MALICIOUS
64
Risk Score
Malware Insights
MITRE ATT&CK
T1566.002 Spearphishing Attachment
T1204.002 Malicious Link
The PDF file contains a large number of external links, many of which point to other PDF files, suggesting a link farm or redirection mechanism. The heuristic 'PDF_SEO_LINK_FARM' indicates a high volume of external links, and the presence of URLs like 'lehmanbrotherbankruptcy.com' and links to cracked software further supports a malicious intent. The document body is heavily obfuscated and does not provide direct clues, but the overall structure and linked content point towards a phishing or malware distribution attempt.
Machine Learning
- Nyx PDF Classifier clean score 0.0048
Heuristics 3
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
External URI info PDF_URIPDF contains an external URL action
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL http://lehmanbrotherbankruptcy.com/ZG93bmxvYWR8blEyWWpWM2FYeDhNVFkxTnpFNE5qazFOWHg4TWpVM05IeDhLRTBwSUhKbFlXUXRZbXh2WnlCYlJtRnpkQ0JIUlU1ZA/arraylist.bass/aWYgaSBmYWxsIGJ5IHNoaXJsZW5ndGVhcmplcmt5IHBkZiBkb3dubG9hZAaWY/bushbucks/underachievers.proposals.perfectionist
- https://www.beaniescustom.com.au/sites/www.beaniescustom.com.au/files/webform/ETABS-181-Crack-With-Full-Torrent-2020-Latest.pdf
- http://listoo.de/wp-content/uploads/alekhr.pdf
- https://1w74.com/mardaani-top-full-movie-in-hd-1080p/
- https://digipal.ps/blog/index.php?entryid=6098
- http://www.viki-vienna.com/hd-online-player-tamil-dubbed-1080p-movies-housefull-exclusive/
- https://theoceanviewguy.com/wp-content/uploads/2022/07/shawove.pdf
- https://yemensouq.com/wp-content/uploads/2022/07/DameWare_Mini_Remote_Control_7590_Portable.pdf
- https://rondaplaces.com/wp-content/uploads/2022/07/uldidal.pdf
- https://stonerx.me/upload/files/2022/07/3AkYpj4aJiDJHVpqkwZ6_08_4088d7bf396d87ad6ece657daae049ee_file.pdf
- https://www.brandybo.com/wp-content/uploads/2022/07/Hate_Story_3_Full_Movie_In_Hindi_Hd_Download.pdf
- http://www.ressn.com/descargar-crack-de-bionic-commando-rearmed-upd/
- https://mandarinrecruitment.com/system/files/webform/darkbem646.pdf
- http://angkasydney.org/ashampoo-winoptimizer-17-00-22-crack-torrent-new-keygen-latest-version/
- https://menamlanxang.com/wp-content/uploads/2022/07/berlann.pdf
- https://www.petersonsign.com/sites/default/files/webform/publicfiles/schmar646.pdf
- https://wozyzy.com/upload/files/2022/07/YUWCxAjy6rtLskcZY3vG_08_4088d7bf396d87ad6ece657daae049ee_file.pdf
- https://www.beaniescustom.com.au/sites/www.beaniescustom.com.au/files/webform/ETABS-181-Cr
- https://yemensouq.com/wp-
- https://stonerx.me/upload/files/2022/07/3AkYpj4aJiDJHVpqkwZ6_08_4088d7bf396d87ad6ece657da
- https://www.brandybo.com/wp-
- https://wozyzy.com/upload/files/2022/07/YUWCxAjy6rtLskcZY3vG_08_4088d7bf396d87ad6ece657d
- https://siodaropigdipip.wixsite.com/prosunasam/post/championshipmanager0304freedownloadfullversion-~repack~
- https://rockmitnesixs1984.wixsite.com/merimipad/post/refx-vanguard-vsti-v1-7-2-air-crack-exclusive
- https://wakelet.com/wake/aDrWlzC4W3Hwuq00AVrKl
- https://prefimhilsukarep.wixsite.com/dishasbquarsunb/post/mixed-in-key-dj-software-for-harmonic-mixing-8-5-3
- http://www.tcpdf.org
- https://siodaropigdipip.wixsite.com/prosunasam/post/championshipmanager0304freedownloadfullv
- https://rockmitnesixs1984.wixsite.com/merimipad/post/refx-vanguard-vsti-v1-7-2-air-crack-
- https://prefimhilsukarep.wixsite.com/dishasbquarsunb/post/mixed-in-key-dj-software-for-harmonic-
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/mm/
- http://www.aiim.org/pdfa/ns/extension/
- http://www.aiim.org/pdfa/ns/schema#
- http://www.aiim.org/pdfa/ns/property#
- http://www.aiim.org/pdfa/ns/id/
Extracted artifacts 1
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
stream_016_off0001b7c4.bindf221e87b81d1531cafdadb6c09a602e9f604d1baf0a17bbd350cbb83baa06f7 |
decompressed-pdf-stream | PDF FlateDecoded stream at offset 0x1B7C4 | 119072 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.