Malware Insights
The PDF file was flagged by a machine learning classifier and contains a large number of external links, indicating a potential SEO link farm or a lure for malicious content. The heuristic 'PDF_SEO_LINK_FARM' specifically points to a mass of external PDF links, with the first identified URL being https://cdn.sqhk.co/romilononove/gfuAhbF/vinenejetejivu.pdf. The presence of embedded URLs and the overall structure suggest an attempt to direct users to potentially harmful external resources, likely as part of a phishing or malware distribution scheme.
Machine Learning
- Nyx PDF Classifier malicious score 0.9475
Heuristics 3
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
External URI info PDF_URIPDF contains an external URL action
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://jacksth.ru/award?keyword=african+wild+dogs+eat+human PDF link annotation
- https://cdn.sqhk.co/romilononove/gfuAhbF/vinenejetejivu.pdfIn PDF document text
- https://xolesozetenosox.weebly.com/uploads/1/3/1/0/131070434/24eafc5ed.pdfIn PDF document text
- https://cdn.sqhk.co/kuzetuzame/9Auls3W/8262886258.pdfIn PDF document text
- https://cdn.sqhk.co/zewumabigige/hd61T5v/27943198305.pdfIn PDF document text
- https://zuzefeza.weebly.com/uploads/1/3/1/3/131397950/jivowuvuxiwazo.pdfIn PDF document text
- https://cdn.sqhk.co/bifoligi/aADXjgp/41594818385.pdfIn PDF document text
- https://cdn.sqhk.co/kogeledewafo/kLAhh7U/37902671004.pdfIn PDF document text
- https://cdn.sqhk.co/zalivelo/aidtBch/vekupirif.pdfIn PDF document text
- http://kobivoweder.mypressonline.com/manonoruzax.pdfIn PDF document text
- https://cdn.sqhk.co/pixukinoma/bNm7Hjf/pewilagujepexaka.pdfIn PDF document text
- https://cdn.sqhk.co/tememagitapo/WghhcBF/12448882110.pdfIn PDF document text
- http://www.ascendercorp.com/In PDF document text
- http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
- https://s3.amazonaws.com/nokiva/wavelepejiperezalejul.pdfIn PDF document text
- http://scripts.sil.org/OFLIn PDF document text
Extracted artifacts 1
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00013a40.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x13A40 | 5516 bytes |
SHA-256: 6b522091db1959464ed14b4aa8f4aa74118af1e636a1cf3d3093d5fce288660a |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.