MALICIOUS
144
Risk Score
Machine Learning
- Nyx PDF Classifier malicious score 0.6797
Heuristics 6
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
Image lure linking to an SEO redirector (free-download phishing) high PDF_SEO_UTM_REDIRECTOR_LINKPDF embeds an image with little or no body text and a clickable link to a multi-word utm_term / FeedBurner-proxied SEO redirector — the 'free ebook / solution-manual / document download' phishing family that ranks for natural-language search queries and routes the user into a payload/redirect chain. The PDF carries no exploit; the risk is the linked destination. Flagged structurally (image lure + SEO redirector) so it does not depend on a ClamAV/ML signature, and regardless of how many filler text pages the lure carries.
-
Embedded JS stream low PDF_JSPDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://loheb.co.za/XSRYdR1H?utm_term=san+francisco+49ers+injury+report PDF link annotation
- https://rowsontw.com/shopadmin/upload/files/90059853857.pdfIn PDF document text
- https://barrierball.cl/ckfinder/userfiles/files/bajovixu.pdfIn PDF document text
- http://plantessentialoil.com/upload/files/gabonulasebabilaxi.pdfIn PDF document text
- https://immo-macedo.lu/userfiles/files/25939058396.pdfIn PDF document text
- http://enjoy.sk/editor_uploads/system/files/logaletelitoti.pdfIn PDF document text
- http://verduciautodemolizioni.it/userfiles/file/dodoloxu.pdfIn PDF document text
- http://world-spa-resorts.com/dok/72240908821.pdfIn PDF document text
- http://www.moteco.ro/wp-content/plugins/formcraft/file-upload/server/content/files/161988134367e1---97894596749.pdfIn PDF document text
- https://remont-bez-zabot.ru/files/file/48195293800.pdfIn PDF document text
- https://nodka.eu/ckeditor/ckfinder/userfiles/files/33138521097.pdfIn PDF document text
- https://ecoolteh.eu/galeria/file/vivera.pdfIn PDF document text
- http://www.recko.ru/ckfinder/userfiles/files/20401912502.pdfIn PDF document text
- https://www.hotel-palladium.gr/wp-content/plugins/super-forms/uploads/php/files/skm0lab5qqjofp7j9qi42qboas/pilisiseboxuvegizamig.pdfIn PDF document text
- http://geofer.eu/userfiles/files/81599653642.pdfIn PDF document text
- https://vipbeachhouse.com/uploads/editor/file/baloridosefisupigivo.pdfIn PDF document text
- https://aymexco.ro/ckfinder/userfiles/files/pawefuto.pdfIn PDF document text
- http://smsalumni1971.com/apadmin/uploads/userfiles/files/mezozuzuzumamudutovidaxit.pdfIn PDF document text
- http://poiskvod.ru/images/file/22244472245.pdfIn PDF document text
- https://mb-classic-service.de/userfiles/file/99474902299.pdfIn PDF document text
- http://filippodelvita.com/demo/userfiles/file/kuwiziwijodosatuwa.pdfIn PDF document text
- http://www.martiusstaden.org.br/js/ckfinder/userfiles/files/9544379020.pdfIn PDF document text
- https://triatlonshop.cz/userfiles/file/6807884353.pdfIn PDF document text
- https://cafesca.mx/ckfinder/userfiles/files/mapiguremiza.pdfIn PDF document text
- https://safetypadlocks.eu/eurostyl/photos/file/80866677479.pdfIn PDF document text
- http://omorits.jp/uploads/files/zebajebawimelisazez.pdfIn PDF document text
- https://altaitur.com/ckfinder/userfiles/files/sapijadutukesebasazafeza.pdfIn PDF document text
- https://ljlconst.com/admin/images/file/nelixevabobepexuv.pdfIn PDF document text
- https://asset-books.com/userfiles/file/51776828770.pdfIn PDF document text
- https://spcinternational.in/ckfinder/userfiles/files/sipafixerefegulu.pdfIn PDF document text
- http://familiehollander.nl/images/uploadedimages/file/sezexawipukinedozerevop.pdfIn PDF document text
- http://szkolaprzybranowo.pl/ckfinder/userfiles/files/84799570357.pdfIn PDF document text
- http://motolargo.pl/userfiles/file/89014787287.pdfIn PDF document text
- http://www.viksexteriors.com/wp-content/plugins/formcraft/file-upload/server/content/files/16113704c736b0---28756998491.pdfIn PDF document text
- https://wamsconference.com/wp-content/plugins/super-forms/uploads/php/files/8d17170f1ebbc7b0503709fe7dcaec7b/zufibejapokijibujogubipaj.pdfIn PDF document text
- https://samuelben-horin.com/userfiles/file/62368849348.pdfIn PDF document text
- http://xn--80adpfaaeictf0c6c7i.xn--p1ai/public/file/pumadititamiselew.pdfIn PDF document text
- https://regenerativetherapyforpain.com/wp-content/plugins/super-forms/uploads/php/files/cf0043e7bc563761ea154a0867ebdc62/51459056587.pdfIn PDF document text
- http://okmarin.ru/userfiles/file/mugatixokudojoguwowabi.pdfIn PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/xap/1.0/rights/In PDF document text
- http://dejavu.sourceforge.netIn PDF document text
- http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text
Extracted artifacts 3
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00044f65.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x44F65 | 18892 bytes |
SHA-256: 35deba218a2dabfc3bc23ac5b2cd47320efaa6f43d63eb10b01b289423d05d96 |
|||
font_01_sfnt_off00048028.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x48028 | 11092 bytes |
SHA-256: 0432afeec404812f0879a20d310927924e9dd36e2096f508bb4ea9827e565623 |
|||
font_02_sfnt_off00049a39.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x49A39 | 16560 bytes |
SHA-256: 924ad5cb737cfd9a34472b2046831991df4d3950e5f0d7b552a18309318c2ee9 |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.