1
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00003b31.bin7bcca8bd223347dedabbdf7a315f24a0011243cb6a31f6141fdad26a367043a1 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x3B31 | 7820 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.