MALICIOUS
62
Risk Score
Malware Insights
MITRE ATT&CK
T1059.001 PowerShell
T1204.002 Malicious Link
The PDF file contains a significant number of external links, identified by the PDF_SEO_LINK_FARM heuristic. These links likely serve to inflate search engine results or redirect users to potentially malicious content. The embedded URL also points to a suspicious domain. No scripts were extracted from this sample, limiting further analysis of its behavior.
Heuristics 3
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
External URI info PDF_URIPDF contains an external URL action
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL http://curtisjrdesigns.com/uploads/1/3/0/7/130775455/130775455.html#awadhesh+premi+2018+video++pagalworld
- http://countee-cullen.com/uploads/1/3/0/4/130436389/nujonolure_guwini_tezepirinavasiz_xozusipolopadam.pdf
- http://rangeitoutdoors.com/uploads/1/3/1/3/131384227/jusilimawezakigewo.pdf
- http://hawaiiworkspace.com/uploads/1/3/0/5/130550654/dikaxinulux.pdf
- http://vonraesfeld.com/uploads/1/3/0/2/130270872/58cd8b.pdf
- http://naturalblackangus.net/uploads/1/3/1/3/131384412/9609404.pdf
- http://financejorge.net/uploads/1/3/0/8/130874451/3079729.pdf
- http://ticinodomus.com/uploads/1/3/0/5/130588703/tuvipu_fexebopaderem.pdf
- http://the-crafty-sagittarius.com/uploads/1/3/1/3/131379252/jefevanadanike-litok-jikumer.pdf
- http://bowyerlegacyfoundation.com/uploads/1/3/0/9/130969045/winawu_lelufesibinife_xowopajulevetig_kiwabenuz.pdf
- http://maynframetechnology.com/uploads/1/3/0/6/130620650/5207165.pdf
- http://philipdeaver.com/uploads/1/3/1/3/131398017/zamakikesusaroxa.pdf
- http://bestak47.com/uploads/1/3/0/8/130814597/2882358.pdf
- http://pushpullpaintlessdentrepair.com/uploads/1/3/1/1/131163578/8580795.pdf
- http://station55bar.com/uploads/1/3/0/4/130476205/widetizi.pdf
- http://collaborativeentrepreneurshipnetwork.com/uploads/1/3/0/4/130490078/8988972.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Extracted artifacts 4
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00006a98.binb20f1d2c85570576aca287a939d76621ae8e81d2f1824a4eb2114ac8a7ffca7f |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x6A98 | 8108 bytes |
font_01_sfnt_off00008a1f.bin1723f1ced37cc89d69e30f3df6281c5e5fb8989544fd4587aa75b00c91af2fd0 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x8A1F | 1388 bytes |
font_02_sfnt_off000091bd.binc770011c50217488db5959bba4e61ed648812afdb95fa3a605d8c0da010ab783 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x91BD | 16116 bytes |
font_03_sfnt_off0000a696.bin34ef0d1740663cec1ba703f6f3e84ef027db2d74bf56161ad40ee70d5948b260 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xA696 | 10236 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.