MALICIOUS
102
Risk Score
Malware Insights
MITRE ATT&CK
T1204 Malicious Link
T1204.001 Malicious Link: Malicious Link
T1566 Phishing
T1566.002 Phishing: Spearphishing Attachment
The PDF contains a mass external link farm, with 30 links pointing to other PDFs hosted on various domains. The heuristic 'SE_BROWSER_INSTALL_LURE' indicates the document's content likely prompts the user to install a browser extension or update. This suggests a social engineering attack aimed at tricking users into compromising their systems. No scripts were extracted from this sample.
Heuristics 4
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Browser extension / update installation lure high SE_BROWSER_INSTALL_LUREDocument tells the user to install a browser extension, plugin, viewer, or browser update to view content — a common social-engineering path for credential theft and malware installation
-
External URI info PDF_URIPDF contains an external URL action
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL http://gentlespiritsproject.com/uploads/1/3/1/3/131379443/131379443.html#mozilla+firefox+42.+0+2
- http://dccltd.org/uploads/1/3/1/6/131636988/764930.pdf
- http://terrahowardphotography.com/uploads/1/3/0/7/130738527/tajarupajerugo.pdf
- http://generalmusicacademy.com/uploads/1/3/0/7/130739116/selok.pdf
- http://lakecumberlanddiscount.com/uploads/1/3/0/8/130814993/vowidajokutiduzo.pdf
- http://formormedia.com/uploads/1/3/0/7/130775858/jezarejabe.pdf
- http://chaoticdetour.com/uploads/1/3/1/4/131438257/nuritow.pdf
- http://mastermoose.ca/uploads/1/3/1/3/131379295/gugujuja.pdf
- http://gpfight.com/uploads/1/3/0/2/130272577/5991195.pdf
- http://adieapriyadi.net/uploads/1/3/0/2/130289353/gugimemogele_tudidejixexoso.pdf
- http://madeformorecreations.com/uploads/1/3/1/1/131163725/sebes.pdf
- http://peterpark1.com/uploads/1/3/1/3/131379554/2c544.pdf
- http://mark-sim.com/uploads/1/3/0/4/130476943/xubifumalasig.pdf
- http://thingz4u.com/uploads/1/3/0/6/130604671/busoxiguzuguxo.pdf
- http://northcarolinawatergardens.com/uploads/1/3/0/5/130588740/5734456.pdf
- http://martadance.com/uploads/1/3/0/4/130494478/rosivelupogixelaje.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Extracted artifacts 1
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000638b.bin9c7baa547b1581c2b5d7a8de45cc6421306dcf11ff1d360bde3debc95c549e4e |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x638B | 10252 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.