Malware Insights
The PDF contains a large number of external links, many of which are dynamically generated and point to seemingly unrelated domains, indicating a link farm or SEO abuse tactic. The document body, though partially corrupted, contains text suggesting it is an 'Ohsas 18001 checklist pdf', a common lure for users seeking compliance documents. The presence of numerous PDF links, combined with the invoice/payment lure heuristic, suggests the primary goal is to redirect users to potentially malicious websites or download further malware. No scripts were extracted from this sample.
Heuristics 4
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Fake invoice / payment lure low SE_INVOICE_LUREDocument contains invoice or payment language paired with an action verb — useful context when combined with link, macro, or attachment indicators
-
External URI info PDF_URIPDF contains an external URL action
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL http://805.bpmtc.com/uploads/1/3/1/4/131452983/131452983.html#ohsas+18001+checklist+pdf
- http://damianconstruction.com/uploads/1/3/0/7/130740151/kafezefero-midota-pudejorufolalo-losedifib.pdf
- http://topdogwoodworks.com/uploads/1/3/0/5/130588727/182422.pdf
- http://venturavineyards.com/uploads/1/3/0/4/130488220/bc64a.pdf
- http://bbkconsultants.com/uploads/1/3/0/7/130776358/b75bfeb8ae6.pdf
- http://sandiegofurnishedrentals.com/uploads/1/3/0/4/130488338/2478214.pdf
- http://thewholisticyou.com/uploads/1/3/0/7/130775510/cb57f.pdf
- http://solone.com.sg/uploads/1/3/1/4/131452989/lifagimedalebaw.pdf
- http://misfit-world.com/uploads/1/3/0/6/130621280/supifololepes_wuvofuxokuf_zanuzudenid.pdf
- http://fsnederland.nl/uploads/1/3/0/5/130541140/busumexopigeroni.pdf
- http://bei-eliza.com/uploads/1/3/0/6/130620248/vubadakemivade.pdf
- http://twofatolives.com/uploads/1/3/0/6/130604780/d3a3a5bc26cc9af.pdf
- http://besthealthandfreedom.com/uploads/1/3/1/4/131483005/xilafavamuxo.pdf
- http://805.bpmtc.com/uploads/1/3/1/4/131452983/terms.html
- http://805.bpmtc.com/uploads/1/3/1/4/131452983/dmca.html
- http://805.bpmtc.com/uploads/1/3/1/4/131452983/policy.html
- https://rogofuxeviso.files.wordpress.com/2020/06/jilebibivigivoraneruwe.pdf
- https://nepumoja.files.wordpress.com/2020/06/30259128534.pdf
- https://lotopakaxil.files.wordpress.com/2020/06/vugavixesisozeze.pdf
- https://kataxufekor.files.wordpress.com/2020/06/13870633037.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Extracted artifacts 1
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00008742.bin22ac867e0a0ae1f875a9bc479b2dbf58253aa44428a82a99c8e04a9a615134da |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x8742 | 11176 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.