MALICIOUS
134
Risk Score
Machine Learning
- Nyx PDF Classifier suspicious score 0.3432
Heuristics 5
-
ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
-
Image lure linking to an SEO redirector (free-download phishing) high PDF_SEO_UTM_REDIRECTOR_LINKPDF embeds an image with little or no body text and a clickable link to a multi-word utm_term / FeedBurner-proxied SEO redirector — the 'free ebook / solution-manual / document download' phishing family that ranks for natural-language search queries and routes the user into a payload/redirect chain. The PDF carries no exploit; the risk is the linked destination. Flagged structurally (image lure + SEO redirector) so it does not depend on a ClamAV/ML signature, and regardless of how many filler text pages the lure carries.
-
PDF link farm points to compromised-WordPress upload storage medium PDF_COMPROMISED_CMS_UPLOAD_LINK_FARMPDF contains multiple clickable links, across many distinct hosts, whose targets are random-slug files parked in the upload directories of vulnerable WordPress form plugins (FormCraft, Super Forms). This is the hallmark of the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains hosted on compromised sites. The PDF itself carries no exploit — the risk is the linked destinations.
-
External URI info PDF_URIPDF contains an external URL action
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://norin.co.za/XSRYdR1H?utm_term=vision+de+la+empresa+coca+cola PDF link annotation
- http://www.psstrecno.sk/wp-content/plugins/formcraft/file-upload/server/content/files/1623a6329e5af5---mavesubigudegin.pdfIn PDF document text
- https://kupujusurigov.weebly.com/uploads/1/3/4/4/134471221/lirejuper.pdfIn PDF document text
- https://petabururumeje.weebly.com/uploads/1/3/4/9/134902787/balirifulizef.pdfIn PDF document text
- https://dafepigog.weebly.com/uploads/1/3/4/6/134605944/9ff8bf6e6b8.pdfIn PDF document text
- http://www.ccengis.be/applications/ckeditor/addons/ckeditor/ckfinder/userfiles/files/22159460558.pdfIn PDF document text
- https://foluxodemebomo.weebly.com/uploads/1/3/0/7/130739593/tazujulotokeradok.pdfIn PDF document text
- http://hmed.vn/upload/files/2407555581.pdfIn PDF document text
- https://pchome.uzai.ca/upload/files/soribokajifamami.pdfIn PDF document text
- http://sp3siemianowice.pl/userFiles/files/zabagi.pdfIn PDF document text
- https://simpangkanan.com/contents/files/xolozetetujotabo.pdfIn PDF document text
- https://vozedebilonede.weebly.com/uploads/1/3/5/3/135333302/3379529.pdfIn PDF document text
- https://pakimisubimoge.weebly.com/uploads/1/3/0/7/130776027/niromekopowu-zemewitogov-junisalexi.pdfIn PDF document text
- http://avandcie-energy.com/ckfinder/userfiles/files/77651269990.pdfIn PDF document text
- https://rixuxakixolewe.weebly.com/uploads/1/3/1/3/131380342/3859c1ce.pdfIn PDF document text
- http://stavebniny-pyramida.cz/admin/upload/files/74206923007.pdfIn PDF document text
- http://e-pisanie-prac.pl/famprojekt_z_serwera/images/file/natapuzanigomulapuvakoral.pdfIn PDF document text
- http://mobitransjogja.com/files/74128307070.pdfIn PDF document text
- http://www.saveurspoitoucharentes.com/admin/ckfinder/userfiles/files/fonazitubofufu.pdfIn PDF document text
- http://bodamvientin.com/uploads/userfiles/file/jugilubaw.pdfIn PDF document text
- http://asirius.su/wp-content/plugins/super-forms/uploads/php/files/149dd4dbf5d8f5e51ca08983b6567606/juvuvikogidojanetenovana.pdfIn PDF document text
- https://intrastorg.com/userfiles/file/turitofaxakapupo.pdfIn PDF document text
- http://test.uebersetzungen-nesselberger.de/wp-content/plugins/formcraft/file-upload/server/content/files/16224d79fee525---tebeviruxenufalokakib.pdfIn PDF document text
- https://lederstuhl-shop.de/ckfinder/userfiles/files/11952016667.pdfIn PDF document text
- https://hoppe.dk/files/guzovefafabejewez.pdfIn PDF document text
- https://fojaruzagix.weebly.com/uploads/1/3/1/3/131379198/44a3ff23b013c5.pdfIn PDF document text
- https://jajoteraluwem.weebly.com/uploads/1/3/4/1/134108878/4339602.pdfIn PDF document text
- http://www.civilhospitalpalampur.in/img/uploads/files/ziniwaxoles.pdfIn PDF document text
- https://crmtristan.talenzsoftware.fr/upload/files/nebimifasagubu.pdfIn PDF document text
- http://lotyzapoznawcze.pl/cms/files/tiripewivimugifawazib.pdfIn PDF document text
Open this report in the interactive analyzer, or submit your own file for analysis.