MALICIOUS
62
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1204.002 Malicious Link
The PDF document contains a significant number of external links, as indicated by the PDF_SEO_LINK_FARM heuristic. The document body, though heavily obfuscated, contains references to URLs that are also present in the heuristics. The primary attack pattern appears to be directing users to a large farm of external websites, potentially for SEO manipulation or to host further malicious content. No scripts were extracted, limiting the analysis of direct payload delivery.
Heuristics 3
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
External URI info PDF_URIPDF contains an external URL action
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL http://africasmefinance.com/uploads/1/3/1/8/131871829/131871829.html#magna+carta+holy+grail+torrent
- http://mummymakemesomething.net/uploads/1/3/0/5/130546937/034341d.pdf
- http://blissfullbeauty.net/uploads/1/3/1/4/131453592/bf0897.pdf
- http://ridalcomediation.com/uploads/1/3/1/6/131637103/2560853.pdf
- http://fmg-goldau.ch/uploads/1/3/1/6/131606861/25f4f2a4bad3a8.pdf
- http://kefinancialservices.com/uploads/1/3/1/8/131856033/kajiwesi.pdf
- http://africasmefinance.com/uploads/1/3/1/8/131871829/terms.html
- http://africasmefinance.com/uploads/1/3/1/8/131871829/dmca.html
- http://africasmefinance.com/uploads/1/3/1/8/131871829/policy.html
- https://wejujixagaz.files.wordpress.com/2020/06/xasafadufa.pdf
- https://wosibol.files.wordpress.com/2020/06/62419362561.pdf
- https://ribijuwet742308788.files.wordpress.com/2020/06/juvadasakosuperuf.pdf
- https://tigizenawa.files.wordpress.com/2020/06/kiwoninaw.pdf
- https://nulogep.files.wordpress.com/2020/06/vasatibikatanalef.pdf
- https://sosunilavef.files.wordpress.com/2020/06/nivetowefijan.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Extracted artifacts 1
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000612e.bin37d605f40eb60f10ce57e2a12fac5ada07d7c538ff2f86ed9f42c1502b38438b |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x612E | 11260 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.