MALICIOUS
166
Risk Score
Machine Learning
- Nyx PDF Classifier malicious score 0.5735
Heuristics 6
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
Image lure linking to an SEO redirector (free-download phishing) high PDF_SEO_UTM_REDIRECTOR_LINKPDF embeds an image with little or no body text and a clickable link to a multi-word utm_term / FeedBurner-proxied SEO redirector — the 'free ebook / solution-manual / document download' phishing family that ranks for natural-language search queries and routes the user into a payload/redirect chain. The PDF carries no exploit; the risk is the linked destination. Flagged structurally (image lure + SEO redirector) so it does not depend on a ClamAV/ML signature, and regardless of how many filler text pages the lure carries.
-
PDF link farm points to compromised-WordPress upload storage medium PDF_COMPROMISED_CMS_UPLOAD_LINK_FARMPDF contains multiple clickable links, across many distinct hosts, whose targets are random-slug files parked in the upload directories of vulnerable WordPress form plugins (FormCraft, Super Forms). This is the hallmark of the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains hosted on compromised sites. The PDF itself carries no exploit — the risk is the linked destinations.
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://vasekupony.sk/jsc/kcfinder/upload/files/gevezolegibipoleboja.pdf In PDF document text
- http://catmo.fr/kcfinder/upload/files/tepaxijerufanib.pdfIn PDF document text
- http://jts-electrical.co.uk/ckfinder/userfiles/files/difevofugedojisa.pdfIn PDF document text
- http://akbmodel.com/wp-content/plugins/formcraft/file-upload/server/content/files/1621c9111dc68a---93104578995.pdfIn PDF document text
- https://starfoil-mail.nl/uploads/wysiwyg/4782411172.pdfIn PDF document text
- http://skmsm.com/userData/board/file/ralikagexiveginepivitejix.pdfIn PDF document text
- https://funstore.dialog.org/userfiles/file/kufuwelolozuxiruwisenifag.pdfIn PDF document text
- https://divinehm.com/ckeditor/kcfinder/upload/files/xafujozupinef.pdfIn PDF document text
- https://lp-tracking.com/userfiles/file/22530129261.pdfIn PDF document text
- http://vswet.ru/f/20738832037.pdfIn PDF document text
- http://belly.bpv.su/content/files/files/sigajijetogikugetuv.pdfIn PDF document text
- http://richmore.kr/uploadfile/fckeditor/file/72776011460.pdfIn PDF document text
- http://xtra360.net/campannas/file/lumudapigenekenibadiwadu.pdfIn PDF document text
- https://orangevelodrometrail.fr/img/uploads/files/89773158847.pdfIn PDF document text
- https://cfacgroup.com/uploads/FCK_files/file/mupapojavekafixok.pdfIn PDF document text
- http://www.stadion-zarya.ru/ckfinder/userfiles/files/pirupele.pdfIn PDF document text
- https://fermuar.com/wp-content/plugins/formcraft/file-upload/server/content/files/16210a535479a6---pavekule.pdfIn PDF document text
- http://joshuadacosta.com/wp-content/plugins/formcraft/file-upload/server/content/files/1621da541718a8---naterarefatu.pdfIn PDF document text
- http://formasrl.com/admin/kcfinder/upload/files/nojafuw.pdfIn PDF document text
- http://nek.ua/wp-content/plugins/formcraft/file-upload/server/content/files/16213ed7042b15---zogomevonunorip.pdfIn PDF document text
- http://exekuce-majetku.cz/kcfinder/upload/files/31304229058.pdfIn PDF document text
- http://abogadosaguilar.com/ckfinder/userfiles/files/lokizogesuxofepixi.pdfIn PDF document text
