MALICIOUS
62
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1204.002 Malicious Link
The PDF file contains numerous external links, a technique often used for SEO link farming to manipulate search engine results. The document body text, though heavily obfuscated, includes a phrase suggesting it is a lure for "Stp mathematics 3a answers pdf". The primary heuristic identified a link farm with 27 external PDF links, predominantly hosted on sd-homes-llc.com. No scripts were extracted from this sample.
Heuristics 3
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
External URI info PDF_URIPDF contains an external URL action
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL http://web3.pleasingfood.com/uploads/1/3/0/6/130605041/130605041.html#stp+mathematics+3a+answers+pdf
- http://sd-homes-llc.com/uploads/1/3/0/2/130289587/kurevoki.pdf
- http://lalunasoul.com/uploads/1/3/0/7/130776319/dbdcb09943.pdf
- http://kevincourt.com/uploads/1/3/1/4/131452934/diwid.pdf
- http://missoulawindowtinting.net/uploads/1/3/0/3/130323612/saxefatofipilinukafi.pdf
- http://web3.pleasingfood.com/uploads/1/3/0/6/130605041/terms.html
- http://web3.pleasingfood.com/uploads/1/3/0/6/130605041/dmca.html
- http://web3.pleasingfood.com/uploads/1/3/0/6/130605041/policy.html
- https://vijulow119455843.files.wordpress.com/2020/06/wonikemubagonife.pdf
- https://beburan.files.wordpress.com/2020/06/73775908292.pdf
- https://sunoxel.files.wordpress.com/2020/06/75176510013.pdf
- https://jedidaridov.files.wordpress.com/2020/06/roxog.pdf
- https://wuwuwomelar.files.wordpress.com/2020/06/76743713001.pdf
- https://vafegavajip.files.wordpress.com/2020/06/76936668556.pdf
- https://wutamewoj.files.wordpress.com/2020/06/pimimofagasufuze.pdf
- https://kajiwudejov.files.wordpress.com/2020/06/warofexabepiromerikom.pdf
- https://zojibulo.files.wordpress.com/2020/06/vugisumagumubotakiw.pdf
- https://degopufavaka197341346.files.wordpress.com/2020/06/78153081130.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000a9a6.bind74454bef7f7caecb5d0e8048443ee1e61a62e05458c36f4aaf014d5e9b2ab8c |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xA9A6 | 11208 bytes |
font_01_sfnt_off0000d020.binf3b752e25d2e3098dc5b351a512c5ca672d2b137fcb7ddb3f81b2384be51d5c3 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xD020 | 16072 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.