MALICIOUS
194
Risk Score
Machine Learning
- Nyx PDF Classifier malicious score 1.0000
Heuristics 5
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Image lure linking to an SEO redirector (free-download phishing) high PDF_SEO_UTM_REDIRECTOR_LINKPDF embeds an image with little or no body text and a clickable link to a multi-word utm_term / FeedBurner-proxied SEO redirector — the 'free ebook / solution-manual / document download' phishing family that ranks for natural-language search queries and routes the user into a payload/redirect chain. The PDF carries no exploit; the risk is the linked destination. Flagged structurally (image lure + SEO redirector) so it does not depend on a ClamAV/ML signature, and regardless of how many filler text pages the lure carries.
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://cctraff.ru/strik?keyword=fresh+ham+steak+pressure+cooker In PDF document text
- https://cdn-cms.f-static.net/uploads/4366964/normal_5f874d919322c.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4381529/normal_5f8d7d5210dc6.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4365636/normal_5f90a06dee1a9.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4393485/normal_5f976d89d0343.pdfIn PDF document text
- http://www.ascendercorp.com/In PDF document text
- http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
- https://s3.amazonaws.com/kavitokolezub/siruleb.pdfIn PDF document text
- https://s3.amazonaws.com/wazotojemov/metal_carbene_complexes.pdfIn PDF document text
- https://s3.amazonaws.com/ditiruz/sql_tutorial_oracle_10g.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/645d63dc-c192-4bfc-8953-bbab5e0a46df/discrete_and_combinatorial_mathematics_an_applied_introduction.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/468b5024-e938-43bb-8452-b4d129dcc53e/vmware_unlocker_mojave.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/e74783ef-847b-42e9-afa4-adfaaebcc3b3/clasificacion_de_antibioticos_por_familias.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/9da0c106-ce9b-43eb-bc12-0d677878f0b2/76980448650.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/77825902-0c94-4404-ab99-5d8b308085ce/36073753612.pdfIn PDF document text
- https://cdn.shopify.com/s/files/1/0428/9737/5388/files/61156676871.pdfIn PDF document text
- https://cdn.shopify.com/s/files/1/0499/7745/8839/files/playground_marvel_studios_avengers_apk.pdfIn PDF document text
- https://cdn.shopify.com/s/files/1/0503/8650/1806/files/49546125852.pdfIn PDF document text
- https://cdn.shopify.com/s/files/1/0498/7768/0280/files/77280853947.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/01665cc7-2d01-4cc1-8884-be42eda47a81/game_of_thrones_8_sezon_4_blm_fragman_trke_altyazl_izle.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/f1b6e775-57e0-4dc7-94da-40deaa42a1c6/hp_pavilion_plugged_in_but_not_charging.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/21e93743-c6fe-46f4-b235-0fee0363cbb8/denewexekodemezivet.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/f37472b6-381f-46c2-8d9b-36a66962b396/florida_keys_fish_guide.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/497a6325-d29f-435f-be6f-2c99c604ba4e/25200100924.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/6c8bd497-1d1c-4f0c-aa01-00982150b435/35493466454.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/86dae278-dfbe-47c0-be87-7c2970a3f5dd/88052345762.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/a2837335-668a-4380-94ff-454518ec727c/teatro_griego_partes.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/e7493bd2-b916-4828-b11f-f803a76b4c6b/vuzuxisisivefiropiwiribe.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/4efa51b2-bf00-445b-9e08-358fdabc1e74/colombiana_full_movie_hindi_dubbed_hd.pdfIn PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/xap/1.0/rights/In PDF document text
- http://scripts.sil.org/OFLIn PDF document text
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00007c8f.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x7C8F | 5160 bytes |
SHA-256: 62e4e2cb28e31e9045b807d25fb6013528c93adbe51e0d9971d34e7754386119 |
|||
font_01_sfnt_off00008df8.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x8DF8 | 14100 bytes |
SHA-256: 617f7943ffc735b671f59cb13ab403293db3791359e0b9d76be806a5df3ca8aa |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.