MALICIOUS
164
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1204.002 Malicious Link
The PDF contains numerous links pointing to external websites, many of which are hosted on compromised CMS platforms, suggesting a link farm or phishing lure. The ML classifier and ClamAV detection strongly indicate malicious intent, likely for distributing malware or facilitating phishing. The presence of a 'download button' heuristic further supports the attack pattern of tricking users into downloading a malicious file.
Machine Learning
- Nyx PDF Classifier malicious score 0.9998
Heuristics 7
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
PDF link farm points to compromised-WordPress upload storage medium PDF_COMPROMISED_CMS_UPLOAD_LINK_FARMPDF contains multiple clickable links, across many distinct hosts, whose targets are random-slug files parked in the upload directories of vulnerable WordPress form plugins (FormCraft, Super Forms). This is the hallmark of the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains hosted on compromised sites. The PDF itself carries no exploit — the risk is the linked destinations.
-
Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARMSmall PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
-
Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTONDocument contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://wastran.ru/uplcv?utm_term=frp+bypass+google+account+manager+apk
- https://burmesecatclub.nz/wp-content/plugins/super-forms/uploads/php/files/af924a4899418baca901c0603d51f98d/wuzofolevopepunazi.pdf
- https://www.ferienhof-schneider.de/wp-content/plugins/formcraft/file-upload/server/content/files/16083fe8126c2d---mebivemapufiwux.pdf
- https://advancedcheckcashadvance.com/wp-content/plugins/formcraft/file-upload/server/content/files/1609a874356780---8463320283.pdf
- https://makemycake.gr/wp-content/plugins/super-forms/uploads/php/files/3olb2qfkqoegehsvn10mrlelh5/45784581166.pdf
- https://globalclassic.org/wp-content/plugins/super-forms/uploads/php/files/m23r929ndscq2t92j7a34klbdr/39305978720.pdf
- http://firanywiktoria.pl/uploads/editor/file/19718642516.pdf
- http://extreamtuning.ru/wp-content/plugins/formcraft/file-upload/server/content/files/1607a8d2933d4f---benepizixekuzode.pdf
- http://pcmcpropertyblog.com/wp-content/plugins/super-forms/uploads/php/files/0803fd116e938123f0c21d093f48b9ea/23616371892.pdf
- https://cbolean.com/wp-content/plugins/super-forms/uploads/php/files/e2c3pbh4t0o38moo599n6li5l6/27324522391.pdf
- http://sahamit.net/userfiles/file/23431805753.pdf
- https://mobistore.co.nz/wp-content/plugins/super-forms/uploads/php/files/c0870e836276a6daa780e08b16c44b26/69626999586.pdf
- https://arizonapoolcontractor.com/wp-content/plugins/formcraft/file-upload/server/content/files/160b57b41c53da---tozafiwukovabijakajimogaf.pdf
- http://okmarin.ru/userfiles/file/jenujutenavovimaxadipozo.pdf
- https://pfgmm.com.au/wp-content/plugins/formcraft/file-upload/server/content/files/1609b037d284ec---64625895952.pdf
- http://trenermichal.pl/wp-content/plugins/formcraft/file-upload/server/content/files/160a4f23495c45---11385644527.pdf
- https://paloaltospeakerseries.com/wp-content/plugins/super-forms/uploads/php/files/ee09023d6e88738d0f7166d53e971325/zijuzuf.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000d4d6.bin5c3bafa36600c78845af99f2d74abd1f490093106e7f5f9d0f05f6a82e4ea5a7 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xD4D6 | 5512 bytes |
font_01_sfnt_off0000e788.binb6d1f25f8d9135b3d0f70b33d93452e290710e5f15267d4d97d17944e6c609ba |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xE788 | 12020 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.