MALICIOUS
94
Risk Score
Malware Insights
MITRE ATT&CK
T1566.002 Spearphishing Attachment
T1204.002 Malicious Link
This PDF file was flagged by a machine learning classifier as malicious. It contains a large number of external links, many of which point to PDF files with numeric slugs, characteristic of a link farm or SEO manipulation tactic. The primary URL, http://theycallmefrida.com/uploads/1/3/1/3/131379268/131379268.html#mr+brahmachari+malayalam+movie+songs, suggests a lure related to movie songs to attract clicks.
Machine Learning
- Nyx PDF Classifier malicious score 0.9988
Heuristics 3
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
External URI info PDF_URIPDF contains an external URL action
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL http://theycallmefrida.com/uploads/1/3/1/3/131379268/131379268.html#mr+brahmachari+malayalam+movie+songs
- http://nursingarmpillow.com/uploads/1/3/0/2/130272394/a228932.pdf
- http://carterwestbound.com/uploads/1/3/1/3/131379743/sotozoxepuvigobiba.pdf
- http://salvis-pupusas.com/uploads/1/3/0/8/130814173/noborodawo_fevopu.pdf
- http://primadonnabeads.com/uploads/1/3/1/4/131453081/4231182.pdf
- http://expandwellbeing.com/uploads/1/3/0/4/130435635/toxez.pdf
- http://anameisterwriting.com/uploads/1/3/0/5/130551176/gevazavumotanif.pdf
- http://mikedaledesign.com/uploads/1/3/1/4/131407995/7225485.pdf
- http://ameetazul.com/uploads/1/3/0/8/130814187/8760d403ea28ea.pdf
- http://mail.byboukje.nl/uploads/1/3/0/8/130873820/58a39991175.pdf
- http://cheerfl.com/uploads/1/3/1/3/131382148/womelusajete-puloz-widamusovina-miwuzazig.pdf
- http://expandwellbeing.com/uploads/1/3/0/4/
Extracted artifacts 1
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00006109.bin296599e516d306533ddf3eb288051b555072223505ab29e4364762777c5a041a |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x6109 | 8108 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.