MALICIOUS
74
Risk Score
Machine Learning
- Nyx PDF Classifier malicious score 1.0000
Heuristics 5
-
Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARMSmall PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
-
Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTONDocument contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://trafficel.ru/123?keyword=flex+1500+microphone PDF link annotation
- https://vefawotujetebab.weebly.com/uploads/1/3/4/6/134651081/7de464fc5c62.pdfIn PDF document text
- https://porelananov.weebly.com/uploads/1/3/0/7/130775759/telimuluzapetubidemu.pdfIn PDF document text
- http://www.ascendercorp.com/In PDF document text
- http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
- https://silisejez.files.wordpress.com/2020/11/schaum_s_signals_and_systems.pdfIn PDF document text
- https://pupirod.files.wordpress.com/2020/11/sagob.pdfIn PDF document text
- https://tumitom.files.wordpress.com/2020/11/13483598324.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/628d8632-7e9b-4835-840b-93fa7b472202/unwashed_eggs_stored_in_lime_water.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/cf2fe8ec-e2df-4924-8a8a-39ac45ccee80/94686660873.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/b1bc73b1-ef41-4c4a-875e-8041e2f9fbfd/82504770938.pdfIn PDF document text
- https://sazaxasegu.files.wordpress.com/2020/11/26344682303.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/fe05c440-a977-473b-947f-5b72ddc94c11/transformers_list_of_autobots_and_de.pdfIn PDF document text
- https://pafegum.files.wordpress.com/2020/11/xumakosokidazok.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/d3a38ac9-2ccd-42ec-99f4-b28a325a4936/96865381351.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/99fe7203-21d5-4760-85a6-835f38093800/secret_garden_inky_treasure_hunt_book.pdfIn PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/xap/1.0/rights/In PDF document text
- http://scripts.sil.org/OFLIn PDF document text
Extracted artifacts 3
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00008260.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x8260 | 3172 bytes |
SHA-256: 8bd715cf427e47a5acbb982debb11dca05fc35fb232e548dc3899cb3c4ab199d |
|||
font_01_sfnt_off00008dc5.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x8DC5 | 5128 bytes |
SHA-256: 759f3f2950534f0ecd28054931a1ed5c6423d3ef2fcad025fa3060d519abec5e |
|||
font_02_sfnt_off00009f1e.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x9F1E | 11432 bytes |
SHA-256: c060c5bf310e14747d088e0a569bf4551518af6e0b956e72a4e18b56b970d3e1 |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.