MALICIOUS
90
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1204.002 Malicious Link
The PDF contains a large number of embedded URLs pointing to a single domain, identified by the PDF_SEO_LINK_FARM heuristic. The ML_NYX_PDF_MALICIOUS heuristic also flagged the document with high confidence. The embedded URLs are likely part of a link farm or SEO poisoning scheme to drive traffic to potentially malicious content. No scripts were extracted from this sample.
Machine Learning
- Nyx PDF Classifier malicious score 0.9912
Heuristics 2
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL http://eascasas.myhome.cx/5aa6aa1aa8aa7aa0/Alice-s-Adventures-in-Wonderland-and-Through-the-Looking-Glass-by-Lewis-Carroll-with-an-excerpt-from-The-Life-and-Letters-of-Lewis-Carroll-by-Lewis-Carroll.pdf
- http://eascasas.myhome.cx/7aa2aa1aa4aa6aa9/Alice-in-Wonderland-And-Through-The-Looking-Glass-By-Lewis-Carroll---Illustrated-Free-Audiobook-Unabridged-Original-E-Reader-Friendly-by-Lewis-Carroll.pdf
- http://eascasas.myhome.cx/6aa6aa8aa2aa8aa5/Lewis-Carroll-Box-Set-Alice-Adventures-in-Wonderland-and-Through-the-Looking-Glass-Including-the-Short-Film-the-Delivery-by-Lewis-Carroll.pdf
- http://eascasas.myhome.cx/8aa7aa6aa9aa0/The-Collected-Stories-of-Lewis-Carroll-Alice-in-Wonderland-Through-the-Looking-Glass-Phantasmagoria-by-Lewis-Carroll.pdf
- http://eascasas.myhome.cx/5aa5aa0aa9aa5aa9/Alice-in-Wonderland-And-Through-The-Looking-Glass-By-Lewis-Carroll-Illustrated-by-Lewis-Carroll.pdf
- http://eascasas.myhome.cx/7aa0aa4aa3aa9aa1/Alice-in-Wonderland-And-Through-The-Looking-Glass-By-Lewis-Carroll---Illustrated-by-Lewis-Carroll.pdf
- http://eascasas.myhome.cx/9aa7aa3aa5aa7aa3/The-Alice-Books-Alice-s-Adventures-in-Wonderland-amp-Through-the-Looking-Glass-and-What-Alice-Found-There-by-Lewis-Carroll.pdf
- http://eascasas.myhome.cx/3aa4aa3aa3aa0/Through-the-Looking-Glass-and-What-Alice-Found-There-Alice-s-Adventures-in-Wonderland-2-by-Lewis-Carroll.pdf
- http://eascasas.myhome.cx/4aa3aa9aa7aa2aa1/The-Annotated-Alice-Alice-s-Adventures-in-Wonderland-and-Through-the-Looking-Glass-by-Lewis-Carroll.pdf
- http://eascasas.myhome.cx/5aa0aa5aa1aa9aa2/Alice-Through-the-Looking-Glass-by-Lewis-Carroll.pdf
- http://eascasas.myhome.cx/2aa9aa8aa9aa0aa3/Through-the-Looking-Glass-and-What-Alice-Found-There-by-Lewis-Carroll.pdf
- http://eascasas.myhome.cx/6aa0aa2aa3aa5aa1/Alice-in-Wonderland-and-Through-the-Looking-Glass-by-Lewis-Carroll.pdf
- http://eascasas.myhome.cx/6aa6aa3aa5aa9aa2/Alice-s-Adventures-in-Wonderland-and-Through-the-Looking-Glass-by-Lewis-Carroll.pdf
- http://eascasas.myhome.cx/6aa5aa9aa6aa0aa0/Alice-s-Adventures-in-Wonderland-amp-Through-the-Looking-Glass-by-Lewis-Carroll.pdf
- http://eascasas.myhome.cx/3aa4aa1aa0aa0aa6/Alice-s-Adventures-in-Wonderland-amp-Through-the-Looking-Glass-by-Lewis-Carroll.pdf
- http://eascasas.myhome.cx/5aa4aa6aa2aa0aa6/Alice-s-Adventures-in-Wonderland-and-Through-the-Looking-Glass-by-Lewis-Carroll.pdf
- http://eascasas.myhome.cx/2aa6aa4aa5aa1aa2/Alice-s-Adventures-in-Wonderland-and-Through-the-Looking-Glass-by-Lewis-Carroll.pdf
- http://eascasas.myhome.cx/8aa3aa2aa8aa2aa4/Alice-s-Adventures-in-Wonderland-Through-the-Looking-Glass-by-Lewis-Carroll.pdf
- http://eascasas.myhome.cx/5aa4aa8aa3aa7aa0/Alice-s-Adventures-in-Wonderland-amp-Through-the-Looking-Glass-by-Lewis-Carroll.pdf
- http://eascasas.myhome.cx/9aa9aa8aa1aa2aa1/Alice-s-Adventures-in-Wonderland-and-Through-the-Looking-Glass-by-Lewis-Carroll.pdf
- http://eascasas.myhome.cx/8aa7aa6aa9aa0/The-Co
Open this report in the interactive analyzer, or submit your own file for analysis.