- http://chernogolovka.inhome360.ru/admin/ckfinder/userfiles/files/zadupizugotijuzete.pdfIn PDF document text
- http://www.nisbd.com/wp-content/plugins/formcraft/file-upload/server/content/files/161f9fa15f02e5---93362314119.pdfIn PDF document text
- http://22vek-omsk.ru/fck_editor_files/files/mimojege.pdfIn PDF document text
- http://bizwd.com/wp-content/plugins/formcraft/file-upload/server/content/files/162099d8198cc1---38370398257.pdfIn PDF document text
- http://www.finanzanlagen-honorarberatung.de/wp-content/plugins/formcraft/file-upload/server/content/files/16216ed02dec62---65657193711.pdfIn PDF document text
- https://vida.posilatko.cz/files/wswg/files/84930029048.pdfIn PDF document text
- https://www.nrsa.tj/nrsa_system/ckeditor/kcfinder/upload/files/81487968035.pdfIn PDF document text
- http://fcms.nl/KCFinder/upload/files/zumemativuxaludusoredini.pdfIn PDF document text
- https://gift-edu.ru/wp-content/plugins/super-forms/uploads/php/files/671754b2c6cde3ffd7507b83c05b905b/88485302978.pdfIn PDF document text
- http://mitrasejati.co.id/assets/kcfinder/upload/files/5534758922.pdfIn PDF document text
- https://educhina.mn/editor/files/fowanelexepe.pdfIn PDF document text
- https://tndvn.com/js/ckfinder/userfiles/files/wamifexopavajikur.pdfIn PDF document text
- http://atem.sciara.eu/public/upload/file/xonirulosudekenapup.pdfIn PDF document text
- http://xn----7sbqwxdbhblh2h.xn--p1ai/data/file/gevozafagakigef.pdfIn PDF document text
- http://stnicholasway.com/userfiles/file/vowupukasiteze.pdfIn PDF document text
- https://henseltech.cz/userfiles/file/21327832057.pdfIn PDF document text
- https://inflexi.com/kcfinder/upload/files/17135711436.pdfIn PDF document text
- http://jd6618.com/jd6618/file/2022-2/file/LwpCms2022_02_16_10_57_15_6685.pdfIn PDF document text
- https://finestblogger.de/wp-content/plugins/super-forms/uploads/php/files/1gvoi59j39m064ffmm88ijj5qs/pejijevilesupumowudi.pdfIn PDF document text
- http://educaholistica.com/resources/img/imagesck/files/fuwuwajubobu.pdfIn PDF document text
- http://apart1day.ru/file/bowoperevararatodopiroso.pdfIn PDF document text
- http://ppic.pl/www/js/kcfinder/upload/files/ganesawa.pdfIn PDF document text
- http://020tzs.com/baige/images/userfiles/file/94601595787.pdfIn PDF document text
- http://accurateverdicts.com/wp-content/plugins/formcraft/file-upload/server/content/files/161fffeb392266---fogimigimunejivovugapede.pdfIn PDF document text
- http://lafedja.cz/public/file/teputuxibu.pdfIn PDF document text
- http://supragyn.cz/userfiles/file/58453500450.pdfIn PDF document text
- https://forkidsvietnam.vn/wp-content/plugins/super-forms/uploads/php/files/tkcutr5be27ldiqc334f14mu3u/mixenulan.pdfIn PDF document text
- https://www.ozkozel.sk/kcfinder/upload/files/5488347439.pdfIn PDF document text
+12 more URL(s)
Extracted artifacts 3
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00034a00.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x34A00 | 17724 bytes |
SHA-256: f3e0837791d27575272ba6ac0ad20f2fcd7f032723f3aca2a4a7a6e7d4874ba5 |
|||
font_01_sfnt_off000378ac.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x378AC | 11268 bytes |
SHA-256: 547d26248ee38a083dde6b63e68054192278b149921f97be3e96bd753b8ed946 |
|||
font_02_sfnt_off00039363.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x39363 | 16560 bytes |
SHA-256: 924ad5cb737cfd9a34472b2046831991df4d3950e5f0d7b552a18309318c2ee9 |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.