MALICIOUS
159
Risk Score
Machine Learning
- Nyx PDF Classifier clean score 0.0112
Heuristics 6
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
Image lure linking to an SEO redirector (free-download phishing) high PDF_SEO_UTM_REDIRECTOR_LINKPDF embeds an image with little or no body text and a clickable link to a multi-word utm_term / FeedBurner-proxied SEO redirector — the 'free ebook / solution-manual / document download' phishing family that ranks for natural-language search queries and routes the user into a payload/redirect chain. The PDF carries no exploit; the risk is the linked destination. Flagged structurally (image lure + SEO redirector) so it does not depend on a ClamAV/ML signature, and regardless of how many filler text pages the lure carries.
-
PDF link farm points to compromised-WordPress upload storage medium PDF_COMPROMISED_CMS_UPLOAD_LINK_FARMPDF contains multiple clickable links, across many distinct hosts, whose targets are random-slug files parked in the upload directories of vulnerable WordPress form plugins (FormCraft, Super Forms). This is the hallmark of the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains hosted on compromised sites. The PDF itself carries no exploit — the risk is the linked destinations.
-
PDF advertises pirated movie streaming/download medium PDF_PIRACY_STREAMING_LUREPDF rendered text advertises free full-movie streaming or download using piracy-brand names or a 'full movie + download/free/watch' intent phrase — recovered after folding the styled Unicode confusables the campaign uses to hide those keywords from plain-text detection. These are disposable SEO-spam carriers that route users to malvertising, fake-player, and scam pages; the PDF itself is inert.
-
External URI info PDF_URIPDF contains an external URL action
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://loheb.co.za/XSRYdR1H?utm_term=rectangular+coordinates+to+polar+form+calculator PDF link annotation
- http://kfoodntea.com/dataroom/file/54757811663.pdfIn PDF document text
- http://bartuceviri.com/userfiles/file/78359333226.pdfIn PDF document text
- https://www.drukwerkmax.nl/public/admin/assets/global/plugins/kcfinder/upload/files/kuxuzimamonemanafiwupivar.pdfIn PDF document text
- https://eclipsetheaters.com/wp-content/plugins/formcraft/file-upload/server/content/files/16106fd47334cf---xubadawu.pdfIn PDF document text
- http://rainhouse.kr/data/editor/file/112042499561a3b010f3d94.pdfIn PDF document text
- https://crv.dascalita.ro/app/webroot/files/userfiles/files/xupetimubotubiwugimazokil.pdfIn PDF document text
- http://happinessgown.com/upload/users/files/22154788711.pdfIn PDF document text
- https://baoholaodong24.baohohoanglong.com/userfiles/file/pexezedadef.pdfIn PDF document text
- https://rent-1.es/ckfinder/userfiles/files/35287805671.pdfIn PDF document text
- http://www.espace-hotelier.com/ckfinder/userfiles/files/zaxowetilijafiketibubugiw.pdfIn PDF document text
- http://koreadramatour.com/FileData/ckfinder/files/20220215_083EE0F36B1B7968.pdfIn PDF document text
- http://mpu-beratung-brendle.de/userfiles/file/14083870052.pdfIn PDF document text
- https://pfgmm.com.au/wp-content/plugins/formcraft/file-upload/server/content/files/1619d9ad8cfebb---53631544471.pdfIn PDF document text
- http://www.elmundodelapiscina.com/ckfinder/userfiles/files/69995963603.pdfIn PDF document text
- http://xn--2e0b30g3uq7pay7m.com/upload/fckeditor/file/10944164933.pdfIn PDF document text
- http://bancasemecanino.com/userfiles/files/42159630255.pdfIn PDF document text
- http://jdjcnc.com/upfolder/e/files/20210826093031.pdfIn PDF document text
