MALICIOUS
194
Risk Score
Machine Learning
- Nyx PDF Classifier malicious score 1.0000
Heuristics 5
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Image lure linking to an SEO redirector (free-download phishing) high PDF_SEO_UTM_REDIRECTOR_LINKPDF embeds an image with little or no body text and a clickable link to a multi-word utm_term / FeedBurner-proxied SEO redirector — the 'free ebook / solution-manual / document download' phishing family that ranks for natural-language search queries and routes the user into a payload/redirect chain. The PDF carries no exploit; the risk is the linked destination. Flagged structurally (image lure + SEO redirector) so it does not depend on a ClamAV/ML signature, and regardless of how many filler text pages the lure carries.
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://ttraff.link/wix?keyword=shop+titans+apk+2.1.3 In PDF document text
- http://sazat.innerworkingsofmymind.com/uploads/1/3/1/4/131408371/8837780.pdfIn PDF document text
- http://pubon.yodha.net/uploads/1/3/1/3/131383744/4241749.pdfIn PDF document text
- http://www.ascendercorp.com/In PDF document text
- http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
- https://cdn.shopify.com/s/files/1/0435/0256/7588/files/explaining_reformed_theology.pdfIn PDF document text
- https://cdn.shopify.com/s/files/1/0431/3828/5725/files/abcd_full_movie_in_tamil_tamilrockers.pdfIn PDF document text
- https://cdn.shopify.com/s/files/1/0483/2614/8249/files/nosirubifakorojud.pdfIn PDF document text
- https://cdn.shopify.com/s/files/1/0428/9835/8432/files/50537202024.pdfIn PDF document text
- https://cdn.shopify.com/s/files/1/0432/5382/5694/files/xitojuligonixal.pdfIn PDF document text
- https://4c670bd4-7679-4485-ac59-3ca8ba948b06.filesusr.com/ugd/b28ae2_6ea4ca632bdd4f679a7cec7249bbc575.pdf?index=trueIn PDF document text
- https://0eaa97bf-c92e-4d6e-9252-cb46ba66e123.filesusr.com/ugd/0d089b_ed78c6e531104700901739d5a85f7a0d.pdf?index=trueIn PDF document text
- https://7de8b191-49e8-443c-abc5-4a0887d50dae.filesusr.com/ugd/2486b5_0a2fec3a5b2c43e99259ec94c2483ef3.pdf?index=trueIn PDF document text
- https://9dfb9fdd-9c80-40f1-8547-df6519849226.filesusr.com/ugd/a2ebd8_df3fe35b51c64096a06e563cbd6b541e.pdf?index=trueIn PDF document text
- https://b13a216a-356f-419d-ab44-b56306ba2d76.filesusr.com/ugd/83b1b3_9684185b17314fb083563f68a66503dd.pdf?index=trueIn PDF document text
- https://7a1c768d-d515-4a5e-80eb-d6724d9fde80.filesusr.com/ugd/b926a8_77ea04e663274c4cbe7368a3d61d3a6d.pdf?index=trueIn PDF document text
- https://24ac7bda-d1f2-434a-80c0-ca21cf728636.filesusr.com/ugd/bba345_e41ea0bfa1cd41558b423488ab78d44b.pdf?index=trueIn PDF document text
- https://fc164591-2b27-47d5-91cc-d1d60d14af9c.filesusr.com/ugd/5be868_6560bd9509fd428596841794a991cba0.pdf?index=trueIn PDF document text
- https://9f65bb56-4d7d-4a40-864c-26c2d77ae95f.filesusr.com/ugd/724fb5_6686dad7d2064790a5955368f614d88d.pdf?index=trueIn PDF document text
- https://394ba002-cfc8-42d9-bbd1-09025bebf855.filesusr.com/ugd/55f640_63dff5e295b1407ca8562d47a7b26d9c.pdf?index=trueIn PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/xap/1.0/rights/In PDF document text
- http://scripts.sil.org/OFLIn PDF document text
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00006497.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x6497 | 5324 bytes |
SHA-256: 0f80e43b2a46ad89fb17ed7d3cf259be52d2323d3f13619b370443eb12bf1fd0 |
|||
font_01_sfnt_off000076bf.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x76BF | 9824 bytes |
SHA-256: 14f84ccb1555d6c4fc9e653147354fc10f4d320b034e21436184bb42d1a4234b |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.