MALICIOUS
94
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1204.002 Malicious Link
The PDF file contains a large number of external URIs, many of which point to compromised WordPress sites or disposable hosting. This suggests the document is primarily functioning as a link farm, likely for SEO manipulation or to distribute further malicious content. The ML classifier strongly supports the malicious nature of this PDF.
Machine Learning
- Nyx PDF Classifier malicious score 0.9841
Heuristics 4
-
PDF link farm points to compromised-WordPress upload storage medium PDF_COMPROMISED_CMS_UPLOAD_LINK_FARMPDF contains multiple clickable links, across many distinct hosts, whose targets are random-slug files parked in the upload directories of vulnerable WordPress form plugins (FormCraft, Super Forms). This is the hallmark of the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains hosted on compromised sites. The PDF itself carries no exploit — the risk is the linked destinations.
-
Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARMSmall PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
-
External URI info PDF_URIPDF contains an external URL action
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://chcial.ru/uplcv?utm_term=derecho+romano+marta+morineau+iduarte+pdf+gratis PDF link annotation
- http://pivotal-technologies.com/userfiles/file/64380635327.pdfIn PDF document text
- https://fortlauderdale-carservice.com/wp-content/plugins/formcraft/file-upload/server/content/files/1608ba1efda037---2871865884.pdfIn PDF document text
- http://www.lightingandhvacexpo.com/wp-content/plugins/super-forms/uploads/php/files/62332b335d50fc4109a6d7daee4cdf23/wobodebejuvegijulejed.pdfIn PDF document text
- http://www.opencalgary.org/wp-content/plugins/formcraft/file-upload/server/content/files/1606ef4675214d---92711784671.pdfIn PDF document text
- https://estigotours.com/wp-content/plugins/super-forms/uploads/php/files/504754c7b0c8fd5d15a26516b5e8dd2f/ribosadenepudubegugodav.pdfIn PDF document text
- http://call.ae/wp-content/plugins/formcraft/file-upload/server/content/files/16073ef5d9de31---32532497593.pdfIn PDF document text
- http://www.pianoszimmermann.com.br/wp-content/plugins/formcraft/file-upload/server/content/files/160825b42e4ecf---9876109284.pdfIn PDF document text
- http://geometrabottero.it/userfiles/files/30193564514.pdfIn PDF document text
- http://www.scmphotography.co.uk/wp-content/plugins/formcraft/file-upload/server/content/files/1606f5a3ea7afe---xezezukozigamigazate.pdfIn PDF document text
- http://precedent.by/_newsite/images_from_html_editor/file/49179911949.pdfIn PDF document text
- http://audiomaster.se/wp-content/plugins/formcraft/file-upload/server/content/files/1607e17192b04e---gagigasisalame.pdfIn PDF document text
- http://gtshotel.it/images/file/ratowi.pdfIn PDF document text
- http://abacusnancy.com/userfiles/file/vixemarafipuvovozenowi.pdfIn PDF document text
- http://amwordpress.org/wp-content/plugins/formcraft/file-upload/server/content/files/160b67e83f1440---16892980101.pdfIn PDF document text
- https://southernlightingsource.com/wp-content/plugins/super-forms/uploads/php/files/3df20e0e9f393fd3f4f6f39263434215/1456835571.pdfIn PDF document text
- https://africanresearchcenter.com/userfiles/file/gipurawovugobugan.pdfIn PDF document text
- http://penoplex24.ru/wp-content/plugins/formcraft/file-upload/server/content/files/16094d0b226534---ladofat.pdfIn PDF document text
- http://philippinesroadshow.com/wp-content/plugins/super-forms/uploads/php/files/b18932b9c65aa231639178b08e78e905/65516503570.pdfIn PDF document text
- https://healthmatters.me/userfiles/file/zuxekezem.pdfIn PDF document text
- https://www.jemelectric.com/wp-content/plugins/formcraft/file-upload/server/content/files/16070232fda419---64148698923.pdfIn PDF document text
- http://www.ascendercorp.com/In PDF document text
- http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
- http://scripts.sil.org/OFLIn PDF document text
Extracted artifacts 1
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000e8f7.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xE8F7 | 5416 bytes |
SHA-256: 579f0c9784c06847217b1489738ea4d6faac42a9f1dafb3cd7b10dc6090e1990 |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.