MALICIOUS
62
Risk Score
Malware Insights
MITRE ATT&CK
T1566.002 Spearphishing Attachment
T1204.002 Malicious Link
The PDF document contains a large number of external links, a technique often used for SEO poisoning or to host malicious content. The document body suggests a lure for a 'Linux study guide pdf download', which is likely a pretext to drive users to download further malicious PDFs from the numerous linked domains. The primary attack pattern involves a link farm designed to distribute potentially harmful files.
Heuristics 3
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
External URI info PDF_URIPDF contains an external URL action
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL http://seastar.websalve.com/uploads/1/3/0/6/130620773/130620773.html#linux++study+guide+pdf+download
- http://divinegrace101.com/uploads/1/3/0/4/130435661/xasilizepise_letawakegasal.pdf
- http://ns.stephaneheaume.com/uploads/1/3/0/6/130639350/pimavin.pdf
- http://pilgrimagesnepal.com/uploads/1/3/0/9/130969904/924343.pdf
- http://robosail.org/uploads/1/3/0/7/130775294/a10b06ec.pdf
- http://giftsandcraftsbyzara.com/uploads/1/3/0/4/130476784/1594056.pdf
- http://www.timelessfaces.com.au/uploads/1/3/0/9/130968911/nuvej.pdf
- http://slhomestead.com/uploads/1/3/0/4/130483136/89ff5ab9dcff.pdf
- http://myfujingarts.com/uploads/1/3/0/5/130551309/sobexidatab.pdf
- http://friendsofmaurinefbailey.org/uploads/1/3/0/7/130739061/najabuwoseni-povewut.pdf
- http://dayscreekschools.com/uploads/1/3/1/0/131071157/xikedagimaniw.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Extracted artifacts 1
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off000063ff.bin9e959a2b69581336debbb4eb819ab39779f700ca29684263960212264bfe69b3 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x63FF | 8260 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.