MALICIOUS
92
Risk Score
Malware Insights
MITRE ATT&CK
T1566.002 Spearphishing Attachment
T1059.001 PowerShell
The PDF contains a large number of external links, indicating a link farm or redirection scheme. The ML classifier strongly flagged this PDF as malicious. The primary attack pattern involves directing users to a network of potentially malicious websites hosted on various domains. No scripts were extracted, limiting the analysis of direct payload delivery.
Machine Learning
- Nyx PDF Classifier malicious score 0.9999
Heuristics 3
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
External URI info PDF_URIPDF contains an external URL action
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL http://x0903667xstreamtravel.xsideas.com/uploads/1/3/0/6/130604741/130604741.html#harvard+undergraduate+research
- http://explorepassover.com/uploads/1/3/1/4/131453456/gisigumutoteju_tosixuwe_muvalivabopo.pdf
- http://mail.dingmac.com/uploads/1/3/0/4/130477584/f29a99e.pdf
- http://adaptiveavsolutions.com/uploads/1/3/0/6/130604821/81ad95.pdf
- http://homebodyandthenomad.com/uploads/1/3/0/4/130476684/a6419f5ab.pdf
- http://aperfectday.rocks/uploads/1/3/0/2/130272577/11967.pdf
- http://fromtheheartliving.com/uploads/1/3/0/6/130621101/319a1ca4b6d.pdf
- http://jensugdenphotography.com/uploads/1/3/1/4/131454158/7957464.pdf
- http://robinosos.com/uploads/1/3/0/4/130483645/bonekapezetul-bofed.pdf
- http://anadarkobasinllc.com/uploads/1/3/0/4/130436020/ramosavivaxaruso.pdf
- http://rgbatiment.net/uploads/1/3/0/7/130776111/vatoji-wivapobexow.pdf
- http://dailypersonalfinance.com/uploads/1/3/1/0/131071151/xesivokuk.pdf
- http://wakeboatporn.net/uploads/1/3/1/4/131438294/vinaseriw_siwusaxenituzet_patef.pdf
- http://tomsfood.com/uploads/1/3/0/7/130775352/86d4131c44.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Extracted artifacts 1
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000b90f.bin4cecdb961daadc2443301a7af4f0b54ac5bfbb4b941d4cf8c4d55fd947ed5e79 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xB90F | 11008 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.