MALICIOUS
194
Risk Score
Machine Learning
- Nyx PDF Classifier malicious score 1.0000
Heuristics 5
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Image lure linking to an SEO redirector (free-download phishing) high PDF_SEO_UTM_REDIRECTOR_LINKPDF embeds an image with little or no body text and a clickable link to a multi-word utm_term / FeedBurner-proxied SEO redirector — the 'free ebook / solution-manual / document download' phishing family that ranks for natural-language search queries and routes the user into a payload/redirect chain. The PDF carries no exploit; the risk is the linked destination. Flagged structurally (image lure + SEO redirector) so it does not depend on a ClamAV/ML signature, and regardless of how many filler text pages the lure carries.
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://ggtraff.ru/strik?keyword=ancient+greek+civilization+summary+pdf In PDF document text
- http://foxuzikum.sanfranrevelstoke.org/uploads/1/3/1/6/131637257/6653694beabd8f0.pdfIn PDF document text
- http://files.toddwyant.com/uploads/1/3/1/4/131452846/9ccb1ded4049c18.pdfIn PDF document text
- http://musajizu.chisagocountyfair.org/uploads/1/3/1/3/131379992/7287413.pdfIn PDF document text
- http://files.ps22q.com/uploads/1/3/1/8/131871781/41130f75fb24.pdfIn PDF document text
- http://jopumat.zerohourtimes.com/uploads/1/3/1/4/131406121/4517310.pdfIn PDF document text
- http://www.ascendercorp.com/In PDF document text
- http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
- https://uploads.strikinglycdn.com/files/b3b2c917-89b2-484f-8e69-69099888ccb2/xokivevaratafaguzadek.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/81a4abb0-2e35-4a05-93bf-188c4ef9960f/40860196220.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/39db3e72-5d34-466e-bc2c-1229382b6f97/dezikadamusinuzetuk.pdfIn PDF document text
- https://cdn.shopify.com/s/files/1/0437/4780/3287/files/maplestory_m_cygnus_guide.pdfIn PDF document text
- https://cdn.shopify.com/s/files/1/0427/9389/4044/files/87520244604.pdfIn PDF document text
- https://cdn.shopify.com/s/files/1/0429/6661/4175/files/70920386367.pdfIn PDF document text
- https://cdn.shopify.com/s/files/1/0463/2100/8802/files/rolokoropabun.pdfIn PDF document text
- https://cdn.shopify.com/s/files/1/0432/6152/6166/files/different_types_of_aluminum_sheet_metal.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/d8685205-851e-42fe-be65-e1d071cd5605/jerobidukokosirol.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/4eb7e662-9f27-42cb-b518-78f1cbc42f91/66590453048.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/0070abce-f843-4eae-8526-1ae92006c19b/49878873613.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/1e5690ca-717d-4299-ba58-23fa1b4cbb51/fozulavisuwovilavifof.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/5d46c771-d6d4-4ec4-824c-06c0b093188c/bizokuki.pdfIn PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/xap/1.0/rights/In PDF document text
- http://scripts.sil.org/OFLIn PDF document text
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off000077aa.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x77AA | 5740 bytes |
SHA-256: ed7af89645ab17d365b741e4a03c3a6f97b53a70d474ab3d22558bf3a2c158a4 |
|||
font_01_sfnt_off00008b40.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x8B40 | 9964 bytes |
SHA-256: f8832b34fbb46dfd7ab6ebb4797988c615741426516675a354f74a069e5a2811 |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.