MALICIOUS
136
Risk Score
Machine Learning
- Nyx PDF Classifier suspicious score 0.3879
Heuristics 6
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
Image lure linking to an SEO redirector (free-download phishing) high PDF_SEO_UTM_REDIRECTOR_LINKPDF embeds an image with little or no body text and a clickable link to a multi-word utm_term / FeedBurner-proxied SEO redirector — the 'free ebook / solution-manual / document download' phishing family that ranks for natural-language search queries and routes the user into a payload/redirect chain. The PDF carries no exploit; the risk is the linked destination. Flagged structurally (image lure + SEO redirector) so it does not depend on a ClamAV/ML signature, and regardless of how many filler text pages the lure carries.
-
PDF link farm points to compromised-WordPress upload storage medium PDF_COMPROMISED_CMS_UPLOAD_LINK_FARMPDF contains multiple clickable links, across many distinct hosts, whose targets are random-slug files parked in the upload directories of vulnerable WordPress form plugins (FormCraft, Super Forms). This is the hallmark of the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains hosted on compromised sites. The PDF itself carries no exploit — the risk is the linked destinations.
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://sunuf.co.za/XSRYdR1H?utm_term=dr+house+capitulos+completos+en+espa PDF link annotation
- http://vetusmeter.com/images/upload/File/6774644839.pdfIn PDF document text
- http://oisvier.nl/UserFiles/files/13098353803.pdfIn PDF document text
- http://etepi.pt/js/ckfinder/userfiles/files/4935610747.pdfIn PDF document text
- http://bhartiyambeohari.in/userfiles/file/lejevijexivapexisikujifit.pdfIn PDF document text
- https://www.caposalasicilia.com/admin/ckeditor/kcfinder/upload/files/22472400419.pdfIn PDF document text
- https://paperland.bg/uploads/file/bokezodogotij.pdfIn PDF document text
- http://heilpraxis-pankow.de/wp-content/plugins/formcraft/file-upload/server/content/files/1623a527d59d2d---32561925990.pdfIn PDF document text
- https://raghuvirtrading.com/userfiles/file/27714895669.pdfIn PDF document text
- https://mikepromedia.com/wp-content/plugins/super-forms/uploads/php/files/2a12153448950f4bd0d63323f99d8796/55681541749.pdfIn PDF document text
- https://corpusbg.com/files/fck/file/wekulaf.pdfIn PDF document text
- https://eliska.grenoo.sk/uploads/file/fapitavivizoxitomasep.pdfIn PDF document text
- http://reklama-opole.pl/userfiles/file/kemuwir.pdfIn PDF document text
- https://yarsan.ru/wp-content/plugins/super-forms/uploads/php/files/d3b71eedb950a54eac30ef9a46d26d8b/lutuwakolidebunigupero.pdfIn PDF document text
- http://www.transfuzia.org/gfx/administration/js/ckeditor/kcfinder/upload/files/sofamajizora.pdfIn PDF document text
- https://www.unecol.com/uploads/kcfinder/upload/files/18300560314.pdfIn PDF document text
- https://www.enviedecrire.com/wp-content/plugins/formcraft/file-upload/server/content/files/1621ef7096f497---76698330201.pdfIn PDF document text
- http://www.saaegfpolis.org.br/ckfinder/userfiles/files/lebaroti.pdfIn PDF document text
- http://www.lbf-cosmetics.com/website/wp-content/plugins/formcraft/file-upload/server/content/files/161fdd18cd5aca---tarokewokapome.pdfIn PDF document text
- https://armour-technoz-ca.otzol.net/ckfinder/userfiles/files/337068399.pdfIn PDF document text
- http://afksport.cz/upload/files/22871168576.pdfIn PDF document text
- http://raduzhniy.com/wp-content/plugins/formcraft/file-upload/server/content/files/1622827b60e055---ronabozawiro.pdfIn PDF document text
- http://conepe.org.br/public/ckeditor/kcfinder/upload/files/nakeniwozosamug.pdfIn PDF document text
- http://bestbelly.org/content/files/files/48287512554.pdfIn PDF document text
- http://xn--90ae5b.xn--p1ai/uld/files/vovimu.pdfIn PDF document text
- http://architettoseneca.com/userfiles/files/wugazemiwotajikovovapuxuf.pdfIn PDF document text
- https://jbdclothiers.net/emailer/userfiles/file/2803460151.pdfIn PDF document text
- http://rdmsrl.it/userfiles/files/74703586227.pdfIn PDF document text
- http://www.dereformasenalicante.com/archivos/files/vumozamumofekowewad.pdfIn PDF document text
- http://2safe4u.cz/UserFiles/File/patos.pdfIn PDF document text
- https://www.q-jin.ne.jp/ckfinder/userfiles/files/volubeboduditan.pdfIn PDF document text
- http://www.veedik.net/assets/admin/kcfinder/upload/files/40137548553.pdfIn PDF document text
- https://educhina.mn/editor/files/xidelijavewi.pdfIn PDF document text
- https://twinslock.com/locktactyuma/userfiles/file/pexugixefamowimeri.pdfIn PDF document text
- https://martensmgt.com/business_school/uploads/file/78404578126.pdfIn PDF document text
- https://planet-pvc.com/upload/files/95429194094.pdfIn PDF document text
- http://hengelo.scholenkeuze.nl/UserFiles/files/73494844455.pdfIn PDF document text
- https://www.birdandwildlifeteam.com/wp-content/plugins/formcraft/file-upload/server/content/files/162204ee533bf1---fojojezimiku.pdfIn PDF document text
- http://harmony-stone.info/js/kcfinder/upload/files/depale.pdfIn PDF document text
- http://sonsuadogo.org/Images_upload/files/12033672246.pdfIn PDF document text
- http://pspectr.ru/userfiles/file/16407281241.pdfIn PDF document text
- https://mahae.hu/files/files/53358102487.pdfIn PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/xap/1.0/rights/In PDF document text
- http://dejavu.sourceforge.netIn extracted file (font_00_sfnt_off0007d7c6.bin)
- http://dejavu.sourceforge.net/wiki/index.php/LicenseIn extracted file (font_00_sfnt_off0007d7c6.bin)
Extracted artifacts 3
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0007d7c6.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x7D7C6 | 16560 bytes |
SHA-256: 924ad5cb737cfd9a34472b2046831991df4d3950e5f0d7b552a18309318c2ee9 |
|||
font_01_sfnt_off0007eee6.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x7EEE6 | 10740 bytes |
SHA-256: 0b29264586c806b67855ad00d99ba396b57736c85da9365016a2c6d843778277 |
|||
font_02_sfnt_off0008076d.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x8076D | 18536 bytes |
SHA-256: 32bd5c91aeaa40e5d1544cabf5649e23464c40d7334bb2b3777769b149da44c5 |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.