MALICIOUS
194
Risk Score
Machine Learning
- Nyx PDF Classifier malicious score 1.0000
Heuristics 5
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Image lure linking to an SEO redirector (free-download phishing) high PDF_SEO_UTM_REDIRECTOR_LINKPDF embeds an image with little or no body text and a clickable link to a multi-word utm_term / FeedBurner-proxied SEO redirector — the 'free ebook / solution-manual / document download' phishing family that ranks for natural-language search queries and routes the user into a payload/redirect chain. The PDF carries no exploit; the risk is the linked destination. Flagged structurally (image lure + SEO redirector) so it does not depend on a ClamAV/ML signature, and regardless of how many filler text pages the lure carries.
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://ttraff.me/pify?keyword=grung+d%2526d+lore In PDF document text
- https://finiluxexolije.weebly.com/uploads/1/3/1/8/131856594/porupeporise-lovude-notojowukal-siniwisu.pdfIn PDF document text
- https://sepikupi.weebly.com/uploads/1/3/0/7/130738949/1245811.pdfIn PDF document text
- https://kubupukadumu.weebly.com/uploads/1/3/1/3/131382740/3665400.pdfIn PDF document text
- https://pigogokeda.weebly.com/uploads/1/3/1/8/131857695/9712958.pdfIn PDF document text
- https://xukabasal.weebly.com/uploads/1/3/0/7/130776322/rugetijafasaru-pogezudi-tamegemepuki-niwazexirekibo.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4366395/normal_5f8fa7f8bd7ee.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4369647/normal_5f920eed73670.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4379971/normal_5f94a84658f13.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4366007/normal_5f8733e876688.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4366630/normal_5f8d2ab9c8bf8.pdfIn PDF document text
- http://www.ascendercorp.com/In PDF document text
- http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
- https://uploads.strikinglycdn.com/files/9f9f1b43-8b03-41cd-abc9-f441be5c1472/sizixader.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/03720fee-3a2e-4f3d-9d22-3304fa53af56/gunidonitaguxu.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/f72b8fdc-04b0-4a3e-803b-ac04b17e6d0c/xelirerorenilisetev.pdfIn PDF document text
- https://cdn.shopify.com/s/files/1/0499/8748/5859/files/48612956456.pdfIn PDF document text
- https://cdn.shopify.com/s/files/1/0500/8405/3156/files/wigavekofulewote.pdfIn PDF document text
- https://cdn.shopify.com/s/files/1/0500/4276/5511/files/31263252388.pdfIn PDF document text
- https://s3.amazonaws.com/gedimuta/16338642589.pdfIn PDF document text
- https://s3.amazonaws.com/wapabefizosumi/preterito_perfecto_de_subjuntivo_ejercicios.pdfIn PDF document text
- https://cdn.shopify.com/s/files/1/0482/9665/7058/files/77173682232.pdfIn PDF document text
- https://cdn.shopify.com/s/files/1/0504/4518/9310/files/tommy_emmanuel_halfway_home_lesson.pdfIn PDF document text
- https://cdn.shopify.com/s/files/1/0499/1388/8936/files/definicion_conflicto_armado_en_colombia.pdfIn PDF document text
- https://cdn.shopify.com/s/files/1/0503/5222/6472/files/ab_workout_for_beginners.pdfIn PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/xap/1.0/rights/In PDF document text
- http://scripts.sil.org/OFLIn PDF document text
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00006813.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x6813 | 4604 bytes |
SHA-256: e2276dedcbe32f3fe783d3de40b11455da6b67eb06ee104eae39541f6156bd98 |
|||
font_01_sfnt_off000077cd.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x77CD | 10500 bytes |
SHA-256: 6e1a6d74cc27a3fc029a1b98797d272ef124e3c4c7d2e3f6cf9520b5e495f854 |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.