MALICIOUS
152
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1204.002 Malicious File
The PDF file contains a large number of embedded links to other PDF files hosted on various domains. This behavior is indicative of a link farm or SEO manipulation tactic, likely intended to drive traffic or distribute further malicious content. The ML classifier and ClamAV detection strongly support its malicious nature.
Machine Learning
- Nyx PDF Classifier malicious score 0.9996
Heuristics 3
-
ClamAV: Pdf.Dropper.Agent-7652373-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Dropper.Agent-7652373-0
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL http://static.ahcnm.org/uploads/1/3/0/6/130639608/4582035.pdf In PDF document text
- http://acceleratecleaning.com/uploads/1/3/0/2/130271098/8dc1b0.pdfIn PDF document text
- http://cad-drafting.net/uploads/1/3/0/6/130621280/3552653.pdfIn PDF document text
- http://emmycodes.com/uploads/1/3/0/7/130738803/miluzidetoriro.pdfIn PDF document text
- http://thwgl.bpmtc.com/uploads/1/3/0/5/130544953/372728.pdfIn PDF document text
- http://youcanownbaltimore.com/uploads/1/3/0/3/130323767/1812262.pdfIn PDF document text
- http://cookielovecustomsugarcookies.com/uploads/1/3/0/7/130776074/lupofokanum.pdfIn PDF document text
- http://www.facebookpostingmadeeasy.com/uploads/1/3/0/8/130873802/wobusonawisotukur.pdfIn PDF document text
- http://nrmorenorealtor.com/uploads/1/3/0/8/130814245/tavamigitodaxakolud.pdfIn PDF document text
- http://maxsocialsecurityforlife.com/uploads/1/3/0/5/130590443/bavipep-nopotudo-bibatef.pdfIn PDF document text
- http://waea.net/uploads/1/3/0/6/130620613/vovalevidat.pdfIn PDF document text
- http://justinbdennis.com/uploads/1/3/0/4/130436271/7d7afaa.pdfIn PDF document text
- http://www.generaldiversity.com/uploads/1/3/0/6/130620835/8d13edc4f.pdfIn PDF document text
- http://44michigan.com/uploads/1/3/0/6/130639875/xedolizavizen.pdfIn PDF document text
- http://tripvector.org/uploads/1/3/0/2/130289045/bofaxirupiwusabi.pdfIn PDF document text
- http://my-mindful-mind.com/uploads/1/3/0/4/130483510/janolefulu.pdfIn PDF document text
- http://www.serviziopublicating.com/uploads/1/3/0/6/130640218/firubejosu.pdfIn PDF document text
- http://windows-defender.com/uploads/1/3/0/7/130740330/130740330.html#achyutam+keshavam+krishna+damodaram+bhajan+lyrics+in+hindiIn PDF document text
- http://fedorahosted.org/lohitIn PDF document text
- https://savannah.gnu.org/projects/freefont/In PDF document text
- http://www.gnu.org/licenses/In PDF document text
- http://www.gnu.org/copyleft/gpl.htmlIn PDF document text
- http://dejavu.sourceforge.netIn PDF document text
- http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text
Extracted artifacts 4
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00004c5a.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x4C5A | 1428 bytes |
SHA-256: 1cbcc6ccb4c0e39095e587a84d88e28c288fced985aab23597519fc935a1653b |
|||
font_01_sfnt_off00005646.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x5646 | 15408 bytes |
SHA-256: f28e81d4e523175b9333fbe4be8c01c6a4460f2da0f84e0f7eae969f7a7e4701 |
|||
font_02_sfnt_off00007e77.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x7E77 | 16204 bytes |
SHA-256: f31c439e28d0137206b91a151f21343900f846ed9ff070250fbe82eb1cc7da1d |
|||
font_03_sfnt_off00009676.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x9676 | 8072 bytes |
SHA-256: d5080aafa8cd544d84f13423eb5ac48a02b5d9027590362fb8dc617921bb7548 |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.