MALICIOUS
62
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1204.002 Malicious Link
This PDF document contains a large number of external links, identified by the PDF_SEO_LINK_FARM heuristic. The primary URL, http://dedicated-15.pleasingfood.com/uploads/1/3/0/8/130874045/130874045.html#school+uniforms+stores+in+montgomery+al, appears to be a lure, possibly for SEO manipulation or to redirect to malicious content. No scripts were extracted from this sample.
Heuristics 3
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
External URI info PDF_URIPDF contains an external URL action
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL http://dedicated-15.pleasingfood.com/uploads/1/3/0/8/130874045/130874045.html#school+uniforms+stores+in+montgomery+al
- http://hostmaster.alex-szy.com/uploads/1/3/0/5/130550847/3481572.pdf
- http://kidsnurseryart.co.uk/uploads/1/3/1/0/131070576/7727588.pdf
- http://dsnatural.com/uploads/1/3/0/2/130270905/6422387.pdf
- http://www.wedoitforthedogs.com/uploads/1/3/0/4/130477979/bc400d.pdf
- http://beardedmanbill.com/uploads/1/3/0/8/130814190/8d6b057711f.pdf
- http://lexingtonsbesttreeservice.com/uploads/1/3/0/6/130639209/5798232.pdf
- http://frc5150.info/uploads/1/3/0/6/130621464/2885198.pdf
- http://www.davidsievers.net/uploads/1/3/0/4/130435905/lavoled.pdf
- http://firstserveuk.com/uploads/1/3/0/3/130323227/mamefodizewiv.pdf
- http://30oakst1.com/uploads/1/3/0/9/130969329/romibeniraxi_duwis_fivelawubinapof_sovap.pdf
- http://www.montcoseniorgames.com/uploads/1/3/0/3/130379821/2675001.pdf
- http://e-bikerepair.com/uploads/1/3/0/7/130775539/a6e66b90f29994.pdf
- http://stulead.org/uploads/1/3/0/5/130588744/lipojub.pdf
- http://www.paulspak.com/uploads/1/3/0/5/130546759/zobeluwavowujas.pdf
- http://www.edencapital.us/uploads/1/3/0/9/130969001/rulupamabovedol.pdf
- http://mooseandmagpiefarm.com/uploads/1/3/0/5/130539881/nafigevuvuzo.pdf
- http://abouttherightfitllc.com/uploads/1/3/0/5/130539085/nolat.pdf
- http://www.boostafterschool.org/uploads/1/3/0/4/130491599/8e345be2b.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Extracted artifacts 1
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000649f.bin8ef86db1243265a7ba3616507e1de478f71ebd79c7fcb49f4187d674cc254ccf |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x649F | 8064 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.