MALICIOUS
156
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1203 Exploitation for Client Execution
The PDF file contains a link farm pointing to numerous websites, many of which are hosted on compromised or disposable domains. This behavior is indicative of a phishing or malware distribution campaign, where users are lured to malicious sites. The ML classifier and ClamAV detection strongly support the malicious nature of this file.
Machine Learning
- Nyx PDF Classifier malicious score 0.9871
Heuristics 6
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
PDF link farm points to compromised-WordPress upload storage medium PDF_COMPROMISED_CMS_UPLOAD_LINK_FARMPDF contains multiple clickable links, across many distinct hosts, whose targets are random-slug files parked in the upload directories of vulnerable WordPress form plugins (FormCraft, Super Forms). This is the hallmark of the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains hosted on compromised sites. The PDF itself carries no exploit — the risk is the linked destinations.
-
Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARMSmall PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL http://advicetao.eu/pictures/file/61893239225.pdf
- http://akinmedical.com/uploads/file/3266361529.pdf
- https://godparents4tz.org/home/god/public_html/ckfinder/userfiles/files/bokirevitepugoles.pdf
- http://www.adanakursmerkezi.com/wp-content/plugins/formcraft/file-upload/server/content/files/160c1c42700adc---25131634337.pdf
- https://www.superioreagle.com/wp-content/plugins/formcraft/file-upload/server/content/files/160a81675bc7be---xipoduvagaxobaregaw.pdf
- https://www.goldenplanet.dk/wp-content/plugins/formcraft/file-upload/server/content/files/160ab8bde20164---68992682411.pdf
- http://wf515345.tw/CKEdit/upload/files/2159030741.pdf
- https://dispomydeal.com/wp-content/plugins/super-forms/uploads/php/files/6a2a98c8c9be3fbd917d8a11d12c5e9f/vudotujurejiwibatap.pdf
- https://lllk.ru/wp-content/plugins/super-forms/uploads/php/files/73582b718a2524dfff4c6fde2d75e8ed/53275668127.pdf
- https://smilepath.com.au/wp-content/plugins/super-forms/uploads/php/files/8eb3ec4951e41ca566d22e18a1dc04d3/58524713883.pdf
- https://rebates.forex/wp-content/plugins/super-forms/uploads/php/files/9mlkdjdn8h22dc0grkc9ql1om5/66594270873.pdf
- https://cambodiadriverservice.com/userfiles/file/28746426615.pdf
- http://mbcasc.net/imgs/file/wemesixigujezipevufulud.pdf
- https://dispomydeal.com/wp-content/plugins/super-forms/uploads/php/files/30606770131105ddabdd012563d3083f/16625999175.pdf
- https://sg-design.top/wp-content/plugins/super-forms/uploads/php/files/8ccfc0d28081d5b62785b44737721595/pejajemifunujumalav.pdf
- https://haps.company/wp-content/plugins/super-forms/uploads/php/files/ec560gfd7rmt1lng1e8uudb507/finenu.pdf
- https://dongytueduc.com/wp-content/plugins/super-forms/uploads/php/files/jutkq7pavhg98nu0rto1r2671n/68395016770.pdf
- https://atlastoursntravels.com/userfiles/file/sejijetikeka.pdf
- http://degeninhotel.ru/admin/ckfinder/userfiles/files/48241661341.pdf
- http://julieesteban.com/wp-content/plugins/formcraft/file-upload/server/content/files/1609d3893abdf7---xozabaru.pdf
- https://psychotherapie-dr-albrecht.de/wp-content/plugins/formcraft/file-upload/server/content/files/160bf052ac58fe---45151665311.pdf
- http://training-solutions.ro/wp-content/plugins/formcraft/file-upload/server/content/files/160bb411392d5b---zanexadokozuwif.pdf
- http://kapli74.ru/upload_picture/razapivejuvitod.pdf
- http://steclotildehorton.ca/wp-content/plugins/formcraft/file-upload/server/content/files/16097a5123a2fe---96448184904.pdf
- https://www.psalighting.com/wp-content/plugins/super-forms/uploads/php/files/699691cbc05b0c96b903c67e1b7d81b9/29623166901.pdf
- https://feedproxy.google.com/~r/1eyvgo/aqOO/~3/zMnd8XtcwSM/uplcv?utm_term=vector+form+of+coulomb+law
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://dejavu.sourceforge.net
- http://dejavu.sourceforge.net/wiki/index.php/License
Extracted artifacts 4
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00013c9b.bin7bcdd96d58029556994dd1130d26a05338481d31d3d7c9c93d73fe0af8a6a4c6 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x13C9B | 20692 bytes |
font_01_sfnt_off0001739d.bin9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x1739D | 16792 bytes |
font_02_sfnt_off00018bb4.bin49d17f3dfa58325bd26eb89b9d01e74a130509a717bac9680288a5d7d0b822c4 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x18BB4 | 10428 bytes |
font_03_sfnt_off0001a376.bin2ec0af74db8f4302b0410a9be76a1410370674b26b7b3b74451a592e0c00b7cc |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x1A376 | 16460 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.