MALICIOUS
150
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.001 PowerShell
The PDF file contains a large number of embedded URLs pointing to other PDF files, a technique often used for SEO manipulation or to distribute malicious content. The ClamAV detection and ML classifier strongly indicate malicious intent. The document body, though heavily obfuscated, appears to be a lure for educational materials, which is a common tactic for phishing or malware distribution.
Machine Learning
- Nyx PDF Classifier malicious score 1.0000
Heuristics 3
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL http://speakup.london/uploads/1/3/0/7/130738924/xujipezagefoxo_ruvokogi.pdf
- http://www.goldencircleent.com/uploads/1/3/0/5/130543682/5122464.pdf
- http://dieselmagic.net/uploads/1/3/0/8/130874261/c5f60526.pdf
- http://thekookas.com/uploads/1/3/0/7/130739232/4531573.pdf
- http://www.bextraordinaire.com/uploads/1/3/0/8/130814717/xavobus.pdf
- http://www.createdesignrestore.com/uploads/1/3/0/2/130288630/af28e320af4a.pdf
- http://shoppivotalchocolates.com/uploads/1/3/0/7/130775203/9889243.pdf
- http://thenewblueworld.com/uploads/1/3/0/7/130775478/8160787.pdf
- http://hostmaster.gastrokidzz.ch/uploads/1/3/0/5/130589050/gonujej_fuwisib.pdf
- http://pbcdac.com/uploads/1/3/0/7/130776275/dipig.pdf
- http://cruisecrtl.com/uploads/1/3/0/4/130435697/4605072.pdf
- http://getpinbox.com/uploads/1/3/0/3/130379141/3a9d1c.pdf
- http://zealgum.com/uploads/1/3/0/6/130640190/fozes.pdf
- http://ourchildrensfund.com/uploads/1/3/0/5/130551718/f95b21a9e.pdf
- http://mail.norcalconcrete.com/uploads/1/3/0/6/130603760/60183ef4246.pdf
- http://besmokefree.co.nz/uploads/1/3/0/4/130436451/2d8903ce811fa.pdf
- http://iamtaylor.net/uploads/1/3/0/6/130639784/5b6e8df76.pdf
- http://one-heart-one-soul.org/uploads/1/3/0/2/130274241/1c0727.pdf
- http://alpha.withcarry.com/uploads/1/3/0/9/130969298/xumemote-suzutepate-vupobefiduj-zagifob.pdf
- http://matthewbrooke.com/uploads/1/3/0/6/130639244/gapivagonivok.pdf
- http://gifsagainsthumanity.com/uploads/1/3/0/4/130491001/39cc29f.pdf
- http://steelbullets.com/uploads/1/3/0/4/130483402/3210739.pdf
- http://host12.pleasingfood.com/uploads/1/3/0/7/130740244/130740244.html#pre+algebra+math+packet+pdf
Extracted artifacts 1
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00001e0c.bind88df3206c15462b72dc1afd9b5a4dc7b34350167a2de665e8dc2e1dfbb16ffb |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x1E0C | 7844 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.