MALICIOUS
194
Risk Score
Machine Learning
- Nyx PDF Classifier malicious score 0.9998
Heuristics 5
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Image lure linking to an SEO redirector (free-download phishing) high PDF_SEO_UTM_REDIRECTOR_LINKPDF embeds an image with little or no body text and a clickable link to a multi-word utm_term / FeedBurner-proxied SEO redirector — the 'free ebook / solution-manual / document download' phishing family that ranks for natural-language search queries and routes the user into a payload/redirect chain. The PDF carries no exploit; the risk is the linked destination. Flagged structurally (image lure + SEO redirector) so it does not depend on a ClamAV/ML signature, and regardless of how many filler text pages the lure carries.
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://ttraff.club/123?keyword=dork+diaries+puppy+love+pdf In PDF document text
- https://givifajilodox.weebly.com/uploads/1/3/0/8/130874655/de7bd3.pdfIn PDF document text
- https://pigogokeda.weebly.com/uploads/1/3/1/8/131857695/225cc1956.pdfIn PDF document text
- https://jovikuveditowe.weebly.com/uploads/1/3/0/8/130874612/1131ef.pdfIn PDF document text
- https://jovikuveditowe.weebly.com/uploads/1/3/0/8/130874612/6304031.pdfIn PDF document text
- http://www.ascendercorp.com/In PDF document text
- http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
- http://www.daltonmaag.com/In PDF document text
- https://uploads.strikinglycdn.com/files/c8bb6f55-950d-480c-a422-ebcc56321410/niwexomomaruxolovis.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/7c3090ce-e16d-4a66-b8b4-08d453a0a618/89289821030.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/cb75c719-5da4-46a7-b28e-453ecb3c7b02/83224807738.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/891a7e59-3078-4ccc-b8cc-8912422f3f18/52446014888.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/c74ffe6e-77e1-4a99-9032-758225cbaefe/magic_of_incarnum_d.pdfIn PDF document text
- https://cdn.shopify.com/s/files/1/0432/5723/3576/files/xotud.pdfIn PDF document text
- https://cdn.shopify.com/s/files/1/0435/7020/0737/files/lonely_planet_hawaii_travel_guide.pdfIn PDF document text
- https://cdn.shopify.com/s/files/1/0434/7900/7384/files/cloverleaf_elementary_school_houston_tx.pdfIn PDF document text
- https://cdn.shopify.com/s/files/1/0494/4314/3858/files/wijexorodekuwosunetorov.pdfIn PDF document text
- https://cdn.shopify.com/s/files/1/0476/6721/6550/files/wetugonavamitar.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/94f65ace-b0f7-4fe2-a5ec-7abff2384c76/waragoza.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/849e5a57-b320-4977-b44b-498093fc9616/41745760523.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/0fb937ba-b11d-4259-b214-8f43c4c37ad9/24235954997.pdfIn PDF document text
- https://cdn.shopify.com/s/files/1/0431/6001/0912/files/euchre_3d_cheats.pdfIn PDF document text
- https://cdn.shopify.com/s/files/1/0430/4483/1386/files/hikvision_access_control_system.pdfIn PDF document text
- https://cdn.shopify.com/s/files/1/0461/3698/3720/files/the_price_is_right_game.pdfIn PDF document text
- https://cdn.shopify.com/s/files/1/0434/4132/4184/files/farewell_to_manzanar_chapter_22_questions_and_answers.pdfIn PDF document text
- https://cdn.shopify.com/s/files/1/0266/7846/0590/files/release_of_liability_form_florida.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/3eeb46de-3103-4e9c-bf7e-34648bbf5a35/10754540270.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/428e49a2-ef1f-4eef-9b23-41d54e086731/raluxosiguwagesefeze.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/f9e0e2cc-40c9-4939-b328-0d4a9de1c952/nodajemagudaleb.pdfIn PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/xap/1.0/rights/In PDF document text
- http://scripts.sil.org/OFLIn PDF document text
- http://dejavu.sourceforge.netIn PDF document text
- http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text
Extracted artifacts 4
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00007702.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x7702 | 4956 bytes |
SHA-256: 39d4d68b532d38aba442c1c5a10a8ebf5a228d3f5f72e35974e5a9ea8cc28fd8 |
|||
font_01_sfnt_off00008805.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x8805 | 10612 bytes |
SHA-256: 48bdd90fb71c8b650845f544c308dcd24ed57acb9c2d6c144f52a5a77fcbca1e |
|||
font_02_sfnt_off0000ac58.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xAC58 | 16328 bytes |
SHA-256: 0ad95216fc52ead1ee8e1b875c7e0507e88213f6ce6a5e96007740e231e172aa |
|||
font_03_sfnt_off0000c1e6.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xC1E6 | 4324 bytes |
SHA-256: 05d2457133b820fa77aa358e30e9acfbad3f04c46ced9a37296d9311117db176 |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.