MALICIOUS
194
Risk Score
Machine Learning
- Nyx PDF Classifier malicious score 1.0000
Heuristics 5
-
PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINKPDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Image lure linking to an SEO redirector (free-download phishing) high PDF_SEO_UTM_REDIRECTOR_LINKPDF embeds an image with little or no body text and a clickable link to a multi-word utm_term / FeedBurner-proxied SEO redirector — the 'free ebook / solution-manual / document download' phishing family that ranks for natural-language search queries and routes the user into a payload/redirect chain. The PDF carries no exploit; the risk is the linked destination. Flagged structurally (image lure + SEO redirector) so it does not depend on a ClamAV/ML signature, and regardless of how many filler text pages the lure carries.
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://gettraff.ru/pify?keyword=livro+primavera+silenciosa+em+pdf In PDF document text
- https://cdn-cms.f-static.net/uploads/4373008/normal_5f90a6e7826b4.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4383449/normal_5f8e3ea5407c6.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4370092/normal_5f910e6b4e8e9.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4401538/normal_5f90f6b741fc8.pdfIn PDF document text
- https://wovasemuzusalej.weebly.com/uploads/1/3/1/6/131636629/e7f58a237e8fe8.pdfIn PDF document text
- https://xilorufanil.weebly.com/uploads/1/3/0/7/130739938/bumelokatenexi.pdfIn PDF document text
- https://lagukekejase.weebly.com/uploads/1/3/0/8/130815031/de03b.pdfIn PDF document text
- https://dutitujazekap.weebly.com/uploads/1/3/0/8/130814390/kadijamiruvinugeno.pdfIn PDF document text
- http://www.ascendercorp.com/In PDF document text
- http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
- https://uploads.strikinglycdn.com/files/bd1d5a08-2357-4bf1-8171-1f9d294aeda0/florida_bdi_course_answers.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/d4cabb44-e8ab-48e5-beff-16656be10585/32397527871.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/c1c384dc-8058-439e-b08b-ddfbb16bcef5/big_horn_pellet_grill_srpg1093xl_own.pdfIn PDF document text
- https://s3.amazonaws.com/tuzamada/genetic_programming_an_introduction.pdfIn PDF document text
- https://s3.amazonaws.com/susopuzupure/how_to_improve_self_esteem_and_confidence.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/34df61d1-f113-466d-b604-4ca93b158424/1509693037.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/96790abc-9d71-4ad2-b0fd-1847690565e6/miveluwuvomamogadekavagez.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/84bb805d-f2e0-42ee-99ec-18cd77b90ee7/29491175012.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/708bbd30-89e5-4832-9269-f1087264893f/nugugugopimus.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/7427855c-fd81-4949-a39a-dcaf95ee926a/15278688327.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/7e0a78b6-f26d-4285-8f2e-4592d9f5b1bd/5869013090.pdfIn PDF document text
- https://uploads.strikinglycdn.com/files/d9786e39-b22b-47fd-860e-fb8ddedff464/87826615192.pdfIn PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/xap/1.0/rights/In PDF document text
- http://scripts.sil.org/OFLIn PDF document text
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00005678.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x5678 | 5304 bytes |
SHA-256: c5c77b55c9822e9a3f3d3e2f09b394cb91fc5aeaf83a0bbbee1635eb10ba0940 |
|||
font_01_sfnt_off0000686c.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x686C | 12476 bytes |
SHA-256: 3d3e5a11a458f965e5d162409f7bb44cab9902fffb7c6e26b786649d4e69051a |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.