MALICIOUS
94
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.001 PowerShell
The PDF document contains a large number of external links, identified by the PDF_SEO_LINK_FARM heuristic. The document body, though partially corrupted, contains text related to 'Wings of Fire books' and wkhtmltopdf, suggesting a lure to a seemingly innocuous topic. The primary function appears to be directing users to a vast network of URLs, likely for SEO spam or to host further malicious content. No scripts were extracted from this sample.
Machine Learning
- Nyx PDF Classifier malicious score 1.0000
Heuristics 4
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL http://reedalec.com/uploads/1/3/0/3/130323764/130323764.html#wings+of+fire+books+in+order+1-13
- http://www.laihlasmum.com/uploads/1/3/0/5/130590140/tefotezir.pdf
- http://www.myaishaalzaabi.com/uploads/1/3/0/6/130639924/fexuziwanef.pdf
- http://enchantingtherapies.com/uploads/1/3/0/2/130287289/6682406.pdf
- http://damiautopflege.ch/uploads/1/3/0/8/130873876/vipul.pdf
- http://impeccablyhandmade.com/uploads/1/3/0/7/130739146/xutuvorop_wavidiba.pdf
- http://ready2mediate.com/uploads/1/3/0/7/130739103/2747660.pdf
- http://myessentialguide.com/uploads/1/3/0/7/130739811/9587559.pdf
- http://bostonerrandservices.com/uploads/1/3/0/3/130313363/pakowufu_giwimozuweju.pdf
- http://qianyiyulechengdailizhuce.f18.ebkf.org/uploads/1/3/0/8/130814219/7136928.pdf
- http://simplytc4me.com/uploads/1/3/0/7/130776719/7710432.pdf
- http://childrensxmasparty.fun/uploads/1/3/0/7/130739718/4744331.pdf
- http://newframeofmind.com/uploads/1/3/0/2/130287835/1a6b3.pdf
- http://romanticcaliforniacoast.com/uploads/1/3/0/7/130776811/5e5010f497772d.pdf
- http://watar-ksa.com/uploads/1/3/0/6/130604949/7d4026cad0c3d.pdf
- http://www.suttonsclassiccars.com/uploads/1/3/0/5/130551564/5320544.pdf
- http://www.healthymomninjawarrior.com/uploads/1/3/0/7/130739211/jitot_sukudapawix.pdf
- http://haddiepiephotography.com/uploads/1/3/0/4/130435842/8e8f489d5971dc4.pdf
- http://www.qixingtanglang.com/uploads/1/3/0/4/130489052/2031816.pdf
- http://cforcinema.org/uploads/1/3/0/6/130621298/sanuli.pdf
- http://statewidefacilitiesservices.com/uploads/1/3/0/6/130605041/tufejuwepanok-musugabinapux-xokurozixajibuf-wemilejenuso.pdf
- http://allstarroad.com/uploads/1/3/0/5/130589122/wirixogalowowivib.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off000084af.bin67ff3c86f5814021eb9c14065b0597611ba6ba6ca8558bed803f49d5093b52de |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x84AF | 9352 bytes |
font_01_sfnt_off0000a75c.binb70ed2bc54d0771f5ebdc02779674387161dbf9fa33dcd8e164b3b38dfc2a238 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xA75C | 16508 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.