MALICIOUS
100
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
The PDF contains a large number of embedded external links, identified as a link farm. While the URLs themselves are marked as benign, the heuristic 'PDF_SEO_LINK_FARM' indicates a malicious intent to manipulate search engine results or direct users to a large number of external resources. The ML classifier also flagged the PDF as malicious with high confidence.
Machine Learning
- Nyx PDF Classifier malicious score 0.9920
Heuristics 3
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTONDocument contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL http://muicuiu.dumb1.com/7a04a06a07a09a07/Competition-in-Telecommunications-by-Jean-Jacques-Laffont.pdf In PDF document text
- http://muicuiu.dumb1.com/6a06a01a02a00a03/Articles-on-French-Comics-Artists-Including-Enki-Bilal-Jacques-Tardi-R-GIS-Loisel-Joann-Sfar-Jean-Jacques-Semp-Jacques-Martin-Comics-Fran-OIS-Bourgeon-Jean-Graton-Emmanuel-Larcenet-David-Beauchard-Michel-Rodrigue-by-Hephaestus-Books.pdfIn PDF document text
- http://muicuiu.dumb1.com/8a04a04a08a01a08/Accuser-et-s-duire-Essais-sur-Jean-Jacques-Rousseau-by-Jean-Starobinski.pdfIn PDF document text
- http://muicuiu.dumb1.com/5a03a05a00a06a06/The-Confessions-of-Jean-Jacques-Rousseau-3-by-Jean-Jacques-Rousseau.pdfIn PDF document text
- http://muicuiu.dumb1.com/2a09a04a06a05a02/The-Musicians-by-Jean-Jacques-Semp-.pdfIn PDF document text
- http://muicuiu.dumb1.com/1a08a03a00a07a05/The-Confessions-by-Jean-Jacques-Rousseau.pdfIn PDF document text
- http://muicuiu.dumb1.com/1a01a07a03a00a07a01/A-Discourse-on-Inequality-by-Jean-Jacques-Rousseau.pdfIn PDF document text
- http://muicuiu.dumb1.com/1a01a05a02a08a03/Death-by-Publication-by-Jean-Jacques-Fiechter.pdfIn PDF document text
- http://muicuiu.dumb1.com/5a04a00a00a08a02/Du-contrat-social-by-Jean-Jacques-Rousseau.pdfIn PDF document text
- http://muicuiu.dumb1.com/7a02a06a06a01a02/L-me-de-l-organisation-by-Jean-Jacques-amp-Collab-Bourque.pdfIn PDF document text
- http://muicuiu.dumb1.com/4a09a04a04a03/Emile-or-On-Education-by-Jean-Jacques-Rousseau.pdfIn PDF document text
- http://muicuiu.dumb1.com/5a03a05a01a06a04/On-the-Origin-of-Language-by-Jean-Jacques-Rousseau.pdfIn PDF document text
- http://muicuiu.dumb1.com/4a04a04a04a07/The-Social-Contract-by-Jean-Jacques-Rousseau.pdfIn PDF document text
- http://muicuiu.dumb1.com/6a04a07a00a07a05/Le-Loup-Du-Massif-Du-Lac-Jacques-Cartier-by-Jean-Flori.pdfIn PDF document text
- http://muicuiu.dumb1.com/3a06a09a03a07a08/The-Baby-Factory-The-Genesis-Society-by-Jean-Jacques.pdfIn PDF document text
- http://muicuiu.dumb1.com/2a09a02a07a06a00/The-Social-Contract-and-Discourses-by-Jean-Jacques-Rousseau.pdfIn PDF document text
- http://muicuiu.dumb1.com/6a01a00a06a01a07/Discours-Sur-l-Origine-De-l-Inegalite-by-Jean-Jacques-Rousseau.pdfIn PDF document text
- http://muicuiu.dumb1.com/8a04a04a07a05a04/Tr-umereien-eines-einsam-Schweifenden-by-Jean-Jacques-Rousseau.pdfIn PDF document text
- http://muicuiu.dumb1.com/1a01a07a03a01a03a05/The-Noble-Savage-Jean-Jacques-Rousseau-1754-1762-by-Maurice-Cranston.pdfIn PDF document text
- http://muicuiu.dumb1.com/5a09a04a05a02a09/discours-sur-l-origine-et-les-fondements-de-l-in-galit-parmi-les-hommes-by-Jean-Jacques-Rousseau.pdfIn PDF document text
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
stream_000_off000001c6.bin |
decompressed-pdf-stream | PDF FlateDecoded stream at offset 0x1C6 | 9272 bytes |
SHA-256: ce965a3a26beb988008c4d65f6bf3ec0f8f8b84de83256d3288a2c3a329b3adf |
|||
stream_001_off00000c04.bin |
decompressed-pdf-stream | PDF FlateDecoded stream at offset 0xC04 | 2575 bytes |
SHA-256: dd8cc828878658c193c3d8689d42f29c2336c00ef6e8c0447864f1129a65f51c |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.