MALICIOUS
141
Risk Score
Machine Learning
- Nyx PDF Classifier malicious score 0.8318
Heuristics 6
-
Image lure linking to an SEO redirector (free-download phishing) high PDF_SEO_UTM_REDIRECTOR_LINKPDF embeds an image with little or no body text and a clickable link to a multi-word utm_term / FeedBurner-proxied SEO redirector — the 'free ebook / solution-manual / document download' phishing family that ranks for natural-language search queries and routes the user into a payload/redirect chain. The PDF carries no exploit; the risk is the linked destination. Flagged structurally (image lure + SEO redirector) so it does not depend on a ClamAV/ML signature, and regardless of how many filler text pages the lure carries.
-
Travel-support phone-number stuffing scam high SE_TRAVEL_SUPPORT_PHONE_SCAMDocument repeats phone numbers in airline/travel/refund/support language, often across multiple regional phrasings. This matches SEO/support-scam PDFs that impersonate airlines or travel brands and route users to attacker-controlled call centers rather than a normal travel document.
-
PDF advertises pirated movie streaming/download medium PDF_PIRACY_STREAMING_LUREPDF rendered text advertises free full-movie streaming or download using piracy-brand names or a 'full movie + download/free/watch' intent phrase — recovered after folding the styled Unicode confusables the campaign uses to hide those keywords from plain-text detection. These are disposable SEO-spam carriers that route users to malvertising, fake-player, and scam pages; the PDF itself is inert.
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://rofasaxoropop.weebly.com/uploads/1/3/5/3/135316675/8031083.pdf In PDF document text
- https://zeruxukekojumu.weebly.com/uploads/1/3/5/3/135345771/a874e22.pdfIn PDF document text
- https://wobanavemo.weebly.com/uploads/1/3/4/0/134096337/wafokotefexoroj.pdfIn PDF document text
- https://atahca.pt/atahca_gestor/kcfinder/upload/files/likuluk.pdfIn PDF document text
- https://rinadulig.weebly.com/uploads/1/3/0/7/130739308/wugufas.pdfIn PDF document text
- https://tirokaroxere.weebly.com/uploads/1/3/2/7/132740449/c05b2360d4f7d9c.pdfIn PDF document text
- http://mypham.privia.vn/userfiles/file/lududebujel.pdfIn PDF document text
- https://dodafawo.weebly.com/uploads/1/3/4/6/134698388/30ddfe976349.pdfIn PDF document text
- https://xozojijeb.weebly.com/uploads/1/3/4/4/134436315/2f8c529.pdfIn PDF document text
- http://asesoriazabalburu.org/azaba/files/file/49693647790.pdfIn PDF document text
- http://garoli.com.br/js/kcfinder/upload/files/23433366041.pdfIn PDF document text
- http://tscyw.net/userfiles/file/20220318170038_uhd23l.pdfIn PDF document text
- https://kovofogigexu.weebly.com/uploads/1/3/1/8/131856149/reforizaneveboxebug.pdfIn PDF document text
- https://paxudusumumo.weebly.com/uploads/1/3/4/3/134312151/rovopojaw.pdfIn PDF document text
- https://wewilapip.weebly.com/uploads/1/4/2/4/142482770/edbf6f4f.pdfIn PDF document text
- https://mazesuxuraname.weebly.com/uploads/1/3/4/3/134373945/gusakivuxorivasated.pdfIn PDF document text
- http://alpes-de-haute-provence.proximeo.com/ckfinder/userfiles/files/foxaruxejilifo.pdfIn PDF document text
- http://ckudzcssffhhj.handysociality.com/upload/files/49686788109.pdfIn PDF document text
- https://gixorinimomavam.weebly.com/uploads/1/3/2/6/132695995/xedutudagafipu.pdfIn PDF document text
- https://selexezox.weebly.com/uploads/1/4/1/4/141447331/fipab_mekimarafagu_bemonijuna.pdfIn PDF document text
- http://autoscuolapezzano.it/userfiles/files/jinipaxewipeduje.pdfIn PDF document text
- http://xeltuve.com/c3?utm_term=henri+lloyd+t+shirt+size+guidePDF link annotation
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/xap/1.0/rights/In PDF document text
- http://dejavu.sourceforge.netIn extracted file (font_00_sfnt_off0003c070.bin)
- http://dejavu.sourceforge.net/wiki/index.php/LicenseIn extracted file (font_00_sfnt_off0003c070.bin)
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0003c070.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x3C070 | 10628 bytes |
SHA-256: fdd46827d3ab663d82d4a5a1230a0f80bc73a10776ae853a8844318bdb98b7f0 |
|||
font_01_sfnt_off0003d879.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x3D879 | 18300 bytes |
SHA-256: 9aa30b6c23050c48ef3b3bb27cb4b5bf24975661a94958359c89bf5a9672511a |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.