MALICIOUS
90
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Phishing: Spearphishing Attachment
The PDF was flagged by a critical heuristic for containing a mass external link farm, with 27 links identified. The embedded URLs, such as http://xiixmcuin.linkpc.net/1201200202206204206/American-Legends-The-Life-of-Red-Skelton-by-Charles-River-Editors.pdf, are likely part of this scheme. The ML classifier also strongly indicated maliciousness. No scripts were extracted, and the document body was heavily obfuscated, making it difficult to determine a more specific attack pattern beyond link farming.
Machine Learning
- Nyx PDF Classifier malicious score 0.9903
Heuristics 2
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL http://xiixmcuin.linkpc.net/1201200202206204206/American-Legends-The-Life-of-Red-Skelton-by-Charles-River-Editors.pdf
- http://xiixmcuin.linkpc.net/4207206201201208/American-Legends-The-Life-of-Walt-Disney-by-Charles-River-Editors.pdf
- http://xiixmcuin.linkpc.net/1200208208202205206/American-Legends-The-Life-of-Marvin-Gaye-by-Charles-River-Editors.pdf
- http://xiixmcuin.linkpc.net/1200209204200201207/American-Legends-The-Life-of-Dolly-Parton-by-Charles-River-Editors.pdf
- http://xiixmcuin.linkpc.net/7207208204209207/Legends-of-the-Renaissance-The-Life-and-Legacy-of-Lucrezia-Borgia-by-Charles-River-Editors.pdf
- http://xiixmcuin.linkpc.net/8209205206202201/Heinz-Guderian-The-Life-and-Legacy-of-Nazi-Germany-s-Famous-Panzer-Commander-by-Charles-River-Editors.pdf
- http://xiixmcuin.linkpc.net/1200202202206203203/Assur-The-History-and-Legacy-of-the-Ancient-Assyrian-Empire-s-Capital-City-by-Charles-River-Editors.pdf
- http://xiixmcuin.linkpc.net/7207203205202202/The-Vikings-in-North-America-The-History-and-Legacy-of-the-Norse-Settlements-in-Greenland-and-Vinland-by-Charles-River-Editors.pdf
- http://xiixmcuin.linkpc.net/9202208202206201/The-Rise-of-Nazi-Germany-The-History-of-the-Events-that-Brought-Adolf-Hitler-to-Power-by-Charles-River-Editors.pdf
- http://xiixmcuin.linkpc.net/6207200204205206/The-League-of-Nations-The-Controversial-History-of-the-Failed-Organization-that-Preceded-the-United-Nations-by-Charles-River-Editors.pdf
- http://xiixmcuin.linkpc.net/5201206208203206/AMERICAN-BOTTOM-ARCH-A-Summary-of-the-FAI-270-Project-Contribution-to-the-Culture-History-of-the-Mississippi-River-Valley-by-Charles-J-Bareis.pdf
- http://xiixmcuin.linkpc.net/4207207205202/Red-Delta-Fighting-for-Life-at-the-End-of-the-Colorado-River-by-Charles-Bergman.pdf
- http://xiixmcuin.linkpc.net/6200209208202202/Gila-The-Life-And-Death-Of-An-American-River-by-Gregory-McNamee.pdf
- http://xiixmcuin.linkpc.net/8201209200204205/American-Cicero-The-Life-of-Charles-Carroll-by-Bradley-J-Birzer.pdf
- http://xiixmcuin.linkpc.net/1200207207209208203/South-American-Myths-amp-Legends-World-Book-Myths-amp-Legends-Series-by-Philip-Ardagh.pdf
- http://xiixmcuin.linkpc.net/1201200202206209204/Red-Skelton-s-Favorite-Ghost-Stories-by-Red-Skelton.pdf
- http://xiixmcuin.linkpc.net/1201200200202206/Margaret-Fuller-An-American-Romantic-Life-Vol-1-The-Private-Years-by-Charles-Capper.pdf
- http://xiixmcuin.linkpc.net/1203208201207201/The-Bell-Curve-Intelligence-and-Class-Structure-in-American-Life-by-Charles-Murray.pdf
- http://xiixmcuin.linkpc.net/1205209207207207/An-American-Profession-of-Arms-The-Army-Officer-Corps-1784-1861-by-William-B-Skelton.pdf
- http://xiixmcuin.linkpc.net/5201202202208206/Sworn-to-Secrecy---For-Life-A-Young-American-Spy-s-Odyssey-Through-War-Torn-Germany-and-Russia-by-Charles-Joseph-Fickey.pdf
- http://xiixmcuin.linkpc.net/12002022022
Open this report in the interactive analyzer, or submit your own file for analysis.