MALICIOUS
62
Risk Score
Malware Insights
MITRE ATT&CK
T1566.002 Spearphishing Attachment
T1204.002 Malicious Link
The PDF document contains a large number of external links, identified by the PDF_SEO_LINK_FARM heuristic. One of these links, http://74-123-76-124.mgwnet.com/uploads/1/3/0/4/130488069/130488069.html#ghost+shark+2013+film+online+subtitr, is present in the document body and appears to be a lure for potentially malicious content. The extensive link farm suggests an attempt to distribute malicious payloads or redirect users to phishing sites.
Heuristics 3
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
External URI info PDF_URIPDF contains an external URL action
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL http://74-123-76-124.mgwnet.com/uploads/1/3/0/4/130488069/130488069.html#ghost+shark+2013+film+online+subtitr
- http://theinkedangel.com/uploads/1/3/1/8/131856062/4655971.pdf
- http://glambybcj.com/uploads/1/3/1/3/131379545/zewulazunapo.pdf
- http://capitalcitybev.com/uploads/1/3/0/5/130550722/kenobunoxa_miridasu.pdf
- http://ainsworthpottery.com/uploads/1/3/0/6/130639693/wejagexivasufa-minipobimose-munajated.pdf
- http://bayarea-interactivehypnotherapy.org/uploads/1/3/0/2/130270985/19d4360.pdf
- http://thewhimsicalwench.com/uploads/1/3/1/4/131437831/04bf6b7a38.pdf
- http://findyouryogawellnesscentre.com/uploads/1/3/0/5/130543985/4711830.pdf
- http://youthening.org/uploads/1/3/1/4/131453253/350356.pdf
- http://id8physics.com/uploads/1/3/1/3/131379231/d8292b0e58c.pdf
- http://goldendoodle.love/uploads/1/3/0/3/130313044/3243554.pdf
- http://bossbellbbqbrew.com/uploads/1/3/0/5/130543133/ffe8f6b818.pdf
- http://allofthethingsproductions.com/uploads/1/3/0/5/130588457/virukijowoku.pdf
- http://hartlandmusiclessons.com/uploads/1/3/0/6/130639444/1764632.pdf
- http://empowerphysio.com/uploads/1/3/0/2/130288410/zerop_gupubam.pdf
- http://spctermites.com/uploads/1/3/0/8/130813546/6807727.pdf
- http://turnernco.com/uploads/1/3/0/4/130483647/jefez.pdf
- http://blackwillowtattoo.net/uploads/1/3/1/3/131384291/8805854.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Extracted artifacts 1
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00004f26.bin3f23514c0ec25ecb3781e16dc227f4d8b89a2b72b4bce9533248f291660fcde7 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x4F26 | 9860 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.