MALICIOUS
90
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.001 PowerShell
The PDF contains a large number of embedded links to external URLs, identified by the PDF_SEO_LINK_FARM heuristic. While most of these URLs were classified as benign, the sheer volume and the nature of the heuristic suggest a malicious intent, possibly for SEO poisoning or to redirect users to malicious content. The ML_NYX_PDF_MALICIOUS classifier also strongly indicated maliciousness. No scripts were extracted from this sample.
Machine Learning
- Nyx PDF Classifier malicious score 0.9908
Heuristics 2
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL http://muicuiu.dumb1.com/6a06a09a05a07a07/La-fin-de-l-Union-europ-enne-by-David-Cayla.pdf
- http://muicuiu.dumb1.com/8a04a05a05a06a05/Yearbook-of-the-European-Convention-for-the-Prevention-of-Torture-and-Inhuman-or-Degrading-Treatment-or-Punishment-Annuaire-de-la-Convention-Europ-enne-Pour-La-Pr-vention-de-la-Torture-Et-Des-Peines-Ou-Traitements-Inhumains-Ou-D-gradants-Volume-20-2011-by-Council-of-Europe-Conseil-de-L-39-Europe.pdf
- http://muicuiu.dumb1.com/5a07a08a00a05a09/La-Duree-Et-L-Amenagement-Du-Temps-de-Travail-Dans-L-Union-Europeenne-by-Institut-D-Etudes-Europ-Eennes-Et-Intern.pdf
- http://muicuiu.dumb1.com/7a06a02a04a01a03/Capital-Punishment-in-the-Soviet-Union-People-Executed-by-the-Soviet-Union-Prisoners-Sentenced-to-Death-by-the-Soviet-Union-Grigory-Zinoviev-by-Source-Wikipedia.pdf
- http://muicuiu.dumb1.com/3a08a04a01a01a09/Abe-Lincoln-and-the-Selfie-that-Saved-the-Union-by-David-Potter.pdf
- http://muicuiu.dumb1.com/1a06a09a01a03a02/Stalin-and-the-Bomb-The-Soviet-Union-and-Atomic-Energy-1939-1956-by-David-Holloway.pdf
- http://muicuiu.dumb1.com/5a00a03a03a03/Sacrifice-Legacy-3-by-Cayla-Kluver.pdf
- http://muicuiu.dumb1.com/5a01a00a02a00a00/The-Chickamauga-Campaign-Glory-or-the-Grave-The-Breakthrough-the-Union-Collapse-and-the-Defense-of-Horseshoe-Ridge-September-20-1863-by-David-A-Powell.pdf
- http://muicuiu.dumb1.com/3a05a08a06a00a04/The-Queen-s-Choice-Heirs-of-Chrior-1-by-Cayla-Kluver.pdf
- http://muicuiu.dumb1.com/8a04a03a01a00a07/Russische-Emigration-in-Deutschland-1918-Bis-1941-Leben-Im-Europ-ischen-B-rgerkrieg-by-Karl-Schlogel.pdf
- http://muicuiu.dumb1.com/1a05a05a02a01a03/The-Union-The-Union-1-by-T-H-Hernandez.pdf
- http://muicuiu.dumb1.com/1a01a01a02a09a05a05/Der-Konzern-in-Der-Krise-Aktuelle-Rechtsfragen-Im-Kontext-Deutscher-Und-Europ-isch-Grenz-berschreitender-Konzerninsolvenzen-by-Christoph-Jensen.pdf
- http://muicuiu.dumb1.com/1a01a06a04a09a07a06/Wegenetz-Europ-ischen-Geistes-II-Universit-ten-Und-Studenten-Die-Bedeutung-Studentischer-Migrationen-in-Mittel--Und-S-dosteuropa-Vom-18-Bis-Zum-20-Jahrhundert-by-Richard-Georg-Plaschka.pdf
- http://muicuiu.dumb1.com/2a05a04a06a08a08/Works-of-Abraham-Lincoln-Includes-Inaugural-Addresses-State-of-the-Union-Addresses-Cooper-s-Union-Speech-Gettysburg-Address-House-Divided-Speech-MORE-by-Abraham-Lincoln.pdf
- http://muicuiu.dumb1.com/3a09a03a07a06/Legacy-Legacy-1-by-Cayla-Kluver.pdf
- http://muicuiu.dumb1.com/2a05a04a08a02a07/The-Union-War-by-Gary-W-Gallagher.pdf
- http://muicuiu.dumb1.com/9a09a05a08a06/Union-Street-by-Pat-Barker.pdf
- http://muicuiu.dumb1.com/1a03a03a00a02a04/Union-by-John-Mulcahy.pdf
- http://muicuiu.dumb1.com/6a06a00a05/We-re-Going-to-Need-More-Wine-by-Gabrielle-Union.pdf
- http://muicuiu.dumb1.com/1a00a09a06a06a02a04/Europaische-Union-by-Josef-Weindl.pdf
- http://muicuiu.dumb1.com/5a07a08a00a05a09/La-Duree-Et-L-Amenagement-Du-Temps-de-Trava
Open this report in the interactive analyzer, or submit your own file for analysis.