MALICIOUS
106
Risk Score
Machine Learning
- Nyx PDF Classifier suspicious score 0.4126
Heuristics 5
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
Image lure linking to an SEO redirector (free-download phishing) high PDF_SEO_UTM_REDIRECTOR_LINKPDF embeds an image with little or no body text and a clickable link to a multi-word utm_term / FeedBurner-proxied SEO redirector — the 'free ebook / solution-manual / document download' phishing family that ranks for natural-language search queries and routes the user into a payload/redirect chain. The PDF carries no exploit; the risk is the linked destination. Flagged structurally (image lure + SEO redirector) so it does not depend on a ClamAV/ML signature, and regardless of how many filler text pages the lure carries.
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://colod.co.za/XSRYdR1H?utm_term=ring+sizer+chart+actual+size PDF link annotation
- https://www.pelicanfinancialnetwork.com/ckfinder/userfiles/files/rebavufesivu.pdfIn PDF document text
- http://sake-tori.com/images/library/File/xiwekukabexi.pdfIn PDF document text
- http://universalestetic.com/userfiles/file/41543744164.pdfIn PDF document text
- https://pejapuvurexoku.weebly.com/uploads/1/3/1/6/131636728/1967012.pdfIn PDF document text
- https://alrukn.co/userfiles/files/togolefezutukokiwijezu.pdfIn PDF document text
- https://xuvaguwofivopi.weebly.com/uploads/1/3/4/4/134463587/1523488.pdfIn PDF document text
- https://www.andimoda.com/wp-content/plugins/super-forms/uploads/php/files/b6eeac400966629349371ba7ba93aee5/dutusuwugujaze.pdfIn PDF document text
- https://codefon.hu/js/ckfinder/userfiles/files/wokiv.pdfIn PDF document text
- https://rizumamor.weebly.com/uploads/1/3/4/3/134395934/bf8a873f56a6445.pdfIn PDF document text
- https://bageriwiko.weebly.com/uploads/1/3/2/8/132814239/42cb0f74d8.pdfIn PDF document text
- https://pulezigo.weebly.com/uploads/1/3/4/6/134600697/01871af2da.pdfIn PDF document text
- http://ilonew.tasksplan.com/ckfinder/userfiles/files/24930483199.pdfIn PDF document text
- https://mikezibe.weebly.com/uploads/1/3/1/4/131453119/4013494.pdfIn PDF document text
- https://precisionautoandac.com/wp-content/plugins/super-forms/uploads/php/files/5c55dece76d133d28b0e32c18510a526/sotelezofam.pdfIn PDF document text
- https://ropidofizo.weebly.com/uploads/1/3/0/7/130738616/ribezigigaluxuluno.pdfIn PDF document text
- https://damexizatu.weebly.com/uploads/1/3/4/7/134736049/gader_kisegi_kivesurejida.pdfIn PDF document text
- https://faremuxonebaw.weebly.com/uploads/1/3/4/5/134598019/f2040302bb68ad.pdfIn PDF document text
- http://cuacuongiare.vn/upload/files/poributevorikowowule.pdfIn PDF document text
- http://boletin.alicantehosteleria.com/lib/ckfinder/userfiles/files/lofugenezogulipebe.pdfIn PDF document text
- https://xn--nmqu14inmf.com/upload/files/14866081095.pdfIn PDF document text
- https://sekawoxovezu.weebly.com/uploads/1/3/4/0/134018239/1217036.pdfIn PDF document text
- https://jumuvive.weebly.com/uploads/1/3/0/7/130776409/297121e1d8.pdfIn PDF document text
- http://ci-tesco.com/kcfinder/upload/files/zipojoxijulokavu.pdfIn PDF document text
- https://zeruxukekojumu.weebly.com/uploads/1/3/5/3/135345771/8622eb021.pdfIn PDF document text
- https://notozovurex.weebly.com/uploads/1/3/2/8/132814393/7cad50f10387b17.pdfIn PDF document text
- https://lixtech.com.tw/ckfinder/ckfiles/files/3516079274.pdfIn PDF document text
- https://towotoguwulij.weebly.com/uploads/1/3/4/4/134482006/diwasipepanudoz_mulolinovidobom.pdfIn PDF document text
- https://wofogubegir.weebly.com/uploads/1/3/4/7/134728038/jabowalanor.pdfIn PDF document text
- http://agencies.opertur.com/uploaded/kcfinder/files/52568578658.pdfIn PDF document text
- http://rostocker-taxi.de/resources/files/61361515478.pdfIn PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/xap/1.0/rights/In PDF document text
- http://dejavu.sourceforge.netIn extracted file (font_00_sfnt_off0007bf7f.bin)
- http://dejavu.sourceforge.net/wiki/index.php/LicenseIn extracted file (font_00_sfnt_off0007bf7f.bin)
Extracted artifacts 3
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0007bf7f.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x7BF7F | 10596 bytes |
SHA-256: f34c940189513b05bb95fe119e4fe0059bc24ebf30738dfd6aadba12fe728f74 |
|||
font_01_sfnt_off0007d7ac.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x7D7AC | 16792 bytes |
SHA-256: 9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1 |
|||
font_02_sfnt_off0007efbe.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x7EFBE | 17616 bytes |
SHA-256: 693898d78542433506f6b9ad417099ce6ec71ef53dadc6545a10bf265482c43f |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.