MALICIOUS
166
Risk Score
Machine Learning
- Nyx PDF Classifier malicious score 0.6000
Heuristics 6
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
Image lure linking to an SEO redirector (free-download phishing) high PDF_SEO_UTM_REDIRECTOR_LINKPDF embeds an image with little or no body text and a clickable link to a multi-word utm_term / FeedBurner-proxied SEO redirector — the 'free ebook / solution-manual / document download' phishing family that ranks for natural-language search queries and routes the user into a payload/redirect chain. The PDF carries no exploit; the risk is the linked destination. Flagged structurally (image lure + SEO redirector) so it does not depend on a ClamAV/ML signature, and regardless of how many filler text pages the lure carries.
-
PDF link farm points to compromised-WordPress upload storage medium PDF_COMPROMISED_CMS_UPLOAD_LINK_FARMPDF contains multiple clickable links, across many distinct hosts, whose targets are random-slug files parked in the upload directories of vulnerable WordPress form plugins (FormCraft, Super Forms). This is the hallmark of the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains hosted on compromised sites. The PDF itself carries no exploit — the risk is the linked destinations.
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://yoyep.co.za/XSRYdR1H?utm_term=free+complete+subject+and+predicate+worksheets PDF link annotation
- https://www.sistemkabin.com/ckfinder/userfiles/files/fekazelusodagev.pdfIn PDF document text
- http://maybaobidinhdinh.com/upload/files/rerirupigexuragapej.pdfIn PDF document text
- http://www.abcklima.hu/data/editorfile/nupegosigoxekaxado.pdfIn PDF document text
- http://elitakhealing.com/ckfinder/userfiles/files/fifivafevevevotuvi.pdfIn PDF document text
- http://gospel-pour-100-voix.com/fichiers/newsletter/file/nofaridutosenulifunowukin.pdfIn PDF document text
- https://samajsutra.com/userfiles/files/43216677224.pdfIn PDF document text
- http://teen.plovdivweek.com/js/ckfinder/userfiles/files/29948233540.pdfIn PDF document text
- http://srhs1980.com/clients/877094/File/30059205433.pdfIn PDF document text
- http://structurecreative.com/wp-content/plugins/formcraft/file-upload/server/content/files/16109afcc8b606---33241815193.pdfIn PDF document text
- https://walkandsmile.com/userfiles/file/pajuwekidudaxawolav.pdfIn PDF document text
- http://biondiairsystem.it/userfiles/files/fumikerezologupif.pdfIn PDF document text
- http://www.primalegal.eu/wp-content/plugins/super-forms/uploads/php/files/4knaueaaj32ke9693tmrkmurm5/nozavafudujide.pdfIn PDF document text
- https://edubox.mn/uploads/users/0/files/joloxuzekekamigujoto.pdfIn PDF document text
- https://mavismanagement.com/wp-content/plugins/formcraft/file-upload/server/content/files/161f73391a3a61---vitafudazepud.pdfIn PDF document text
- http://biznesfishki.ru/files/userfiles/files/61126433001.pdfIn PDF document text
- http://mskabel.cz/UserFiles/File/jagevefawivuj.pdfIn PDF document text
- http://www.mardancci.com/assets/ckeditor/kcfinder/upload/files/8267894280.pdfIn PDF document text
- https://keluargamimpi.com/contents//files/jeduwukoduzelesa.pdfIn PDF document text
- http://www.trackls.com/application/ckeditor/ckfinder/userfiles/files/jegeriraf.pdfIn PDF document text
- http://showpelec.com/data/file/20211027_112429_385.pdfIn PDF document text
- http://edv-denk.com/userfiles/file/73816255665.pdfIn PDF document text
- https://sharzh-ufa.ru/wp-content/plugins/super-forms/uploads/php/files/b611d62fe2f2624070d08f3b109c3804/napaxusema.pdfIn PDF document text
- https://sklepbonus.pl/userfiles/file/38919567891.pdfIn PDF document text
- https://www.puskinas.lt/ckfinder/userfiles/files/44846517820.pdfIn PDF document text
- http://kientrucphatloc.com/upload/files/wineku.pdfIn PDF document text
- http://kfnmsz.com/upfolder/e/files/20220106142114.pdfIn PDF document text
- https://shiokuda2.com/contents/files/60847399793.pdfIn PDF document text
- http://arndt-fahrschule.de/userfiles/file/14261791782.pdfIn PDF document text
- http://entrackintl.com/uploads/munuzukozuwaxizo.pdfIn PDF document text
- https://www.mtiwelding.co.uk/admin/ckfinder/userfiles/files/36039968350.pdfIn PDF document text
- https://geneolock.com/ckfinder/userfiles/files/nakuget.pdfIn PDF document text
- http://flussobjekte.at/kcfinder/upload/files/jokaliviluvabafagazafo.pdfIn PDF document text
- http://elvirajogsi.hu/ckfinder/userfiles/files/3302856198.pdfIn PDF document text
- http://sladkiy-ostrov.ru/userfiles/files/latovuvejeda.pdfIn PDF document text
- http://www.hkwebdesign.com.hk/wp-content/plugins/formcraft/file-upload/server/content/files/161ef0d6ff1e00---lanega.pdfIn PDF document text
- https://mamotato.ro/userfiles/file/jabizefud.pdfIn PDF document text
- http://sambometal.com/dataroom/file/36082477089.pdfIn PDF document text
- http://alvit-bk.ru/userfiles/file/jeremovuwadusupoveveb.pdfIn PDF document text
- http://rydelko.pl/userfiles/file/molusajid.pdfIn PDF document text
- http://www.hypnotiseur.com/wp-content/plugins/formcraft/file-upload/server/content/files/161b50d3e516e5---51083015236.pdfIn PDF document text
- http://aligokdemir.com/resimler/files/59332832979.pdfIn PDF document text
- https://mytalk7.com/_UploadFile/Images/file/54636340288.pdfIn PDF document text
- https://trade.inter-ural.ru/ckfinder/userfiles/files/tomugexonosofudaruwus.pdfIn PDF document text
- http://global-poseg.com/wp-content/plugins/formcraft/file-upload/server/content/files/161e847f13523d---zuminokekomarapekubagu.pdfIn PDF document text
- https://thaiwoodengames.com/files/upload/files/7423139482.pdfIn PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
+4 more URL(s)
Extracted artifacts 3
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0004a1e8.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x4A1E8 | 17084 bytes |
SHA-256: 5d761b17f9642b7cafd9eb7a11525afc9d49b94f8cc939e70112b5ee34c78cbe |
|||
font_01_sfnt_off0004cdfe.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x4CDFE | 11304 bytes |
SHA-256: a693b17ac4fd5f1eef10f4ffd08375cf583fddf4ebc70e21622faeb403314c01 |
|||
font_02_sfnt_off0004e826.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x4E826 | 16560 bytes |
SHA-256: 924ad5cb737cfd9a34472b2046831991df4d3950e5f0d7b552a18309318c2ee9 |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.