MALICIOUS
124
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
The PDF file contains numerous embedded URLs pointing to compromised WordPress sites and disposable domains, indicating a link farm designed to redirect users to malicious content. ClamAV detection as 'Pdf.Phishing.Trojan' further supports a phishing or trojan distribution intent. The presence of external URI heuristics and link farm indicators strongly suggests this PDF is part of a phishing campaign, likely delivered as a spearphishing attachment.
Machine Learning
- Nyx PDF Classifier suspicious score 0.4539
Heuristics 5
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
PDF link farm points to compromised-WordPress upload storage medium PDF_COMPROMISED_CMS_UPLOAD_LINK_FARMPDF contains multiple clickable links, across many distinct hosts, whose targets are random-slug files parked in the upload directories of vulnerable WordPress form plugins (FormCraft, Super Forms). This is the hallmark of the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains hosted on compromised sites. The PDF itself carries no exploit — the risk is the linked destinations.
-
Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARMSmall PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
-
External URI info PDF_URIPDF contains an external URL action
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://laborke.ru/uplcv?utm_term=the+haunting+of+hill+house+torrent PDF link annotation
- https://drjou-vc.com/upload/files/padugujofiwexabuduze.pdfIn PDF document text
- https://eyescare.vn/app/webroot/upload/ckfinder/files/zunurugotujoguxop.pdfIn PDF document text
- http://isgsrl.it/images/file/67173327936.pdfIn PDF document text
- http://jockmurray.com/wp-content/plugins/formcraft/file-upload/server/content/files/16134cf6353c3b---21504216152.pdfIn PDF document text
- https://vokalensemble-vocembalo.ch/userfiles/file/verunifizavagiponibi.pdfIn PDF document text
- https://www.inkfactory.pk/wp-content/plugins/formcraft/file-upload/server/content/files/1613510829d4e2---zusumofijutikupakumejeje.pdfIn PDF document text
- https://ooo-kenk.ru/userfiles/file/41918372611.pdfIn PDF document text
- http://www.britocunhaadvocacia.com.br/home/wp-content/plugins/formcraft/file-upload/server/content/files/1613227194f967---53484308354.pdfIn PDF document text
- https://aneri12.cz/res/file/5684295080.pdfIn PDF document text
- https://equinox-e.com/upload/files/70358681140.pdfIn PDF document text
- http://richmore.kr/uploadfile/fckeditor/file/futike.pdfIn PDF document text
- https://masini-de-ambalat.ro/images/userfiles/65389717483.pdfIn PDF document text
- http://alconsprom.ru/ckfinder/userfiles/files/zunerajinexi.pdfIn PDF document text
- http://centrlita.ru/archive/image/file/ruguzipobevavul.pdfIn PDF document text
- https://bosgo.mn/uploads/files/62789941829.pdfIn PDF document text
- http://chernogolovka.inhome360.ru/admin/ckfinder/userfiles/files/58671788594.pdfIn PDF document text
- http://www.ashtralmedia.com/wp-content/plugins/formcraft/file-upload/server/content/files/16134db85b0159---xisajenijuxex.pdfIn PDF document text
- https://www.helpagesl.org/wp-content/plugins/formcraft/file-upload/server/content/files/161317ebda7a81---43003556242.pdfIn PDF document text
- http://debten.net/UserFiles/File/1534421652.pdfIn PDF document text
- https://selectwifi.com/wp-content/plugins/formcraft/file-upload/server/content/files/16136e8650dbf5---moribowekegexaluzawo.pdfIn PDF document text
- http://samtle.net/ckupload/files/mijetofopegesul.pdfIn PDF document text
- http://oletrans.sk/editor_uploads/files/70560492369.pdfIn PDF document text
- http://poketomecam.com/uploads/files/bowagixajex.pdfIn PDF document text
- http://artwatch.ru/userfiles/file/15724190304.pdfIn PDF document text
- http://dejavu.sourceforge.netIn PDF document text
- http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000cceb.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xCCEB | 16792 bytes |
SHA-256: 9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1 |
|||
font_01_sfnt_off0000e4fd.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xE4FD | 17776 bytes |
SHA-256: 6f07a60be1c1d1e168106c0afed7739511202fe842e60f9f7f871bb37603df5f |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.