Malware Insights
The PDF document contains a large number of embedded external links, identified as a 'PDF_SEO_LINK_FARM'. The primary URL, http://miracleinabucket.com/uploads/1/3/0/2/130270808/130270808.html#c%C3%A1ch+l%C3%A0m+nhi%E1%BB%87m+v%E1%BB%A5+thi%C3%AAn+m%C3%B4n+tr%E1%BA%ADn+vl2, and many others point to domains that appear to be hosting PDF files. This suggests a tactic to manipulate search engine results or to redirect users to potentially malicious content. No scripts were extracted, but the extensive link farm is a strong indicator of malicious intent.
Machine Learning
- Nyx PDF Classifier malicious score 1.0000
Heuristics 4
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL http://miracleinabucket.com/uploads/1/3/0/2/130270808/130270808.html#c%C3%A1ch+l%C3%A0m+nhi%E1%BB%87m+v%E1%BB%A5+thi%C3%AAn+m%C3%B4n+tr%E1%BA%ADn+vl2
- http://costumespropssets.com/uploads/1/3/0/2/130288549/fe7bc229d230.pdf
- http://brigliacapitalpartners.com/uploads/1/3/0/7/130775672/1642004.pdf
- http://functionalartaholic.com/uploads/1/3/0/7/130776158/fiwumimebijugam-gebiwakejezigud.pdf
- http://redriverdrones.com/uploads/1/3/0/4/130435763/pexura.pdf
- http://artganga.com/uploads/1/3/0/7/130738752/totibakev.pdf
- http://buddingenterprisefund.com/uploads/1/3/0/4/130483656/gawebef_puwiteke.pdf
- http://laurieannbird.com/uploads/1/3/0/4/130483242/bac9c3.pdf
- http://socialstudiesforthefuture.com/uploads/1/3/1/0/131070314/nevomalovet_tixaso_moruz_megepokanufobe.pdf
- http://tlhindustires.com/uploads/1/3/0/7/130776702/rivemo-dalekuz-fozotonikafob.pdf
- http://dnp123nano.us/uploads/1/3/0/5/130540176/vezoweneg_xirarenufav_jalixakodopeset.pdf
- http://recovermorevalue.com/uploads/1/3/0/9/130970012/vuzulefilipej-gumiti.pdf
- http://mechanicalsupplier.com/uploads/1/3/0/5/130588502/suvelosopetonun-koganim-legosamozujev-selijurijup.pdf
- http://kingdomcurator.com/uploads/1/3/1/3/131383934/ba0d4d7f5b10290.pdf
- http://honestandmodest.com/uploads/1/3/1/4/131437285/zokodizusug.pdf
- http://cofficurean.com/uploads/1/3/0/8/130874430/0a664.pdf
- http://dprservices513.com/uploads/1/3/0/7/130776483/wopiwusemewifox.pdf
- http://chantyogastudio.com/uploads/1/3/0/5/130542727/tozibiboxo_bobeve.pdf
- http://n90.net/uploads/1/3/0/2/130272377/nisetavibafe-vurat-tugevij.pdf
- http://expertsforglobalchange.org/uploads/1/3/0/7/130776795/newirisovesop_xurotudila.pdf
- http://permaculturefoundationofhawaii.com/uploads/1/3/1/0/131071056/5eea0.pdf
- http://takingthecity.org/uploads/1/3/0/5/130551064/bazubi-tamokof-jeziwobajaj-mamodimalezal.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- https://fedoraproject.org/wiki/Licensing/LiberationFontLicense
- http://dejavu.sourceforge.net
- http://dejavu.sourceforge.net/wiki/index.php/License
Extracted artifacts 3
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000a104.bin416255533ca254a1547266089177ef5f2342e7f6f5ba4b3da3416f203e142e29 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xA104 | 10660 bytes |
font_01_sfnt_off0000c326.bin27aad4e7100ae85831cc1a9cf4859e84521ff6b1ee9ac199fa10e6c4d4b25dad |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xC326 | 2736 bytes |
font_02_sfnt_off0000ccd3.bin1d35b09d7a46ae68b54c37a0461d06864e3d9749fa19ba1687c7f142ab4a19d0 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xCCD3 | 23948 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.