MALICIOUS
92
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1204.002 Malicious Link
The PDF file contains a large number of external links, many of which are numerically or generically named and hosted on unrelated domains, indicating a link farm or SEO manipulation tactic. The document body, though heavily obfuscated, contains references to 'article about social media pdf' and the wkhtmltopdf generator, suggesting a lure to external content. The presence of numerous PDF_URI and PDF_SEO_LINK_FARM heuristics strongly supports this. No scripts were extracted from this sample.
Machine Learning
- Nyx PDF Classifier malicious score 0.9961
Heuristics 3
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
External URI info PDF_URIPDF contains an external URL action
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL http://calgarybrokerageproposal.com/uploads/1/3/1/3/131384254/131384254.html#article+about+social+media+pdf
- http://disneymovieworld.com/uploads/1/3/1/3/131380086/3f5e0da4661.pdf
- http://coastcards.net/uploads/1/3/0/7/130775668/b6320.pdf
- http://carpetcleaningchattanoogatn.com/uploads/1/3/1/4/131437359/2941429.pdf
- http://cleansetocalm.com/uploads/1/3/0/7/130776200/8929142.pdf
- http://thechefonice.com/uploads/1/3/1/4/131452732/026a90a78404de.pdf
- http://edgemereestate.com/uploads/1/3/0/5/130539269/tefefexobexuvu-solewefere-xegekenugovuma-lidete.pdf
- http://qbinvictus.com/uploads/1/3/1/6/131606526/visipu_wudefowabijof_lubapiv.pdf
- http://sprinklerrepairfresno.com/uploads/1/3/1/4/131407367/3306942.pdf
- http://munchiesbistrocafe.com/uploads/1/3/1/4/131483217/pasiletaduk.pdf
- http://annehoitink.nl/uploads/1/3/1/4/131453573/2ba7434be.pdf
- http://promexdistributionllc.com/uploads/1/3/1/4/131407537/sovapomofoxad-rodumizomuxoj-zezojukisikup-jetejobo.pdf
- http://bridlewoodyoga.com/uploads/1/3/0/7/130775632/rolojet_famedivo_bexeko.pdf
- http://mbpphotobooths.com/uploads/1/3/0/6/130605357/b445c1.pdf
Open this report in the interactive analyzer, or submit your own file for analysis.