MALICIOUS
62
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1204.002 Malicious Link
The PDF document contains a large number of embedded external links, identified by the PDF_SEO_LINK_FARM heuristic. The document body text, while partially corrupted, includes a URL that is also present in the list of extracted URLs. This suggests the primary function of the document is to redirect users to a network of potentially malicious websites, possibly for SEO spam or to host further attack stages.
Heuristics 3
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
External URI info PDF_URIPDF contains an external URL action
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL http://lykkenkommerindefra.dk/uploads/1/3/1/1/131164130/131164130.html#cambiar+de+fraccion+a+decimal+ejemplos
- http://californiaradoncoalition.org/uploads/1/3/0/6/130621995/1f593861480.pdf
- http://josephvecchione.com/uploads/1/3/0/9/130969363/1212107.pdf
- http://iteropartnerlab.com/uploads/1/3/0/7/130775217/jefeb-loxiwewunilowos-getagij-zirarisolenane.pdf
- http://famcamper.nl/uploads/1/3/0/8/130874143/6374610.pdf
- http://jminvestmentplanning.com/uploads/1/3/1/0/131070327/zawusujawametujasa.pdf
- http://saesweets.com/uploads/1/3/0/6/130639734/tobejajodizazeseri.pdf
- http://waythroughthewildernesshandwovens.com/uploads/1/3/0/7/130739658/kijuputawekopadozeke.pdf
- http://www.mrshkwkh.co.uk/uploads/1/3/0/7/130775593/jenuxawatugenu.pdf
- http://www.nakomahomesandland.com/uploads/1/3/0/6/130621521/towekiguler-jukomiratid.pdf
- http://101travelphotos.com/uploads/1/3/0/5/130588700/wodarawexaxewaz.pdf
- http://autumncalica.net/uploads/1/3/0/5/130550722/zevujedeseri_bazulew_sizemigoxijesu_femawanoxerevew.pdf
- http://swfloridaframingservices.com/uploads/1/3/0/8/130814731/lokeke-jadozukub-naxodekulige.pdf
- http://www.cityparkphotography.com/uploads/1/3/0/4/130436367/rusewetemosaxabumafi.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Extracted artifacts 3
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000692f.bincc9156834f08cb0b1da6813beb76af120a48e78290d265354cdedae55b713ef4 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x692F | 9276 bytes |
font_01_sfnt_off00008ae2.bine2f1373bf3d70a40ff4276a486f0a1d2d32154e4f45ad1243a44c3d3b7d91cea |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x8AE2 | 2652 bytes |
font_02_sfnt_off0000944b.binfb0748da6da2a1f7232feb297295a3ed328ee898c567929ff1fa5cd99482ed5a |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x944B | 16064 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.