MALICIOUS
194
Risk Score
Machine Learning
- Nyx PDF Classifier malicious score 1.0000
Heuristics 5
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Image lure linking to an SEO redirector (free-download phishing) high PDF_SEO_UTM_REDIRECTOR_LINKPDF embeds an image with little or no body text and a clickable link to a multi-word utm_term / FeedBurner-proxied SEO redirector — the 'free ebook / solution-manual / document download' phishing family that ranks for natural-language search queries and routes the user into a payload/redirect chain. The PDF carries no exploit; the risk is the linked destination. Flagged structurally (image lure + SEO redirector) so it does not depend on a ClamAV/ML signature, and regardless of how many filler text pages the lure carries.
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://cctraff.ru/pify?keyword=turn+on+autocomplete+android In PDF document text
- https://site-1041499.mozfiles.com/files/1041499/sefegubikogezabib.pdfIn PDF document text
- https://site-1036628.mozfiles.com/files/1036628/57518828101.pdfIn PDF document text
- https://besavikeneg.weebly.com/uploads/1/3/2/8/132815808/21e75.pdfIn PDF document text
- https://jakedekokobara.weebly.com/uploads/1/3/1/3/131381480/divili_dapixi.pdfIn PDF document text
- https://viweposedijul.weebly.com/uploads/1/3/1/0/131070314/9376504.pdfIn PDF document text
- http://www.ascendercorp.com/In PDF document text
- http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
- https://uploads.strikinglycdn.com/files/ca53eae0-c501-4f3e-9147-ac760b5e8c1e/fevetidetapalodipivof.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/5a85263c-8ee1-4b10-a2c5-68915075a771/2947149201.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/601ae2c2-7a5e-4a88-8eb2-f5f903597169/76379456763.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/376ae905-3d4b-485a-92cb-de0ed296c03e/51288605981.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/0ea12e61-c383-4cee-84ca-312d4391ff67/71305056902.pdfIn PDF document text
- https://cdn.shopify.com/s/files/1/0438/4774/5698/files/kuxizuwomaramenizeru.pdfIn PDF document text
- https://cdn.shopify.com/s/files/1/0483/5799/8743/files/taguwuwoletojekewez.pdfIn PDF document text
- https://cdn.shopify.com/s/files/1/0266/9563/1043/files/lastiseal_brick__concrete_sealer.pdfIn PDF document text
- https://cdn.shopify.com/s/files/1/0434/5816/6949/files/61801619398.pdfIn PDF document text
- https://cdn.shopify.com/s/files/1/0439/0020/7272/files/ooze_dab_pen_charger.pdfIn PDF document text
- https://cdn.shopify.com/s/files/1/0437/9879/0301/files/10849842157.pdfIn PDF document text
- https://cdn.shopify.com/s/files/1/0430/6377/1293/files/15515662694.pdfIn PDF document text
- https://cdn.shopify.com/s/files/1/0499/2722/5506/files/lost_ca_drivers_license.pdfIn PDF document text
- https://cdn.shopify.com/s/files/1/0476/5171/7286/files/holt_french_2_answers.pdfIn PDF document text
- https://cdn.shopify.com/s/files/1/0482/3836/2786/files/mi_casa_furniture_los_angeles.pdfIn PDF document text
- https://cdn.shopify.com/s/files/1/0431/8789/6480/files/mugen_megamix_black_edition_free_download.pdfIn PDF document text
- https://cdn.shopify.com/s/files/1/0432/9118/1214/files/ap_statistics_chapter_5b_test_answer_key.pdfIn PDF document text
- https://cdn.shopify.com/s/files/1/0500/3611/3571/files/boss_therm_brtrf_user_manual.pdfIn PDF document text
- https://cdn.shopify.com/s/files/1/0481/4598/9783/files/principles_of_accounting_11th_edition_solution_manual.pdfIn PDF document text
- https://cdn.shopify.com/s/files/1/0482/8010/9218/files/the_hangar_long_beach_california.pdfIn PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/xap/1.0/rights/In PDF document text
- http://scripts.sil.org/OFLIn PDF document text
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00007184.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x7184 | 4988 bytes |
SHA-256: f5dd2233df4722dd2dcea277870129b60ad78cc1c406034f68d8b0b2f0ec5932 |
|||
font_01_sfnt_off0000825f.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x825F | 10416 bytes |
SHA-256: f4416358fd8c6d3b8dde3572b657d6f1e76cce4ecb7b7f995aea5503efa6b0b7 |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.