- http://cosyromania.com/media/file/wibobofebafoposove.pdfIn PDF document text
- http://ng-sons.com/userfiles/file/11777286008.pdfIn PDF document text
- http://maaramachandifpo.com/admin/userfiles/file/jebixa.pdfIn PDF document text
- https://epagneuls-bretons.fr/caningest/images/file/41125633309.pdfIn PDF document text
- https://www.pfgpartners.com.au/wp-content/plugins/formcraft/file-upload/server/content/files/1612f0b68e1a9e---maxes.pdfIn PDF document text
- http://www.adarshvidhyasankul.org/userfilesfile/13538145424.pdfIn PDF document text
- https://www.gs-gleichmann.de/wp-content/plugins/formcraft/file-upload/server/content/files/1611d838e0d2bd---39394138898.pdfIn PDF document text
- http://onestep-tokyo.com/userfiles/file/gevegezedoloxovimibo.pdfIn PDF document text
- http://yonetim.e-cari.com/upload/files/18597894112.pdfIn PDF document text
- http://macautemple.com/userfiles/file/14806014745.pdfIn PDF document text
- https://dezsredstvompx.ru/wp-content/plugins/super-forms/uploads/php/files/05c71207e6903122d6c1505f991818f1/5868083263.pdfIn PDF document text
- http://battlegrouponline.com/app/webroot/js/ckfinder/userfiles/files/poxusafog.pdfIn PDF document text
- https://cira.thinkabit.net/downloads/files/gagibubibo.pdfIn PDF document text
- http://raovat.coi.vn/uploads/userfiles/file/83687965149.pdfIn PDF document text
- http://thamdinhgiadaiquang.com/img/files/18521984012.pdfIn PDF document text
- https://abicecream.ru/ckfinder/userfiles/files/banekizuwejetib.pdfIn PDF document text
- https://pristineleather.com/userfiles/file/87690085042.pdfIn PDF document text
- http://rungruangsteel.com/public/upload/userfiles/files/82086450799.pdfIn PDF document text
- https://vibangthuaphatlai.net/uploads/files/fokedeniziwawuzupedoxovi.pdfIn PDF document text
- http://shop-exclusive.cz/userfiles/file/11953354377.pdfIn PDF document text
- https://www.ogblfrontaliers.fr/wp-content/plugins/super-forms/uploads/php/files/mqp6737j031o97he0je6pk0a30/5686761045.pdfIn PDF document text
- http://urbariatprasice.sk/upload/file/sipejunoxe.pdfIn PDF document text
- https://kurek-rowery.pl/user_pict/file/35463658.pdfIn PDF document text
- https://pilot-nav.com/ckfinder/userfiles/files/xubanuzukonapagifivub.pdfIn PDF document text
- http://hoanggiaphatland.com/uploads/image/files/jamukiso.pdfIn PDF document text
- http://e-restauracion.com/app/webroot/files/uploads/files/37832589832.pdfIn PDF document text
- http://nek.ua/wp-content/plugins/formcraft/file-upload/server/content/files/161b7111a64a54---fojof.pdfIn PDF document text
- http://dejavu.sourceforge.netIn extracted file (font_00_sfnt_off0003cff2.bin)
- http://dejavu.sourceforge.net/wiki/index.php/LicenseIn extracted file (font_00_sfnt_off0003cff2.bin)
Extracted artifacts 4
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0003cff2.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x3CFF2 | 16560 bytes |
SHA-256: 924ad5cb737cfd9a34472b2046831991df4d3950e5f0d7b552a18309318c2ee9 |
|||
font_01_sfnt_off0003e712.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x3E712 | 11108 bytes |
SHA-256: 232fd3d0c48165a31658e9aea83f5ddce9ac270f669bfdafaaa891680c54e702 |
|||
font_02_sfnt_off000400c8.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x400C8 | 20344 bytes |
SHA-256: ee31f235366e2a69aaf5ab7c3664c7e90b0d434436801d778f9c8317d87131e4 |
|||
font_03_sfnt_off000436ad.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x436AD | 16220 bytes |
SHA-256: 207eb3b51995adbdef2a766e0364e2c2ee182a7f0f0647c12a4a3807efc046f6 |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.