MALICIOUS
174
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
This PDF document was flagged as malicious by ClamAV and an ML classifier. The file embeds a large number of external links characteristic of an SEO link farm, many hosted on compromised CMS upload directories and uses an image-based lure. Specific URLs and indicators for this sample are listed in the indicators section.
Machine Learning
- Nyx PDF Classifier malicious score 0.7830
Heuristics 6
-
ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
-
Image-only document with action trigger (screenshot lure) medium PDF_IMAGE_LUREPDF has 1 image(s), only 0 text block(s), carries a click-outward action, and is only 41 KB — typical shape of a phishing lure where a full-page screenshot hides a clickable button that launches or submits to an attacker URL.
-
PDF link farm points to compromised-WordPress upload storage medium PDF_COMPROMISED_CMS_UPLOAD_LINK_FARMPDF contains multiple clickable links, across many distinct hosts, whose targets are random-slug files parked in the upload directories of vulnerable WordPress form plugins (FormCraft, Super Forms). This is the hallmark of the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains hosted on compromised sites. The PDF itself carries no exploit — the risk is the linked destinations.
-
Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARMSmall PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
-
External URI info PDF_URIPDF contains an external URL action
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://pilotcenter.gr/wp-content/plugins/super-forms/uploads/php/files/l40i1jl6iafgsqnbff09s2jnpv/xabevutituvilojak.pdf In PDF document text
- https://dermo.com/wp-content/plugins/formcraft/file-upload/server/content/files/160730e760c87b---47094377279.pdfIn PDF document text
- https://drahmetbostanci.com/wp-content/plugins/formcraft/file-upload/server/content/files/160baecd9e3c0b---50366679581.pdfIn PDF document text
- https://1877painters.com/FCKeditor/file/88467001267.pdfIn PDF document text
- https://cffcommunications.nl/wp-content/plugins/formcraft/file-upload/server/content/files/1/16093a414b4f0c---1532757385.pdfIn PDF document text
- http://kinel-hunter.ru/upfiles/file/pamijojeki.pdfIn PDF document text
- http://hamdard.com/hamdard/app/webroot/img/ckfinder/userfiles/files/42825062590.pdfIn PDF document text
- https://hirurgija.me//files/retudatirejiso.pdfIn PDF document text
- http://www.siscard.com/wp-content/plugins/formcraft/file-upload/server/content/files/160ba048b8376d---19117942841.pdfIn PDF document text
- https://ladychief.com/wp-content/plugins/super-forms/uploads/php/files/209d2f9a9f6df9e83cb17769ad96a9de/27943638766.pdfIn PDF document text
- http://www.awakohchang.com/image/upload/File/473873044.pdfIn PDF document text
- http://alphabodysupplements.com/newerac2c/userfiles/file/ximute.pdfIn PDF document text
- http://famcareconnect.org/wp-content/plugins/formcraft/file-upload/server/content/files/160a645e34afe5---60873019128.pdfIn PDF document text
- https://www.projectorrentals.com/wp-content/plugins/formcraft/file-upload/server/content/files/1608e2f4d8befa---temosopasunasuzu.pdfIn PDF document text
- https://blackknowledge.com/wp-content/plugins/super-forms/uploads/php/files/b662cbedb51e8a135a13455dba323cec/88057207634.pdfIn PDF document text
- https://arnetbilgisayar.com/upload/ckfinder/files/xajixexurajinenota.pdfIn PDF document text
- https://www.asahinafunnels.com/wp-content/plugins/super-forms/uploads/php/files/drq5oqr4b3j8oolpnsscfvkgcr/66245974253.pdfIn PDF document text
- http://www.dnevi-sekretarjev.eu/wp-content/plugins/formcraft/file-upload/server/content/files/16074709551911---92522890691.pdfIn PDF document text
- https://givemeit.ru/wp-content/plugins/super-forms/uploads/php/files/c0900aa07116f7e39a41fedddccfaf59/91356791778.pdfIn PDF document text
- https://feedproxy.google.com/~r/Uplcv/~3/ngfLrbzwjls/uplcv?utm_term=harmonica+lessons+pdfPDF link annotation
Open this report in the interactive analyzer, or submit your own file for analysis.