MALICIOUS
94
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.001 PowerShell
The PDF contains a large number of external links, identified by the PDF_SEO_LINK_FARM heuristic, pointing to various domains. The ML classifier also strongly indicated maliciousness. The document body contains a mix of seemingly unrelated text and URLs, suggesting a spam or SEO poisoning tactic. No scripts were extracted from this sample.
Machine Learning
- Nyx PDF Classifier malicious score 1.0000
Heuristics 4
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL http://iweargreatness.com/uploads/1/3/0/2/130289431/130289431.html#gana+achu+new+hd+video+song
- http://trianglebusinessnetworks.com/uploads/1/3/0/4/130435955/zopojutugegolag-tikeke-xegaboziz.pdf
- http://massagebylisa.net/uploads/1/3/0/7/130739775/ce4e19e8ad2a463.pdf
- http://lookingwithin.ca/uploads/1/3/1/4/131438692/b0acc7d25dbff8.pdf
- http://bulldogrestorationservices.org/uploads/1/3/0/7/130776149/vududalumawog_tolavajafa_ronodibev.pdf
- http://ileftmyangel.com/uploads/1/3/0/9/130969939/guxupugebejekavutixe.pdf
- http://21centuryhs.com/uploads/1/3/0/7/130775427/6958500.pdf
- http://aircheckmoncton.com/uploads/1/3/0/5/130543212/8268a98d666b.pdf
- http://celestialharmonyproductions.com/uploads/1/3/1/3/131381614/ridisavojegazojoz.pdf
- http://createcapitaladvisors.com/uploads/1/3/0/3/130379297/2117239.pdf
- http://greatrecessframework.org/uploads/1/3/1/4/131438610/likunimikij.pdf
- http://parktowncommunion.net/uploads/1/3/0/5/130589442/foluvimomozaduxo.pdf
- http://polycarbonatewholesale.com/uploads/1/3/0/6/130604492/8230679.pdf
- http://oasistankservices.com/uploads/1/3/0/5/130589202/151898.pdf
- http://theroguerobots.com/uploads/1/3/0/5/130551187/julobexo.pdf
- http://espanola-vbbc.org/uploads/1/3/0/5/130540293/124758b42d2f.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off000059e6.bincbcc920ab5d2b44bcc1e224549894d5e107ba9402fed944d7431f014b510e208 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x59E6 | 9512 bytes |
font_01_sfnt_off00007372.bindb68a57132c8148cf528a89566c71060ca8363ba66987885241212b04a17798c |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x7372 | 10692 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.