MALICIOUS
192
Risk Score
Machine Learning
- Nyx PDF Classifier malicious score 1.0000
Heuristics 6
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARMSmall PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
-
Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTONDocument contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://gettraff.ru/123?keyword=reduce+pdf+size+below+200kb+online In PDF document text
- https://dutitujazekap.weebly.com/uploads/1/3/0/8/130814390/kanasazizofowire.pdfIn PDF document text
- https://vilukenuxe.weebly.com/uploads/1/3/2/8/132814007/tikewutoxawip-xeperebe-linejav.pdfIn PDF document text
- https://genamimiwovem.weebly.com/uploads/1/3/1/6/131636881/karagovog.pdfIn PDF document text
- https://wonigebegi.weebly.com/uploads/1/3/1/6/131606731/1154415.pdfIn PDF document text
- https://jawasolasazilem.weebly.com/uploads/1/3/1/3/131379174/d1ee3c84.pdfIn PDF document text
- https://site-1038707.mozfiles.com/files/1038707/mirusasiro.pdfIn PDF document text
- https://site-1038979.mozfiles.com/files/1038979/24048190451.pdfIn PDF document text
- https://site-1040050.mozfiles.com/files/1040050/92596827629.pdfIn PDF document text
- https://site-1036737.mozfiles.com/files/1036737/dorepusituzu.pdfIn PDF document text
- https://site-1042287.mozfiles.com/files/1042287/2589899476.pdfIn PDF document text
- https://site-1037835.mozfiles.com/files/1037835/linobugomafisazikewulex.pdfIn PDF document text
- https://site-1038614.mozfiles.com/files/1038614/82675969271.pdfIn PDF document text
- https://site-1048482.mozfiles.com/files/1048482/5283634096.pdfIn PDF document text
- http://www.ascendercorp.com/In PDF document text
- http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
- https://uploads.strikinglycdn.com/files/30cd7f9b-9fc1-4a09-9589-978b7bf49a74/82369454790.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/9994a96c-ef4a-4d49-bcba-67112de8d3c3/79614335016.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/294d1715-a1b3-4fdf-94b6-0d8b74368e7a/23722045710.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/aa185e62-9b14-4ee6-a832-19e901af593d/doxavuvepuzepojelogubeto.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/cb59ac66-babb-4ef2-ad9c-9d52296a3276/lixisixiv.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/c33df735-996c-4b8c-87d0-39a33ab658c2/josilukapuperagejugofiv.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/0cbfd0d3-ad33-448e-8db8-aa5d8781ad10/12497711564.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/f9571229-e4d1-405f-b64f-d41c7fa0ed94/gakakidinoz.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/5a163495-89c7-4314-b6fe-dd854432c6ca/dererolujonufiposoz.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/3f19be4b-162a-4579-ba0f-b4b1d6b370e2/84758164158.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/ebc3e4d5-2363-4cc1-8fe6-d0bbc8197a8f/fibufisoserisofabawadem.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/2e2be742-b438-4543-914f-8750e6014389/jeverafekuvavumuriwabilu.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/f45bbb5e-4988-4ea9-b3b2-467bacc43f5f/wavixerajifanuse.pdfIn PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/xap/1.0/rights/In PDF document text
- http://scripts.sil.org/OFLIn PDF document text
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00007400.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x7400 | 5472 bytes |
SHA-256: eaac7fdb55a3687ab5a5734859cf95bf09a1d15a3971cacf582d674cb86bf43a |
|||
font_01_sfnt_off000086ce.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x86CE | 10336 bytes |
SHA-256: 0fbc618f8c7132c2ffb6a9a0a131e570f884e085630569c22ea928862e54da21 |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.