MALICIOUS
154
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1204.002 Malicious Link
The PDF contains a large number of links, many of which point to compromised WordPress sites. This behavior is indicative of a link farm designed to host malicious content or facilitate phishing attacks. The ClamAV detection and ML classifier further support its malicious nature.
Machine Learning
- Nyx PDF Classifier malicious score 0.8168
Heuristics 5
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
PDF link farm points to compromised-WordPress upload storage medium PDF_COMPROMISED_CMS_UPLOAD_LINK_FARMPDF contains multiple clickable links, across many distinct hosts, whose targets are random-slug files parked in the upload directories of vulnerable WordPress form plugins (FormCraft, Super Forms). This is the hallmark of the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains hosted on compromised sites. The PDF itself carries no exploit — the risk is the linked destinations.
-
Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARMSmall PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
-
External URI info PDF_URIPDF contains an external URL action
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL http://vietsonplastic.com/uploads/userfiles/file/90105115070.pdf In PDF document text
- https://ludifrance.fr/userfiles/file/96309602308.pdfIn PDF document text
- https://encouragingmath.com/wp-content/plugins/super-forms/uploads/php/files/4b9bd02eb1b2ef1b3b7b1994dc9cfec8/11277966587.pdfIn PDF document text
- http://zadonskiy.ru/wp-content/plugins/formcraft/file-upload/server/content/files/160aa86d7b0e2e---53392942252.pdfIn PDF document text
- http://veronicanealhome.com/wp-content/plugins/formcraft/file-upload/server/content/files/2/160b7f401c702f---17199245627.pdfIn PDF document text
- https://www.anandtirth.com/wp-content/plugins/super-forms/uploads/php/files/4nno7gupqtuin6gpqem2mhak83/27844759542.pdfIn PDF document text
- https://webmodeli.com/wp-content/plugins/formcraft/file-upload/server/content/files/160c89cc13ffee---33868663033.pdfIn PDF document text
- https://www.techsrollout.com/wp-content/plugins/formcraft/file-upload/server/content/files/160b64a17bc6cd---lixejogowixevefaku.pdfIn PDF document text
- http://www.xpresswedding.com/wp-content/plugins/formcraft/file-upload/server/content/files/160a5297229500---88969149853.pdfIn PDF document text
- https://postscriptproductions.com/wp-content/plugins/formcraft/file-upload/server/content/files/160c4526d6b4d3---nupurixobupos.pdfIn PDF document text
- http://www.kickcommerce.com/userfiles/file/35358067728.pdfIn PDF document text
- http://philipwillettelaw.com/customer/3/d/9/3d947ad6ce2568d98b832ccf5548371bFile/17504707537.pdfIn PDF document text
- http://wksystems.net/HotelEstimator/userfiles/file/bixatorokesugiworem.pdfIn PDF document text
- http://kindervakantieweekdeurne.nl/wp-content/plugins/formcraft/file-upload/server/content/files/16094102a22a47---zewunaw.pdfIn PDF document text
- http://legendtec-eg.com/wp-content/plugins/super-forms/uploads/php/files/8cta8ujbhkrpc7f1bd368g2nj3/41952621133.pdfIn PDF document text
- https://arvikabc.com/images/uploadedimages/file/28220561840.pdfIn PDF document text
- https://stpetejazz.com/wp-content/plugins/super-forms/uploads/php/files/hmivqkuhbmcelg80mvk8hn5t52/fesiganavijupirizo.pdfIn PDF document text
- http://luingpyrex.cz/foto/Image/file/82083848061.pdfIn PDF document text
- http://www.investing-in-women.com/wp-content/plugins/formcraft/file-upload/server/content/files/1608c660440f0c---97064178896.pdfIn PDF document text
- https://dycmc.com/DATA/upload/files/202106152108015531.pdfIn PDF document text
- https://www.theknowledgeonline.com/files/lib/ckfinder/userfiles/files/77852794686.pdfIn PDF document text
- http://www.hypnotiseur.com/wp-content/plugins/formcraft/file-upload/server/content/files/16076a2e0c53aa---27100130304.pdfIn PDF document text
- https://greenturtleproductions.com.au/wp-content/plugins/super-forms/uploads/php/files/dade403caecf7bb5518b6c2758705402/gubena.pdfIn PDF document text
- http://ntouioc.ntou.edu.tw/ckfinder/userfiles/files/vazusibinomuz.pdfIn PDF document text
- http://speakingaboutnetworking.com/ckfinder/userfiles/files/47750496298.pdfIn PDF document text
- https://feedproxy.google.com/~r/skout/mBVl/~3/6naE_Nh8_CY/uplcv?utm_term=marketing+management+quiz+questions+and+answers+pdfPDF link annotation
Open this report in the interactive analyzer, or submit your own file for analysis.