MALICIOUS
156
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
This PDF file was flagged by multiple heuristics, including a critical ClamAV detection for 'Pdf.Phishing.Trojan'. The file contains numerous external links, many pointing to compromised WordPress upload directories or disposable hosting, suggesting a link farm designed to redirect users. The ML classifier also strongly indicated maliciousness. While no scripts were explicitly extracted, the PDF structure and link farm behavior are indicative of a phishing or malware distribution lure.
Machine Learning
- Nyx PDF Classifier malicious score 0.9951
Heuristics 6
-
ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
-
PDF link farm points to compromised-WordPress upload storage medium PDF_COMPROMISED_CMS_UPLOAD_LINK_FARMPDF contains multiple clickable links, across many distinct hosts, whose targets are random-slug files parked in the upload directories of vulnerable WordPress form plugins (FormCraft, Super Forms). This is the hallmark of the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains hosted on compromised sites. The PDF itself carries no exploit — the risk is the linked destinations.
-
Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARMSmall PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://synerhu.ru/uplcv?utm_term=the+loyalty+effect+reichheld+pdf
- http://alexhofford.com/temp/files/file/bigizuba.pdf
- http://kino-profi.com/wp-content/plugins/super-forms/uploads/php/files/2e4801d8db52bc92729d5f0381b1b0f9/47100927041.pdf
- https://spencershaulageltd.co.uk/wp-content/plugins/super-forms/uploads/php/files/b1a2ff125e0e7709218bd79f8783c232/64453554926.pdf
- http://hellnocancershow.com/wp-content/plugins/formcraft/file-upload/server/content/files/160854b105bed7---61016280245.pdf
- https://jdbailbonds.com/wp-content/plugins/super-forms/uploads/php/files/e08eac76f091b71767c99ddcbc4a9fc4/puwulirazitadobowixawu.pdf
- http://softtox.com/new/userfiles/file/nuvavisemapajinatotexi.pdf
- http://gingerwooddesign.com/wp-content/plugins/formcraft/file-upload/server/content/files/1608226cae2e76---76749455428.pdf
- http://www.rolstoellift.com/wp-content/plugins/formcraft/file-upload/server/content/files/160af48b2c0c8f---75934357492.pdf
- http://www.mtpartnersfl.com/wp-content/plugins/formcraft/file-upload/server/content/files/1609a9834bd3e9---vufabowidisexefosusav.pdf
- http://sladkiy-ostrov.ru/userfiles/files/xokotavoxotusevapuwi.pdf
- https://gionggiacam.com/ckfinder/userfiles/files/juloxokowaka.pdf
- http://www.inhd.com.br/wp-content/plugins/formcraft/file-upload/server/content/files/1608d93053cccb---73303984836.pdf
- https://wscnaturalhealings.com/wp-content/plugins/super-forms/uploads/php/files/c04f76599b4ebeabaaceb72d9aa02653/82635881537.pdf
- http://gzky.cn/dubeite/ckfinder/userfiles/files/20210616_113738.pdf
- http://grani-tonkogo-mira.ru/wp-content/plugins/super-forms/uploads/php/files/638d22bee494f704ad40c278b2a9282d/fevetavaguselasejirodite.pdf
- https://www.hadlowsecurityshutters.com/wp-content/plugins/super-forms/uploads/php/files/bd14f8535a3356fe80c16c1b5df84fcd/rixonofifororirebiponegam.pdf
- https://klingende-zeder.de/wp-content/plugins/formcraft/file-upload/server/content/files/1608591874211a---gakazirupan.pdf
- https://www.die-umzugsfabrik.com/wp-content/plugins/formcraft/file-upload/server/content/files/1607578d622937---99855026781.pdf
- http://www.stockholmswingallstars.com/wp-content/plugins/formcraft/file-upload/server/content/files/160d665e1c6bda---75501580902.pdf
- http://podhoru.cz/userfiles/file/jezivededuju.pdf
- https://medprobr.com.br/wp-content/plugins/super-forms/uploads/php/files/0b611eb2899860990b00eeacea427c3a/19090169084.pdf
- https://swotin.com/wp-content/plugins/formcraft/file-upload/server/content/files/16091e8da82ec5---kezones.pdf
- https://socialchangefactory.org/wp-content/plugins/super-forms/uploads/php/files/53c1561b303e4e54c846892f06709fad/gugixesokot.pdf
- https://noithatkuongthinh.com/uploads/files/laretoxanu.pdf
- http://elonsummerstorage.com/wp-content/plugins/formcraft/file-upload/server/content/files/16075ed0cf12c4---veropura.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://dejavu.sourceforge.net
- http://dejavu.sourceforge.net/wiki/index.php/License
Extracted artifacts 3
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000e659.bin7ee03398b05f08fc41d00384e3e73f1d29de3f1a7ade1e9532d7b24733c1f448 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xE659 | 17388 bytes |
font_01_sfnt_off000113f4.bin3c2dffeedb5009a704c8b8a2686a89bfbb58eee78153e5f68210e9bd4a8c71a0 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x113F4 | 10524 bytes |
font_02_sfnt_off00012c14.bin9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x12C14 | 16792 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.