MALICIOUS
166
Risk Score
Machine Learning
- Nyx PDF Classifier malicious score 0.5565
Heuristics 6
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
Image lure linking to an SEO redirector (free-download phishing) high PDF_SEO_UTM_REDIRECTOR_LINKPDF embeds an image with little or no body text and a clickable link to a multi-word utm_term / FeedBurner-proxied SEO redirector — the 'free ebook / solution-manual / document download' phishing family that ranks for natural-language search queries and routes the user into a payload/redirect chain. The PDF carries no exploit; the risk is the linked destination. Flagged structurally (image lure + SEO redirector) so it does not depend on a ClamAV/ML signature, and regardless of how many filler text pages the lure carries.
-
PDF link farm points to compromised-WordPress upload storage medium PDF_COMPROMISED_CMS_UPLOAD_LINK_FARMPDF contains multiple clickable links, across many distinct hosts, whose targets are random-slug files parked in the upload directories of vulnerable WordPress form plugins (FormCraft, Super Forms). This is the hallmark of the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains hosted on compromised sites. The PDF itself carries no exploit — the risk is the linked destinations.
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://yubit.co.za/XSRYdR1H?utm_term=pandora%27+s+box+puzzle+game+free PDF link annotation
- http://fashionflutters.com/ckfinder/userfiles/files/59552697837.pdfIn PDF document text
- http://jl-vacuum.com/upload/files/zujimuvajonulesef.pdfIn PDF document text
- http://alrehabourhome.com/userfiles/files/20826359782.pdfIn PDF document text
- http://zensushialiso.com/uploads/files/dujarafisurivigegunoz.pdfIn PDF document text
- http://computer-rudolstadt.de/upload/file/riteromokitosevimigeze.pdfIn PDF document text
- https://producedepot.us/userfiles/files/50019854423.pdfIn PDF document text
- http://dermalab.pl/userfiles/file/3774480535.pdfIn PDF document text
- http://vizilo-vizitura.hu/admin/kcfinder/upload/files/ladame.pdfIn PDF document text
- http://www.hebrewforreadingcomprehension.com/content/4460612134.pdfIn PDF document text
- http://cpk.by/ckfinder/userfiles/files/58317664458.pdfIn PDF document text
- http://f-okinawa.com/img/tmp/file/91350016829.pdfIn PDF document text
- https://refakatci.net/userfiles/file/rixoteta.pdfIn PDF document text
- http://altiro.nl/home/tjerk/file/48553240210.pdfIn PDF document text
- http://musicincw.com/fckeditor/userfiles/image/dajamoteratinudifetixanuw.pdfIn PDF document text
- https://nitdgp.ac.in/uploads/userfiles/files/kowonubemi.pdfIn PDF document text
- https://taipeitccia.org/CKEdit/upload/files/genadimipifemeju.pdfIn PDF document text
- http://ozhelalikram.de/resimler/files/89177936906.pdfIn PDF document text
- https://rrvchefs.com/wp-content/plugins/super-forms/uploads/php/files/52625b4884c6eb51e746cd95da4f9abf/2750216843.pdfIn PDF document text
- http://audiencefertilization.com/fckeditor/editor/filemanager/connectors/php/userfiles/file/getidilevowowav.pdfIn PDF document text
- http://jian-yuan.com.tw/kcfinder/upload/files/lipuziji.pdfIn PDF document text
- https://www.wikiwebagency.it/wp-content/plugins/super-forms/uploads/php/files/ba384324c0b21b5177c9df4c3ae35341/lanivoxofibivawusekibef.pdfIn PDF document text
- https://jetaime-shop.dvsportbg.com/files/31377996598.pdfIn PDF document text
- http://atel-j.nl/uploads/files/3659125798.pdfIn PDF document text
- https://grup-rul.ro/printuri-fi/files/bigefanif.pdfIn PDF document text
- https://jackinthegym.com/uploads/files/202109090728189007.pdfIn PDF document text
- https://alarrabnews.com/images/content/content/file/jimesosetomi.pdfIn PDF document text
- http://www.playerclub.ro/wp-content/plugins/formcraft/file-upload/server/content/files/161e8aed748a36---vidiwiwiv.pdfIn PDF document text
- https://peltonfell.org.uk/ckfinder/userfiles/files/lulazuz.pdfIn PDF document text
- https://netiko.fr/img/Data/file/sabazelo.pdfIn PDF document text
- http://lesboutiquesquercitaines.com/kcfinder/upload/files/zurolivefapijus.pdfIn PDF document text
- http://robertoantoniz.com/resources/original/file/36921726617.pdfIn PDF document text
- http://ghemassagenhatban.vn/Images_upload/files/50598488214.pdfIn PDF document text
- http://laser-piskovani.cz/democms/userfiles/file/zinodixabetegurumazeso.pdfIn PDF document text
- https://hoangphatdanang.xetnghiemadndanang.com/uploads/image/files/93463198348.pdfIn PDF document text
- https://gestionarival.com/userfiles/file/vinexopodopemowubibojezil.pdfIn PDF document text
- https://goez1.com/10005001208290177/ckfinder/userfiles/files/6057730662.pdfIn PDF document text
- https://chemainus.gocascadia.com/images/cms/file/rosigokojalexisas.pdfIn PDF document text
- http://driver-jazda.pl/upload/file/27648129458.pdfIn PDF document text
- https://ngoctraithaibinhduong.com/uploads/news_file/xuvud.pdfIn PDF document text
- http://www.next-conseil.fr/wp-content/plugins/formcraft/file-upload/server/content/files/161bc34f6f1d2c---22337351321.pdfIn PDF document text
- https://www.ideakliniksisli.com/wp-content/plugins/formcraft/file-upload/server/content/files/1618f28faee3a1---63160954251.pdfIn PDF document text
- https://rescue.bg/wp-content/plugins/formcraft/file-upload/server/content/files/16186b9811aa3c---97810244390.pdfIn PDF document text
- https://dispomydeal.com/wp-content/plugins/super-forms/uploads/php/files/c975264a8f900b1c3042de3977db8956/48545968105.pdfIn PDF document text
- http://stroynerud-sm.ru/wp-content/plugins/formcraft/file-upload/server/content/files/1614c348eb642e---xudabamubeduwojas.pdfIn PDF document text
- http://okna-stv.ru/userfiles/files/96652926319.pdfIn PDF document text
- http://chin.getrade.net/uploadfiles/file/77969579948.pdfIn PDF document text
- http://e-photosynthesis.org/userfiles/file/pazabulewabugufowur.pdfIn PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
+6 more URL(s)
Extracted artifacts 3
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0004ae94.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x4AE94 | 16384 bytes |
SHA-256: 16c14c08c25c04a45c3ef5678294fa41e9872e6cde3351ae2166250eaec6b19a |
|||
font_01_sfnt_off0004d8fe.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x4D8FE | 16416 bytes |
SHA-256: cfa2c3fbce80cc5607e01af033b793d17c57c214fb1d96e845eedea48cccd336 |
|||
font_02_sfnt_off0004efa8.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x4EFA8 | 11088 bytes |
SHA-256: b1a1de8047b9864d9aab1215ceb4136690e4c6bdb7c562d8ddd9f2ca00bf12c0 |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.