MALICIOUS
174
Risk Score
Machine Learning
- Nyx PDF Classifier malicious score 0.6567
Heuristics 7
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
Image lure linking to an SEO redirector (free-download phishing) high PDF_SEO_UTM_REDIRECTOR_LINKPDF embeds an image with little or no body text and a clickable link to a multi-word utm_term / FeedBurner-proxied SEO redirector — the 'free ebook / solution-manual / document download' phishing family that ranks for natural-language search queries and routes the user into a payload/redirect chain. The PDF carries no exploit; the risk is the linked destination. Flagged structurally (image lure + SEO redirector) so it does not depend on a ClamAV/ML signature, and regardless of how many filler text pages the lure carries.
-
PDF link farm points to compromised-WordPress upload storage medium PDF_COMPROMISED_CMS_UPLOAD_LINK_FARMPDF contains multiple clickable links, across many distinct hosts, whose targets are random-slug files parked in the upload directories of vulnerable WordPress form plugins (FormCraft, Super Forms). This is the hallmark of the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains hosted on compromised sites. The PDF itself carries no exploit — the risk is the linked destinations.
-
Embedded JS stream low PDF_JSPDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://lovig.co.za/XSRYdR1H?utm_term=birthday+card+template+unicorn PDF link annotation
- http://dpsnowodworze.pl/userfiles/file/43708978819.pdfIn PDF document text
- http://artetendasud.it/userfiles/files/lazibotiketaxonula.pdfIn PDF document text
- http://xn--h49al33a2zdp0eo1x.com/DATA/file/20211016034451.pdfIn PDF document text
- http://www.neoneofitou.com/ckfinder/userfiles/files/36405021408.pdfIn PDF document text
- http://dhs-bank-sample.com/app/webroot/js/kcfinder/upload/files/39147611615.pdfIn PDF document text
- http://www.icareonline.net.au/ckfinder/icare/files/68504267849.pdfIn PDF document text
- https://www.sussexweddingservices.co.uk/wp-content/plugins/formcraft/file-upload/server/content/files/161f1557ae26fa---80923459238.pdfIn PDF document text
- http://villaturri.it/wp-content/plugins/formcraft/file-upload/server/content/files/1618793004f640---72685183954.pdfIn PDF document text
- http://sportgalaktik.sk/userfiles/file/88720054827.pdfIn PDF document text
- https://eastmanllc.net/ckfinder/userfiles/files/nulokiburaroxemu.pdfIn PDF document text
- https://latrinquette.com/upload/editor/file/23910671911.pdfIn PDF document text
- https://essuances.com/ckfinder/userfiles/files/pulotojirofoxalogup.pdfIn PDF document text
- https://gangwontaxi.com/FileData/ckfinder/files/20220213_CA7F973BB2E05476.pdfIn PDF document text
- https://crmtristan.talenzsoftware.fr/upload/files/kifivirogosuwuxatoloki.pdfIn PDF document text
- http://polesprogettazioni.com/userfiles/files/kevafefidopuxasetazaw.pdfIn PDF document text
- http://er-trans.com/img/produkty/files/pupadotumogumuvoxok.pdfIn PDF document text
- https://artemishosp-em.tw/uploads/files/202110071429411343.pdfIn PDF document text
- http://www.sunarmisir.com.tr/wp-content/plugins/super-forms/uploads/php/files/681ol7vrfh684hlese0gema901/butezivosadoxidurujudasi.pdfIn PDF document text
- http://heatexchangersolution.com/upload_fck/file/2021-9-3/20210903201645183107.pdfIn PDF document text
- http://tothimi.com/admin/kcfinder/upload/files/53733336340.pdfIn PDF document text
- http://hanauhrova.cz/files/93306247739.pdfIn PDF document text
- https://balletpanov.com/uploads/files/72415465588.pdfIn PDF document text
- http://stefanourso.com/public/userfiles/file/folezujudovisode.pdfIn PDF document text
- http://meuble-tunisie.com/userfiles/file/73762753314.pdfIn PDF document text
- http://xn--rssx31a7tec6p.com/upload/userfiles/files/20211123040245.pdfIn PDF document text
- http://thietbidienmpe.net/upload/files/meroxevegibise.pdfIn PDF document text
- http://automsystem.com/UploadFile/file/20211127100051384.pdfIn PDF document text
- https://lockerova.eu/admin/upload/documents/8631856986.pdfIn PDF document text
- https://purpleleafestatebuyers.com/wp-content/plugins/formcraft/file-upload/server/content/files/1619df1151c1a1---pusiridexuxukelat.pdfIn PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/xap/1.0/rights/In PDF document text
- http://dejavu.sourceforge.netIn PDF document text
- http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text
Extracted artifacts 4
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0004c711.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x4C711 | 16336 bytes |
SHA-256: adf38969d40f501586e0caf93d33991e243baeeecfe575c4831cdbf64b7044fa |
|||
font_01_sfnt_off0004dd13.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x4DD13 | 16560 bytes |
SHA-256: 924ad5cb737cfd9a34472b2046831991df4d3950e5f0d7b552a18309318c2ee9 |
|||
font_02_sfnt_off0004f433.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x4F433 | 10880 bytes |
SHA-256: e6220f1a6db54ce5f591f2593607b40f93533be66c30626fe9bdc7b1e3decd74 |
|||
font_03_sfnt_off00050d2a.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x50D2A | 18708 bytes |
SHA-256: a0f40d57d1ad607defd3d2b78e1986bd087e40c99b743fbb7601bc5ef45ab03a |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.