MALICIOUS
94
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1204.002 Malicious Link
This PDF file was flagged by a machine learning classifier with high confidence. It contains a large number of external links, many of which are dynamically generated and point to various domains, suggesting a link farm or SEO spam campaign. One of the extracted URLs is http://lw8bn.bpmtc.com/uploads/1/3/0/4/130488229/130488229.html#urine+chlamydia+trachomatis+rrna+%28pcr%2Fnaat%29, which appears to be part of a lure. The primary attack pattern involves redirecting users to these external sites.
Machine Learning
- Nyx PDF Classifier malicious score 0.9999
Heuristics 4
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL http://lw8bn.bpmtc.com/uploads/1/3/0/4/130488229/130488229.html#urine+chlamydia+trachomatis+rrna+%28pcr%2Fnaat%29
- http://fitnessbyalisharenae.com/uploads/1/3/0/6/130604445/saximozuxamibarugila.pdf
- http://www.gracefuloctopus.com/uploads/1/3/0/6/130640125/685389.pdf
- http://hshaikhart.com/uploads/1/3/0/4/130435763/2525521.pdf
- http://demothewriter.com/uploads/1/3/0/5/130538880/sorupikalojesanuxo.pdf
- http://www.dovernewlife.com/uploads/1/3/0/7/130738874/wiludezufedukil-rubovageb-doxopepefa.pdf
- http://techeducation.ca/uploads/1/3/0/2/130291996/cb7c2eff.pdf
- http://spectacularvintageevents.com/uploads/1/3/0/7/130775743/13bbfcd8e26.pdf
- http://mta142.qualitynow.net/uploads/1/3/0/9/130969249/7608953.pdf
- http://factofevolution.net/uploads/1/3/0/4/130436252/zikowik.pdf
- http://stmargaretbiglake.com/uploads/1/3/0/7/130775368/2671648.pdf
- http://daleanimalhospital.preview.pethealthnetworkpro.com/uploads/1/3/0/5/130588403/zobafirobelemibixof.pdf
- http://comercializadoraibsasa.com/uploads/1/3/0/8/130874615/5472359.pdf
- http://bonneicho.com/uploads/1/3/0/4/130488542/mumesadapubepezur.pdf
- http://www.residentialone.ca/uploads/1/3/0/7/130738708/rekivo.pdf
- http://holeinonesotogrande.com/uploads/1/3/0/7/130775572/wajusolizip-dawoge-xapugaj.pdf
- http://webdisk.vandersystreefarm.com/uploads/1/3/0/8/130874154/narufadomirawapudiji.pdf
- http://circularprice.com/uploads/1/3/0/3/130379101/bojovas.pdf
- http://hodline.news/uploads/1/3/0/6/130621486/ec41ec97b7dc8f.pdf
- http://freeyourmindnow.org/uploads/1/3/0/6/130620475/2723240.pdf
- http://michaelgrew.net/uploads/1/3/0/6/130621790/guzidemalafu.pdf
- http://dripdropmedspa.com/uploads/1/3/0/5/130551749/roxujika.pdf
- http://www.whidbeycooks.org/uploads/1/3/0/7/130739001/6706446.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00017c26.bin581b8df8cd035a692af48511d6016979698d50a8c193026cfe3c1cfba02cad92 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x17C26 | 8196 bytes |
font_01_sfnt_off00019b9a.bin6dc6e07f93ae70488a19e8a398a1c6cda2f5723fc3d3cbe180c5afbb10c3611e |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x19B9A | 2864 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.