MALICIOUS
126
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1203 Exploitation for Client Execution
The PDF file contains a large number of links, many of which point to compromised WordPress sites. The ClamAV detection and heuristic firings indicate this is a phishing or trojan distribution attempt. The embedded links are designed to lure users to potentially malicious content hosted on these compromised platforms.
Machine Learning
- Nyx PDF Classifier suspicious score 0.3271
Heuristics 6
-
ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
-
PDF link farm points to compromised-WordPress upload storage medium PDF_COMPROMISED_CMS_UPLOAD_LINK_FARMPDF contains multiple clickable links, across many distinct hosts, whose targets are random-slug files parked in the upload directories of vulnerable WordPress form plugins (FormCraft, Super Forms). This is the hallmark of the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains hosted on compromised sites. The PDF itself carries no exploit — the risk is the linked destinations.
-
Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARMSmall PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
-
External URI info PDF_URIPDF contains an external URL action
-
PDF differential parser failed info PDF_DIFFERENTIAL_PARSE_FAILEDThe cross-check parser (pdfminer.six) failed on this file: PDF differential parser failed: PDFSyntaxError. Static heuristics still ran and any of their findings above are valid; only the differential cross-check signal is missing.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://futuresbuilder.net/dayafter/uploadimages/newsimages/file/57119188584.pdf In PDF document text
- https://lightupalife.org.uk/wp-content/plugins/formcraft/file-upload/server/content/files/160797ce6327ab---buxulovu.pdfIn PDF document text
- https://yziact.fr/wp-content/plugins/super-forms/uploads/php/files/6lnik474da0idmhaejjkiui7do/kafukafokukejirisevimabe.pdfIn PDF document text
- https://www.edutechusa.com/wp-content/plugins/formcraft/file-upload/server/content/files/160aaf69546ea9---33192963449.pdfIn PDF document text
- http://aimecostruzioni.it/userfiles/files/gegixagatewinojevegiwasew.pdfIn PDF document text
- http://erdivigado.hu/userkepek/file/16392574357.pdfIn PDF document text
- https://thejinglelab.com/wp-content/plugins/super-forms/uploads/php/files/9uh099r718ugcen2e22fq7qhkh/64501174153.pdfIn PDF document text
- http://www.gunyagder.org.tr/wp-content/plugins/super-forms/uploads/php/files/tknusvmtv01ijn06cep7eslcm2/98522546526.pdfIn PDF document text
- http://interel-rus.ru/test/sites/default/files/file/96985851512.pdfIn PDF document text
- https://flvirginia.com/wp-content/plugins/super-forms/uploads/php/files/356fdfaa039ba41fc20e8fbfe5c78664/muditewadubesajewosezata.pdfIn PDF document text
- http://hkbroadwin.com/userfiles/61158467420.pdfIn PDF document text
- http://nomorecpapmachine.com/userfiles/files/jixoz.pdfIn PDF document text
- https://trsbarriersdirect.com/wp-content/plugins/super-forms/uploads/php/files/6eflgkfen8kd185r9tnl3oddg3/71561980999.pdfIn PDF document text
- https://www.idromeccanicasrl.com/idromeccanicasrl.com/wp-content/plugins/super-forms/uploads/php/files/57204faa19e0d5ac076e1f77709a1c50/romifuva.pdfIn PDF document text
- https://northstarexecutivesearch.com/wp-content/plugins/super-forms/uploads/php/files/0bd768a61b285c95eb3d57cce68a9ac7/falawi.pdfIn PDF document text
- https://socialacademy.gr/wp-content/plugins/super-forms/uploads/php/files/6b8aecb3f1b6fc0ba1797a8764dd832c/wopodevopixozelujerepow.pdfIn PDF document text
- https://pensionatiitalianiinportogallo.it/wp-content/plugins/super-forms/uploads/php/files/c68bb2a13fda5dc5ff8e49785a9fc551/64627665027.pdfIn PDF document text
- http://www.atrium-tuiles.com/wp-content/plugins/formcraft/file-upload/server/content/files/1609b47c93888e---32382300653.pdfIn PDF document text
- http://www.optionassurance.ca/wp-content/plugins/formcraft/file-upload/server/content/files/1609235dec8953---fosemuropekifukibud.pdfIn PDF document text
- http://qiuyutv.com/userfiles/files/20210624055717.pdfIn PDF document text
- https://study-go.info/wp-content/plugins/super-forms/uploads/php/files/639152d5ede35bba194e0b68d8737ad3/fegalibo.pdfIn PDF document text
- http://www.anjhimayath.com/upload/file/57619954038.pdfIn PDF document text
- http://english-island.pl/wp-content/plugins/super-forms/uploads/php/files/tbvcipfkvk4hfletp0f0sg74n5/losoxoxojulozoraratetu.pdfIn PDF document text
- https://alphaveneers.co.uk/wp-content/plugins/super-forms/uploads/php/files/96a59f010a2ed05e505d053fc71285a4/34085591271.pdfIn PDF document text
- http://24cvety.ru/upload/files/govovotelolevowifav.pdfIn PDF document text
- https://feedproxy.google.com/~r/skout/mBVl/~3/zMnd8XtcwSM/uplcv?utm_term=refeeding+syndrome+and+phosphorusPDF link annotation
- http://dejavu.sourceforge.netIn PDF document text
- http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text
Extracted artifacts 3
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000c0b5.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xC0B5 | 16792 bytes |
SHA-256: 9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1 |
|||
font_01_sfnt_off0000d8c7.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xD8C7 | 16084 bytes |
SHA-256: af0e204541414dcb33ec62a5e06aff5345d7d42115a08c414b075d29d1c74069 |
|||
font_02_sfnt_off0001023d.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x1023D | 11060 bytes |
SHA-256: 904007f300977c50f3dd160151ced67c42f0f540897f7bba9f6a25fc1e7a471b |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.