MALICIOUS
164
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The ML classifier and ClamAV detection strongly indicate maliciousness. The PDF contains numerous links pointing to compromised WordPress uploads and disposable hosting, suggesting a phishing or malware distribution campaign. The embedded URLs like 'https://catamma.ru/uplcv?utm_term=instagram+stories+anonymous+online' are likely used to redirect users to malicious sites.
Machine Learning
- Nyx PDF Classifier malicious score 0.9523
Heuristics 7
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
PDF link farm points to compromised-WordPress upload storage medium PDF_COMPROMISED_CMS_UPLOAD_LINK_FARMPDF contains multiple clickable links, across many distinct hosts, whose targets are random-slug files parked in the upload directories of vulnerable WordPress form plugins (FormCraft, Super Forms). This is the hallmark of the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains hosted on compromised sites. The PDF itself carries no exploit — the risk is the linked destinations.
-
Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARMSmall PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
-
Urgency / deadline lure low SE_URGENCY_LUREDocument contains urgency or deadline language ('account will be terminated', 'action required within 24 hours', etc.) — useful context, but low-signal without other findings
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://catamma.ru/uplcv?utm_term=instagram+stories+anonymous+online PDF link annotation
- https://alenakovalchuk.ru/wp-content/plugins/super-forms/uploads/php/files/dfb1e7d47f83ea4bb28cf86984835e1e/44925830859.pdfIn PDF document text
- https://samiznojmo.cz/wp-content/plugins/super-forms/uploads/php/files/b97167d2e8ccb38e7e808c01cb3d3fc6/mesixozemotufoj.pdfIn PDF document text
- https://camile.vn/wp-content/plugins/super-forms/uploads/php/files/u30iqpvd79cfs7dgss7np28718/vusubowafaxowe.pdfIn PDF document text
- https://halobysciton.com/wp-content/plugins/formcraft/file-upload/server/content/files/16080ce7fa0117---bipinigiwutifi.pdfIn PDF document text
- http://amtusa.com/wp-content/plugins/formcraft/file-upload/server/content/files/16087a063a8709---70704922904.pdfIn PDF document text
- http://travisreunion.com/clients/1/1d/1d9c560ef9ee6310b862f4c9d288d7bd/File/17653502509.pdfIn PDF document text
- https://deltagroup.bg/uploads/file/52535855241.pdfIn PDF document text
- https://designcoordinators.com/wp-content/plugins/formcraft/file-upload/server/content/files/1607fb2ca5ab47---murunoxakitulu.pdfIn PDF document text
- http://anvlaw.com/userfiles/file/53607522204.pdfIn PDF document text
- https://www.amiunaorchestra.ro/wp-content/plugins/formcraft/file-upload/server/content/files/1606ccc610d653---jozaroge.pdfIn PDF document text
- https://alternativecarrepair.com/userfiles/file/36745633258.pdfIn PDF document text
- https://robertmatzuzi-massagetherapist.co.uk/wp-content/plugins/formcraft/file-upload/server/content/files/160a0becd07aa9---66987533219.pdfIn PDF document text
- https://cedarcreeksauce.com/wp-content/plugins/super-forms/uploads/php/files/7a7946376d4e55d5b8cc69d8949ba484/zadomogawuwokoman.pdfIn PDF document text
- https://antoinepanau.com/wp-content/plugins/super-forms/uploads/php/files/1cf7cbea04660bc0e9c57a9e872155cb/21314315018.pdfIn PDF document text
- https://postscriptproductions.com/wp-content/plugins/formcraft/file-upload/server/content/files/160bfa64135e35---17602895014.pdfIn PDF document text
- https://qualitycountscleaning.com/wp-content/plugins/super-forms/uploads/php/files/b5b3e01dda7f91f7368fe9c93073bc25/13441465550.pdfIn PDF document text
- http://www.annaleehuber.com/content_files/file/torakusubekev.pdfIn PDF document text
- http://www.oknookna.pl/wp-content/plugins/formcraft/file-upload/server/content/files/160720b39a6931---39390267755.pdfIn PDF document text
- http://hellnocancershow.com/wp-content/plugins/formcraft/file-upload/server/content/files/1609d35dabff05---numijebotife.pdfIn PDF document text
- http://www.ascendercorp.com/In PDF document text
- http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
- http://www.opentle.orgIn PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/xap/1.0/rights/In PDF document text
- https://savannah.gnu.org/projects/freefont/In PDF document text
- http://www.gnu.org/licenses/In PDF document text
- http://www.gnu.org/copyleft/gpl.htmlIn PDF document text
- http://scripts.sil.org/OFLIn PDF document text
- http://www.gnu.org/licenses/gpl.htmlIn PDF document text
- http://dejavu.sourceforge.netIn PDF document text
- http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text
Extracted artifacts 8
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
stream_005_off0001528a.bin |
decompressed-pdf-stream | PDF FlateDecoded stream at offset 0x1528A | 88068 bytes |
SHA-256: a772f380e9886c6eb73ab4290a7f69e1d137041354be913c4ddbd38ffd1ab096 |
|||
font_00_sfnt_off0000ec9e.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xEC9E | 13164 bytes |
SHA-256: 6ac9e27338b0d9bb758cb5b2ddf28257813e2a27b06ddc4539a9ad4d8debf234 |
|||
font_01_sfnt_off0001115a.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x1115A | 14548 bytes |
SHA-256: f4f2048432889b1b9e73a8ff8270949f67e01cb0fccc841c126ab31356fa2610 |
|||
font_02_sfnt_off00014174.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x14174 | 5044 bytes |
SHA-256: 0f2be0d9d2a4f6ed85a87768b9c927bd7cb9b62a27a23448e17bd848a783a5ab |
|||
font_04_sfnt_off00023d57.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x23D57 | 5812 bytes |
SHA-256: ac46ee95c0fa6e3a7d391a0d808f02bfdea0c489ddbd44b21f539b2961f851a0 |
|||
font_05_sfnt_off00024bf0.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x24BF0 | 17812 bytes |
SHA-256: 193e7c4839630677020c86783ac22a23b8c0f04292894e29b4cb847035f2fd24 |
|||
font_06_sfnt_off0002817e.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x2817E | 22192 bytes |
SHA-256: a76240c216256d7e833c8d3ec2a7d8a6f7bf16dba12ca00d7b53ef0f6beab806 |
|||
font_07_sfnt_off0002a831.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x2A831 | 1752 bytes |
SHA-256: 67470589e40c7db1288ffadf7c2c566778eec73a0d27cdc44437c8436fa9b068 |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.