MALICIOUS
184
Risk Score
Machine Learning
- Nyx PDF Classifier malicious score 0.9997
Heuristics 5
-
ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARMSmall PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://crophysi.ru/award?keyword=kenmore+700+washer+repair+manual In PDF document text
- https://cdn-cms.f-static.net/uploads/4460680/normal_6033b17b3db88.pdfIn PDF document text
- http://dabopoxele.getenjoyment.net/calligraphy_classes_fees.pdfIn PDF document text
- http://rasazajafatirek.mypressonline.com/75365079743.pdfIn PDF document text
- https://static.s123-cdn-static.com/uploads/4408995/normal_5feeb83644157.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4499972/normal_6014d03a7b7e9.pdfIn PDF document text
- https://static.s123-cdn-static.com/uploads/4474449/normal_5fceb1b446fe2.pdfIn PDF document text
- https://tivepikilusu.weebly.com/uploads/1/3/4/7/134759048/60b9091.pdfIn PDF document text
- http://galufixagomedo.getenjoyment.net/dusagusopaturu.pdfIn PDF document text
- https://jafobepajimo.weebly.com/uploads/1/3/4/8/134881918/voteduno-zenapejakokexa.pdfIn PDF document text
- http://www.ascendercorp.com/In PDF document text
- http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
- http://gujusul.epizy.com/how_to_do_carb_cycling_v_shred.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/dd7defe0-6584-4a32-b0bb-7ab022301af7/how_to_install_honeywell_rth9585wf1004_u.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/f436ca1c-e623-4e8c-b380-e6187cfb3c39/gexijipidisedak.pdfIn PDF document text
- https://ef2e072a-e8a2-4438-804d-cc750be2e2f6.filesusr.com/ugd/6a22cb_71c8593af2894b219b9b14b55a1a3ec9.pdf?index=trueIn PDF document text
- https://0c2a99dd-71fd-4a0d-b96f-672cfa785c21.filesusr.com/ugd/515c54_99deafff76854009b45e658261633c38.pdf?index=trueIn PDF document text
- https://e0ff2378-281a-4ea3-95ae-419c526fdc99.filesusr.com/ugd/0baf77_1a933d342a0b4a3fae7ba73707db03e2.pdf?index=trueIn PDF document text
- https://c2bc7a71-cb21-434c-84f6-8d2fc09ed56d.filesusr.com/ugd/03ae60_dc12a3c2c409445dabf5825c79730765.pdf?index=trueIn PDF document text
- https://f77c8dad-41d7-4a8f-8d8d-c05149a3a236.filesusr.com/ugd/36d413_ea6342634e754921aec87d37d866731e.pdf?index=trueIn PDF document text
- http://petefuzaz.epizy.com/what_is_a_kenworth_t800.pdfIn PDF document text
- http://kikukuvikato.myartsonline.com/webafirotarepeni.pdfIn PDF document text
- http://wekazuvenasiwuf.epizy.com/agricultural_research_policy_kenya.pdfIn PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/xap/1.0/rights/In PDF document text
- http://scripts.sil.org/OFLIn PDF document text
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000dfda.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xDFDA | 5344 bytes |
SHA-256: 37c40c5269b1cca7100897613735914afd180de1da523d7cdd3e87825bc17857 |
|||
font_01_sfnt_off0000f1f4.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xF1F4 | 10688 bytes |
SHA-256: f897c9fb2640a93e42e0e787e6575da8613425e3ceb1f72693113ab332ef2d6c |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.