MALICIOUS
136
Risk Score
Machine Learning
- Nyx PDF Classifier suspicious score 0.3305
Heuristics 6
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
Image lure linking to an SEO redirector (free-download phishing) high PDF_SEO_UTM_REDIRECTOR_LINKPDF embeds an image with little or no body text and a clickable link to a multi-word utm_term / FeedBurner-proxied SEO redirector — the 'free ebook / solution-manual / document download' phishing family that ranks for natural-language search queries and routes the user into a payload/redirect chain. The PDF carries no exploit; the risk is the linked destination. Flagged structurally (image lure + SEO redirector) so it does not depend on a ClamAV/ML signature, and regardless of how many filler text pages the lure carries.
-
PDF link farm points to compromised-WordPress upload storage medium PDF_COMPROMISED_CMS_UPLOAD_LINK_FARMPDF contains multiple clickable links, across many distinct hosts, whose targets are random-slug files parked in the upload directories of vulnerable WordPress form plugins (FormCraft, Super Forms). This is the hallmark of the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains hosted on compromised sites. The PDF itself carries no exploit — the risk is the linked destinations.
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://khanikango.in/file/bilizomiloka.pdf In PDF document text
- http://inoxbienhoa.com/upload/files/19489378580.pdfIn PDF document text
- http://getsolarny.com/userfiles/file/bemapidekufazugigimof.pdfIn PDF document text
- https://safewatersolutions.in/ckfinder/userfiles/files/48452199906.pdfIn PDF document text
- https://simpeg.unsam.ac.id/kcfinder/upload/files/79310661763.pdfIn PDF document text
- https://www.cuadernosmanchegos.com/panel/cuadrodemandos/assets/ckeditor/kcfinder/upload/files/70729561569.pdfIn PDF document text
- http://dieta-plus.pl/userfiles/file/30316810167.pdfIn PDF document text
- http://csim.jp/ckeditor/uploads/files/fodezibafenenozabof.pdfIn PDF document text
- http://novotulka.ru/upload/files/sevukudepoxojewozul.pdfIn PDF document text
- https://blagoustroystvo24.ru/ckfinder/userfiles/files/1932685498.pdfIn PDF document text
- http://dentherapia.hu/files/file/80038192241.pdfIn PDF document text
- https://socialacademy.gr/wp-content/plugins/super-forms/uploads/php/files/8ad8019f50d0c85f016280d755bee5b9/jokuwefubifin.pdfIn PDF document text
- http://grupomagister.com.br/kcfinder/upload/files/rulagexijigur.pdfIn PDF document text
- https://ppuhperspektywa.pl/files/edytor/file/dunubitak.pdfIn PDF document text
- https://maleki-group.ir/js/kcfinder/upload/files/basepa.pdfIn PDF document text
- http://smartbazar.online/app/webroot/upload/files/xotejukewis.pdfIn PDF document text
- https://prolinenergy.com/Admin/plugins/ckeditor/kcfinder/upload/files/53005356089.pdfIn PDF document text
- https://hladiagnostico.com.br/kcfinder/upload/files/nitivulojaxesetidujoz.pdfIn PDF document text
- http://drapikowski.pl/uploaded/fck_files/file/fajavadadilu.pdfIn PDF document text
- https://www.crossfitparamaribo.com/wp-content/plugins/formcraft/file-upload/server/content/files/162360382737c5---55523281706.pdfIn PDF document text
- https://artgallery.devctn.com/ckfinder/userfiles/files/33542821139.pdfIn PDF document text
- https://cpo.artacademyplovdiv.com/cpo_files/file/15912313403.pdfIn PDF document text
- https://www.d-table.com/wp-content/plugins/super-forms/uploads/php/files/29953cefeae27d13f188cdd8fe607975/sesarumizugudugasikeraz.pdfIn PDF document text
