Malware Insights
The PDF file was flagged by an ML classifier as malicious with high confidence. It contains a large number of external links, many pointing to PDF files with numeric slugs, indicative of a link farm or SEO manipulation tactic. The primary URL found in the document body is http://myentouragemusic.com/uploads/1/3/0/6/130639936/130639936.html#california+mission+san+francisco+solano+history, and another significant link farm URL is http://lynnleelists.com/uploads/1/3/0/6/130604286/44e56e1b31306d5.pdf. No scripts were extracted, and the document body is heavily obfuscated, but the sheer volume of external links suggests a malicious intent to redirect users or manipulate search engine results.
Machine Learning
- Nyx PDF Classifier malicious score 1.0000
Heuristics 4
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL http://myentouragemusic.com/uploads/1/3/0/6/130639936/130639936.html#california+mission+san+francisco+solano+history
- http://lynnleelists.com/uploads/1/3/0/6/130604286/44e56e1b31306d5.pdf
- http://cllws.co.za/uploads/1/3/0/6/130605482/1a8a1ac14237.pdf
- http://calvarynewliferadio.calvarynewlifesa.com/uploads/1/3/0/5/130538992/godinojus.pdf
- http://dunmarrawaysideinn.com/uploads/1/3/0/6/130639664/zipixajubekomodubafe.pdf
- http://mail.railroadseafood.com/uploads/1/3/0/3/130379287/jametozugexonulu.pdf
- http://vivernsamazingsales.com/uploads/1/3/0/9/130969950/bolubebonagigaj.pdf
- http://tonyjamesonline.com/uploads/1/3/0/8/130813762/lifejelewinafak_sasezekulop_vuwideza.pdf
- http://nexuschapel.org/uploads/1/3/0/5/130544078/geguni_vibujofupif_nasitek_fufixowemujav.pdf
- http://leeaib.com/uploads/1/3/0/2/130271077/da28d3ec21f.pdf
- http://alpinelegendspixiebobs.org/uploads/1/3/0/7/130739206/parulamunikoniron.pdf
- http://www.donnaconlanphysiotherapistleichhardt.com/uploads/1/3/0/5/130539735/c3af70d0685.pdf
- http://allanparachinicustomfurniturekauai.com/uploads/1/3/1/0/131070044/mowikexajevozije.pdf
- http://www.amandagrahamlpc.com/uploads/1/3/0/3/130379844/xofudaxewup_gunalikezupoj.pdf
- http://mta-sts.mail.shoutsave.com/uploads/1/3/0/7/130739250/6955859.pdf
- http://honeycombclothing.com/uploads/1/3/0/8/130873894/6059457.pdf
- http://tjmun.com/uploads/1/3/0/7/130775127/fe1933da6.pdf
- http://chicagoliterarywriters.com/uploads/1/3/0/6/130604536/lamodurox-zezupasodekuguz-vimolibob.pdf
- http://iscribe4u.com/uploads/1/3/0/6/130604319/218676.pdf
- http://gmchamberpatrons.com/uploads/1/3/0/3/130379341/27ddc.pdf
- http://mahaloateliereterapias.com/uploads/1/3/0/8/130814297/6648775.pdf
- http://bunburymarriage.com/uploads/1/3/0/6/130621802/ranezu.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Extracted artifacts 1
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off000082b2.binff821415409e6535f59e0f5d2288b0acb8cf723e7e19094959030a4905083db1 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x82B2 | 8024 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.