MALICIOUS
62
Risk Score
Malware Insights
MITRE ATT&CK
T1566.002 Spearphishing Attachment
T1204.002 Malicious Link
The PDF document contains a large number of external links pointing to various domains, a technique often used for SEO link farms or to distribute malicious content. The heuristic 'PDF_SEO_LINK_FARM' specifically flags this behavior. The embedded URLs and the document body suggest a lure related to product parts or information, directing users to a network of PDF files hosted on numerous unrelated domains. No scripts were extracted, limiting the ability to determine a specific payload.
Heuristics 3
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
External URI info PDF_URIPDF contains an external URL action
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL http://avabaycompany.com/uploads/1/3/0/7/130738949/130738949.html#karcher+k+3.86+parts
- http://salondefiestascapital.com/uploads/1/3/0/5/130541285/zusajutunapeb.pdf
- http://ficat.us/uploads/1/3/0/6/130621436/788157.pdf
- http://runningcode3.net/uploads/1/3/1/0/131070167/miwugukoxusefad_kazajavefuf_xurosuxerasa.pdf
- http://lf-ant.com/uploads/1/3/1/4/131437544/fakaselefamuwo_fofijulalexo.pdf
- http://fannyericsson.com/uploads/1/3/0/8/130874635/xorizejomud_sewafazivusilid.pdf
- http://tigerser.com/uploads/1/3/0/5/130550993/pinunap.pdf
- http://hcnnelsonjewelers.com/uploads/1/3/1/3/131378897/4738088.pdf
- http://cencalpgf.com/uploads/1/3/0/7/130776177/8f8633649a4a3.pdf
- http://bozemanradiant.com/uploads/1/3/1/4/131437766/xuvamufizutududifisi.pdf
- http://kattpittman.com/uploads/1/3/0/7/130739154/07c9bd.pdf
- http://computanti.com/uploads/1/3/0/3/130379178/54224.pdf
- http://cohorsiustorum.org/uploads/1/3/0/2/130289734/4261539.pdf
- http://life-with-lemons.com/uploads/1/3/0/3/130324350/67680a38e0.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Extracted artifacts 1
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off000061bc.bin188aabd1291b7a015d18ff836e01e9fca6ba0af7c55e5425b5d076ca4ea7bcbd |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x61BC | 7828 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.