MALICIOUS
184
Risk Score
Machine Learning
- Nyx PDF Classifier malicious score 1.0000
Heuristics 5
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARMSmall PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://ttraff.cc/pify?keyword=cantoral+catolico+partituras In PDF document text
- http://files.nkphillipscpa.com/uploads/1/3/1/1/131164125/rebewodale.pdfIn PDF document text
- http://suzekep.lomondlogs.co.uk/uploads/1/3/2/6/132681647/f55163ee.pdfIn PDF document text
- http://luzegovo.mindfulnesscenteronline.com/uploads/1/3/1/0/131070867/4744133.pdfIn PDF document text
- http://penokano.jcweber.com/uploads/1/3/1/4/131408899/599f228ab6.pdfIn PDF document text
- http://sujoze.monacof1grandprix.com/uploads/1/3/0/8/130874601/8199955.pdfIn PDF document text
- http://www.ascendercorp.com/In PDF document text
- http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
- https://e19b66ad-7368-499d-8af5-b4c2cce9b360.filesusr.com/ugd/22bf55_5f39bc11bb9847b7a1e32c8b2367382b.pdf?index=trueIn PDF document text
- https://5a2c6d0e-cc13-4319-b171-b05fc45c007d.filesusr.com/ugd/12daa7_24454ebf0e4242a3ae5a131c4a067352.pdf?index=trueIn PDF document text
- https://c2c1b339-b4f8-43a0-83bb-06f09142fa97.filesusr.com/ugd/bc4951_45654a7f6e5843ca8efe7cbbd616893d.pdf?index=trueIn PDF document text
- https://0e26175e-70c9-4ea5-9f32-64e9f77fafd5.filesusr.com/ugd/3be48b_963d7ad2d4934ec38f647bed5e83a49f.pdf?index=trueIn PDF document text
- https://eb0eb594-ce16-4687-8758-c89f0408d7d1.filesusr.com/ugd/bb4607_0e8ab6f50b23422badc21d81ff1ac9b9.pdf?index=trueIn PDF document text
- https://2aa27abd-37cb-4a0a-b811-be903139d3fd.filesusr.com/ugd/90d19e_bdbd68e9fba148c7b727a6b6874f84b7.pdf?index=trueIn PDF document text
- https://8b6c1379-8d8d-4216-8f8b-7d65bc6c6122.filesusr.com/ugd/bcfc12_2fe567db65d7429bbbb54d9d6f53762a.pdf?index=trueIn PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/xap/1.0/rights/In PDF document text
- http://scripts.sil.org/OFLIn PDF document text
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000810d.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x810D | 4832 bytes |
SHA-256: 671afc8ae570337430130ece2543b88411912959729727e7160a8a600e6c8fc6 |
|||
font_01_sfnt_off0000917f.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x917F | 15404 bytes |
SHA-256: 37633bde175d2a2a6e597404aa04ed77bcf71a31f203a37020c521114f1eda1f |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.