MALICIOUS
186
Risk Score
Machine Learning
- Nyx PDF Classifier malicious score 0.9997
Heuristics 6
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARMSmall PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://nipisod.ru/wix?keyword=sharp+carousel+microwave+manual+r408ls PDF link annotation
- http://zugasanuko.getenjoyment.net/46527331721.pdfIn PDF document text
- http://0fruit.space/zosafigop38g.pdfIn PDF document text
- https://matomuzunoto.weebly.com/uploads/1/3/5/3/135389802/bamoxojevi-mevizezimijopal-supupusoza-rajijalumezefa.pdfIn PDF document text
- http://numulul.mygamesonline.org/26812166054.pdfIn PDF document text
- https://deriwofapavuz.weebly.com/uploads/1/3/4/3/134311795/7799806.pdfIn PDF document text
- http://tewatag.medianewsonline.com/how_to_get_a_baseball_bat_in_gta_5_online_xbox_one_2020.pdfIn PDF document text
- http://dreabling.online/vajim9z468.pdfIn PDF document text
- https://tifalexax.weebly.com/uploads/1/3/4/4/134471923/49e962c360.pdfIn PDF document text
- http://importants.space/12768317466wt93y.pdfIn PDF document text
- https://xovadodelemowuz.weebly.com/uploads/1/3/1/3/131383330/sowumokona-kawemokaben-pojafunus.pdfIn PDF document text
- https://kibewuzogoluwiw.weebly.com/uploads/1/3/1/6/131636689/wekatisozifewif.pdfIn PDF document text
- http://www.ascendercorp.com/In PDF document text
- http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
- https://3175e58c-9db9-4d87-bcb9-15e03531d93d.filesusr.com/ugd/c93210_71f70d083fff45a288b79ab4faff20be.pdf?index=trueIn PDF document text
- https://627f215e-41ba-4aa4-9906-5f9f9d117739.filesusr.com/ugd/8ab72e_5a5532423a43438c95b4af2da025c3b5.pdf?index=trueIn PDF document text
- https://80b2a579-f9ed-4aa0-b91a-ac3c8973c086.filesusr.com/ugd/353d00_508dcad1959043deacfb879284d35b4a.pdf?index=trueIn PDF document text
- https://3485775d-af35-4505-8fb4-f6750f575e04.filesusr.com/ugd/42f18e_79ad30479b7243ebb8e2e5ecea248975.pdf?index=trueIn PDF document text
- https://b4095e1f-5e43-4c35-8b28-ff0c3185c247.filesusr.com/ugd/9cc3de_b79083d4a3b84c72a0459a6c3d68e912.pdf?index=trueIn PDF document text
- https://3633ae4e-9acc-45df-885e-1bfa1481cb44.filesusr.com/ugd/e73054_1e7404064da049ac9e6468f2866c99c8.pdf?index=trueIn PDF document text
- https://2cc12256-1025-444a-bacb-901a9f007bda.filesusr.com/ugd/d1fcfc_1df966bf93cd4b2db7aada923dd8d615.pdf?index=trueIn PDF document text
- https://f733e552-90a1-4d1f-83ca-a6b36afcf31c.filesusr.com/ugd/38bf1f_4c0f3c106bde4eab99762a70a3ff1998.pdf?index=trueIn PDF document text
- https://dc58184e-bbba-402a-8e08-a55d552c8f3f.filesusr.com/ugd/0ebc1f_4f8608061c25499f96945fa22a548a99.pdf?index=trueIn PDF document text
- https://0c2a7d7b-be9d-4ef2-a94c-09ca905cc17d.filesusr.com/ugd/7d21c0_23044c5c38734d7b8f1f3810c66cc04a.pdf?index=trueIn PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/xap/1.0/rights/In PDF document text
- http://scripts.sil.org/OFLIn PDF document text
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000c5c4.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xC5C4 | 5852 bytes |
SHA-256: aeba745b06b1f70e1614257d145954708a2b188fba663bef998ab38ef3cf913f |
|||
font_01_sfnt_off0000d9a0.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xD9A0 | 9592 bytes |
SHA-256: 2267dac8af3b49ce2be180cb5bd910365def228f1e389195d8bdd29da282d2f5 |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.