Malware Insights
The PDF file was identified as malicious due to the presence of a PDF SEO link farm heuristic, indicating a large number of external links designed to manipulate search engine results or redirect users. The document body contains numerous URLs, with the primary ones being http://en.gobrazil.co.uk/uploads/1/3/0/4/130435819/130435819.html#yunan+i%25CC%2587%25C3%25A7+sava%25C5%259F%25C4%25B1 and http://robertion.com/uploads/1/3/1/1/131164204/viperifu.pdf. These links likely serve as a distribution mechanism for further malicious content or phishing attempts.
Heuristics 3
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
External URI info PDF_URIPDF contains an external URL action
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL http://en.gobrazil.co.uk/uploads/1/3/0/4/130435819/130435819.html#yunan+i%25CC%2587%25C3%25A7+sava%25C5%259F%25C4%25B1
- http://robertion.com/uploads/1/3/1/1/131164204/viperifu.pdf
- http://bertschi.ca/uploads/1/3/0/4/130476844/9630d82369.pdf
- http://outlook.microendeavors.com/uploads/1/3/1/3/131398336/goxenuxu.pdf
- http://boatparty.org/uploads/1/3/0/9/130969150/wotinosat.pdf
- http://silvertonnaz.org/uploads/1/3/0/5/130551401/3732990.pdf
- http://itsjewelrytime.com/uploads/1/3/0/7/130739194/8409556.pdf
- http://2s6.undesirable.us/uploads/1/3/0/4/130483558/luvadifosazevab_kowogarogaz_viwanidapizewad_tovagejiti.pdf
- http://muellerprofessionalservices.ca/uploads/1/3/0/7/130740356/5286794.pdf
- http://cnxtaiwan.com/uploads/1/3/0/3/130313491/revuweti.pdf
- http://hanamakeup.studio/uploads/1/3/1/4/131455956/leposotilirem.pdf
- http://fairytalesandwar.net/uploads/1/3/1/4/131437689/xifusivusenijo_xosumuw_mavigotagipiru_fabokomi.pdf
- http://hellohappyday.com/uploads/1/3/0/6/130622025/vanuzifonivet.pdf
- http://kimauriemmadesigns.com/uploads/1/3/0/7/130738555/panopedudob-ripasex-tedigit.pdf
- http://markscarb.com/uploads/1/3/0/7/130738792/redosivij-makovapepo-fazubamorabex-wenib.pdf
- https://wiginikinu.files.wordpress.com/2020/06/rifisutexufeviranojofuzup.pdf
- https://poxenatus.files.wordpress.com/2020/06/82940799791.pdf
- https://xufojev.files.wordpress.com/2020/06/misitobi.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Extracted artifacts 1
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00007f4c.binece692f1640f025f1c04d3f06b0cdfe964dc6d1e123f631371e2f1bbf9e6596b |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x7F4C | 13744 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.