- http://nfc.soo.jp/file/jukulurerejubapegaxi.pdfIn PDF document text
- http://www.roosprommenschenckelfoundation.nl/ckfinder/files/files/29601573703.pdfIn PDF document text
- https://solelane.com/ckfinder/userfiles/files/15467710077.pdfIn PDF document text
- http://botan-koubou.com/js/kcfinder/upload/files/lumiduvedas.pdfIn PDF document text
- http://proxima-design.cz/files/file/xabijufuzebilubunisuzo.pdfIn PDF document text
- http://inhome360.ru/admin/ckfinder/userfiles/files/29725323651.pdfIn PDF document text
- http://www.investing-in-women.com/wp-content/plugins/formcraft/file-upload/server/content/files/162307091741af---lozaxoxodiliduxefimi.pdfIn PDF document text
- https://cuisinescartier.ca/upload/editor/file/ruwedotixurixurasezurukug.pdfIn PDF document text
- http://jun-travel.com/userfiles/file/97426723123.pdfIn PDF document text
- http://apisicul.com/userfiles/files/jidopabejufo.pdfIn PDF document text
- http://sergeisurzhin.ru/ckfinder/userfiles/files/67269266087.pdfIn PDF document text
- https://westech.solar-napkollektor.hu/js/ckfinder/userfiles/files/tubikowowenaz.pdfIn PDF document text
- https://yaofangpeixun.com/upload/files/69862216711.pdfIn PDF document text
- http://termosystem.pl/userfiles/file/79178033135.pdfIn PDF document text
- https://partnyor.az/userfiles/file/dufozelisilobiwaturevape.pdfIn PDF document text
- https://3drm.bg/uploads/pictures/files/jamuwisosidegaleluzidex.pdfIn PDF document text
- https://resortweeks.pro/userfiles/file/goboluvi.pdfIn PDF document text
- https://www.yamanosake.com/js/kcfinder/upload/files/zofofilubinekawej.pdfIn PDF document text
- https://www.cis2020.scrs.in/kcfinder/upload/files/vusinobejotebojofo.pdfIn PDF document text
- http://helix.chuing.net/mai/ckfile/files/15594358161.pdfIn PDF document text
- http://rediger.vammenkro.dk/upload/files/67915172468.pdfIn PDF document text
- https://laval.gatr.ca/img/etablissements/files/96405212424.pdfIn PDF document text
- http://klwas.org/userfiles/images/file/logarafigulupodigotipu.pdfIn PDF document text
- http://keemunblacktea.cn/uploads/file/140313475838.pdfIn PDF document text
- http://isisorganizasyon.net/panel/kcfinder/upload/files/perixepuxut.pdfIn PDF document text
- http://ildong.org/sa_upload/userfiles/file/20220222130829.pdfIn PDF document text
- http://xdankfort.com/rhnew/file/51983571356.pdfIn PDF document text
+12 more URL(s)
Extracted artifacts 5
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0004cd96.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x4CD96 | 16992 bytes |
SHA-256: 1cd524ef3ee11011214347cbdd6ddd08f93db625ba4b9ad5b1912d86e7d67862 |
|||
font_01_sfnt_off0004e5ea.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x4E5EA | 16560 bytes |
SHA-256: 924ad5cb737cfd9a34472b2046831991df4d3950e5f0d7b552a18309318c2ee9 |
|||
font_02_sfnt_off0004fd0d.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x4FD0D | 15216 bytes |
SHA-256: a67b37a2277044d0d01f34d592e1d7e695a4522bcbf4143ecd608222d055f297 |
|||
font_03_sfnt_off00052d10.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x52D10 | 19444 bytes |
SHA-256: 90e3ee0dd86c2d9cbc1547a3c0cda3fb98448bf1130e268bede016077ff6cbc0 |
|||
font_04_sfnt_off00055f17.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x55F17 | 11096 bytes |
SHA-256: 3ff96d12cc4d8f29ba9aa5cf5ee959a074d2055a0aa3c83553e5d0aa9b9ecbae |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.