MALICIOUS
126
Risk Score
Machine Learning
- Nyx PDF Classifier malicious score 0.9998
Heuristics 5
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARMSmall PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://pelibifir.ru/wix?keyword=perkasie+school+district PDF link annotation
- https://static.s123-cdn-static.com/uploads/4417119/normal_5ff790398372e.pdfIn PDF document text
- http://indohealth365.online/rivuketidevukuk4o57.pdfIn PDF document text
- https://cdn.sqhk.co/letaziseb/aP6WAfu/48296502509.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4384639/normal_5fd661d801b1c.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4418788/normal_6033ab30cfccb.pdfIn PDF document text
- https://cdn.sqhk.co/lexelinowe/4hhcYgi/29987955575.pdfIn PDF document text
- http://nepatokada.mypressonline.com/yamaha_mixing_console_model_mg10_2.pdfIn PDF document text
- http://rejemezurufoveg.mywebcommunity.org/32827684606.pdfIn PDF document text
- https://cdn.sqhk.co/fofateze/8iagiHz/4004955009.pdfIn PDF document text
- http://tortomsk.ru/farm_animals_toys_for_salenu3ft.pdfIn PDF document text
- http://gilumesu.mypressonline.com/jikisogojafonamuzik.pdfIn PDF document text
- https://cdn.sqhk.co/kogewole/djjEbbS/69107649744.pdfIn PDF document text
- http://konalofasu.mywebcommunity.org/is_kill_the_irishman_based_on_a_true_story.pdfIn PDF document text
- https://cdn.sqhk.co/jerivudofin/Ciajdif/1794924928.pdfIn PDF document text
- http://best-store.club/puzzle_page_answers_word_snake6rznn.pdfIn PDF document text
- http://www.ascendercorp.com/In PDF document text
- http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
- http://sogoxutagejuno.atwebpages.com/79617142351.pdfIn PDF document text
- http://zubiluwetij.myartsonline.com/how_to_change_epson_8350_bulb.pdfIn PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/xap/1.0/rights/In PDF document text
- http://scripts.sil.org/OFLIn PDF document text
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000dca2.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xDCA2 | 5092 bytes |
SHA-256: 8613f5a96755a8fb2a85ca075d9f8e4a182b751d66f933a2f58ec14a7ef6c3e0 |
|||
font_01_sfnt_off0000eded.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xEDED | 10856 bytes |
SHA-256: e9d9f2f10bc20202efa9b1adbddf11ea0487d1d9061d281e587a94138cb1fae7 |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.