MALICIOUS
64
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1204.002 Malicious Link
The PDF file contains a significant number of external links, with one heuristic specifically identifying it as a 'PDF_SEO_LINK_FARM'. This suggests the primary purpose is to direct users to potentially malicious content hosted on external sites. The embedded URL 'http://dormister.com/asferic/buteae/UGFnaW5pIEh0bWwgR2F0YSBGYWN1dGUUGF.caches.ZG93bmxvYWR8ODdqWkd0emVueDhNVFkxTnpFNE5qazFOWHg4TWpVNE4zeDhLRTBwSUVobGNtOXJkU0JiUm1GemRDQkhSVTVk?singifcantly.gditeam.nighters.unzip' is a key indicator of the attack vector. No scripts were extracted from this sample.
Machine Learning
- Nyx PDF Classifier clean score 0.0155
Heuristics 3
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
External URI info PDF_URIPDF contains an external URL action
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL http://dormister.com/asferic/buteae/UGFnaW5pIEh0bWwgR2F0YSBGYWN1dGUUGF.caches.ZG93bmxvYWR8ODdqWkd0emVueDhNVFkxTnpFNE5qazFOWHg4TWpVNE4zeDhLRTBwSUVobGNtOXJkU0JiUm1GemRDQkhSVTVk?singifcantly.gditeam.nighters.unzip
- https://evening-ocean-58659.herokuapp.com/ferdkarm.pdf
- https://levitra-gg.com/?p=19582
- https://powerful-escarpment-85571.herokuapp.com/loutleo.pdf
- https://austraffic.com.au/system/files/webform/survey-quote/percnivi63.pdf
- https://volektravel.com/wp-content/uploads/2022/07/Zor_Lagaa_Ke_Haiya_movie_download_in_hindi_hd_720p_kickass.pdf
- https://qiemprego.com/wp-content/uploads/2022/07/mass_effect_2_nude_mods.pdf
- https://hillkesari.com/manuale-di-legislazione-universitaria-pdf-16-updated/
- https://aquadiscovery.ru/wp-content/uploads/2022/07/free_download_ultraseps_full_version_crack_and_keygen.pdf
- https://ihcen.com/wp-content/uploads/2022/07/Essl_Smart_Office_Suite_Cracked_UPD.pdf
- http://educationalliance.org/2022/07/die-fat-or-get-tough-pdf/
- https://www.solomaco.org/2022/07/07/adobe-cs6-core-x-force-keygenl-2021/
- https://wanoengineeringsystems.com/solomon-organik-kimya-kitap-soru-ve-cevaplar-rar10-portable/
- https://classifieds.cornerecho.com/advert/autocad-2018-64bit-product-key-and-xforce-keygen-keygen-exclusive/
- https://you.worldcruiseacademy.co.id/upload/files/2022/07/5F3yNu74QoFWWHgiVkHF_08_8b2f6677d9be0f2c2c95655234813a62_file.pdf
- https://www.pizzavisor.fr/wp-content/uploads/2022/07/delarmi.pdf
- https://teleo.es/upload/files/2022/07/1HkK9UMwwwPVG8ndMEuI_08_ea76229187ce5021f434cb7f655dd91c_file.pdf
- https://ecop.pk/railworks-ts2015-dtg-munich-augsburg-route-add-on-torrent-exclusive/
- https://volektravel.com/wp-
- https://aquadiscovery.ru/wp-
- https://classifieds.cornerecho.com/advert/autocad-2018-64bit-product-key-and-xforce-keygen-
- https://you.worldcruiseacademy.co.id/upload/files/2022/07/5F3yNu74QoFWWHgiVkHF_08_8b2f6677d
- https://teleo.es/upload/files/2022/07/1HkK9UMwwwPVG8ndMEuI_08_ea76229187ce5021f434cb7f655
- https://networny-social.s3.amazonaws.com/upload/files/2022/07/hQuhW23yh659hfbHdWHi_08_8b2f6677d9be0f2c2c95655234813a62_file.pdf
- http://zambconi.yolasite.com/resources/Muvee-Reveal-X-Crack-HOT-17.pdf
- https://trello.com/c/Fk4aSjCD/57-war-in-the-pacific-admirals-edi
- http://www.tcpdf.org
- https://networny-social.s3.amazonaws.com/upload/files/2022/07/hQuhW23yh659hfbHdWHi_08_8b2f6
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/mm/
- http://www.aiim.org/pdfa/ns/extension/
- http://www.aiim.org/pdfa/ns/schema#
- http://www.aiim.org/pdfa/ns/property#
- http://www.aiim.org/pdfa/ns/id/
Open this report in the interactive analyzer, or submit your own file for analysis.