MALICIOUS
156
Risk Score
Machine Learning
- Nyx PDF Classifier malicious score 0.9996
Heuristics 5
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://vilenefex.ru/123?utm_term=baby+pic+wallpaper
- https://rosajojuzexoked.weebly.com/uploads/1/3/0/8/130874599/2907455.pdf
- https://ralutadepijug.weebly.com/uploads/1/3/5/3/135305627/larunes.pdf
- https://zopiwaseka.weebly.com/uploads/1/3/0/9/130969839/fegobepulodademowat.pdf
- https://figinuvoniz.weebly.com/uploads/1/3/4/6/134654755/3680530.pdf
- https://jozudepixivi.weebly.com/uploads/1/3/4/6/134682498/muzuzifosejedusavixa.pdf
- https://wilexezixokesu.weebly.com/uploads/1/3/4/7/134764798/7669188.pdf
- https://pogedefulelot.weebly.com/uploads/1/3/4/6/134628496/6644081.pdf
- https://xowemaxixedire.weebly.com/uploads/1/3/5/3/135325030/7372217.pdf
- https://zokelafeg.weebly.com/uploads/1/3/4/8/134889419/6571009.pdf
- https://kefavevanafas.weebly.com/uploads/1/3/4/6/134633526/kazisevelabori.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- http://www.daltonmaag.com/
- https://uploads.strikinglycdn.com/files/b3cada45-cf4e-48b7-9f5c-fc2fb0a14083/7860701617.pdf
- https://uploads.strikinglycdn.com/files/f8263f92-fde7-4b7b-a79d-263cf739820a/49895346559.pdf
- https://uploads.strikinglycdn.com/files/fc49ee71-b2e6-49fb-8a25-b11954977c1f/modelo_atomico_de_bohr_cloro.pdf
- https://uploads.strikinglycdn.com/files/4c6386ed-5bd7-43fb-9e13-d05e8c048d68/73163535564.pdf
- https://uploads.strikinglycdn.com/files/c332913d-87f6-4978-9c70-fb509f3f3e10/zagg_folio_backlit_keyboard_case_for_ipad_mini_5.pdf
- https://uploads.strikinglycdn.com/files/56fc8f4d-0b18-4ed4-9d86-aa9c0d612e2f/xogukekexiboxafamoki.pdf
- https://uploads.strikinglycdn.com/files/89c0e965-468c-4830-917b-73162f406aa6/big_green_egg_vertical_turkey_roaster.pdf
- https://uploads.strikinglycdn.com/files/a6976271-fbee-4c26-a1a7-4b0860a65b63/how_to_connect_turtle_beach_420x_to_xbox_one.pdf
- https://uploads.strikinglycdn.com/files/af675304-11b9-49b9-9678-d49878a56bd5/84018167915.pdf
- https://uploads.strikinglycdn.com/files/cb4f0cf9-9e20-4643-b7d3-d5e16f6760b6/wapanagosabo.pdf
- https://uploads.strikinglycdn.com/files/7d1038b9-107b-4879-9a78-a5add32a61ab/zapajovixebevoxedadigejov.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 3
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000efe3.bin2d39742f5d5de29b9342fdd90501c7216d9d935587b0f6bd95a9ae16287313f9 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xEFE3 | 4624 bytes |
font_01_sfnt_off0000ffaa.bin79b86c325a805969ae7cf68a871dba7a70540ac863010f563b1371a6082f4767 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xFFAA | 10052 bytes |
font_02_sfnt_off0001214f.bin0d0f64e27578eb124b8bc81c7eceacdd166e22eddd95c81328e9fbd7de2a6333 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x1214F | 4324 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.