MALICIOUS
62
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1204.002 Malicious Link
The PDF file contains a large number of external links, identified by the PDF_SEO_LINK_FARM heuristic. These links point to various PDF files hosted on different domains, suggesting a link farm or a distribution mechanism for further malicious content. The document body contains text related to 'Macbeth study guide questions act 2', likely a lure to disguise the malicious intent. No scripts were extracted from this sample.
Heuristics 3
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
External URI info PDF_URIPDF contains an external URL action
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL http://theonlinefashionlounge.com/uploads/1/3/0/5/130550846/130550846.html#macbeth+study+guide+questions+act+2
- http://joshop.eu/uploads/1/3/0/7/130776159/174755de5e36d.pdf
- http://aimhealthgta.com/uploads/1/3/0/7/130740127/5464315.pdf
- http://eriktoddbenefit.com/uploads/1/3/0/6/130639552/sanov.pdf
- http://dynamitecheer.org/uploads/1/3/0/7/130738903/1ef98e0af.pdf
- http://eatthinkandbemerry.net/uploads/1/3/1/0/131070213/8164514.pdf
- http://alterationscscom.com/uploads/1/3/0/6/130620998/3871273.pdf
- http://kipjonproductions.com/uploads/1/3/0/6/130603958/9713849.pdf
- http://vistaimmigration.com/uploads/1/3/0/4/130435772/9239128.pdf
- http://honeybrookhomeinspectionllc.com/uploads/1/3/0/3/130313057/1005865.pdf
- http://djvcqrushmrsb.com/uploads/1/3/0/5/130551639/mowusizolano_vubuvewiw.pdf
- http://jncorbett.com/uploads/1/3/0/7/130739873/gikepomulevate.pdf
- http://gosafealarm.com/uploads/1/3/0/5/130546543/a713a99be.pdf
- http://mail.unbreakable.be/uploads/1/3/0/3/130312924/wimunema_rotenijepado_pibuw.pdf
- http://croboycemetary.org/uploads/1/3/0/8/130874432/2667827.pdf
- http://kelseymmontgomery.com/uploads/1/3/1/3/131381277/7d2d46fb.pdf
- http://keepitreal-kevin.com/uploads/1/3/1/4/131437724/kosajofovut.pdf
- http://toprewardsite.com/uploads/1/3/0/3/130313035/gemax.pdf
- http://michaelwanrealty.com/uploads/1/3/0/7/130739021/levizalitikelumatepu.pdf
- http://kajhu.com/uploads/1/3/0/5/130588810/22136bdd46fd8.pdf
- http://benkiashaninka.com/uploads/1/3/0/6/130621385/3506322.pdf
- http://affinityhomeagent.com/uploads/1/3/0/5/130545421/vebowaginika.pdf
- http://epmclarity.com/uploads/1/3/0/7/130775758/e0d97881a8b64.pdf
- http://thequiltstudio.com/uploads/1/3/0/7/130739324/tabik.pdf
- http://emmenriedel.nl/uploads/1/3/0/7/130739155/30c7c769cc04.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Extracted artifacts 1
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00006155.bin31738893d61d2490590e668d3464a9d6d19af4b50e50743dde3c914eb5f2dce8 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x6155 | 7000 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.