MALICIOUS
162
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
The sample contains embedded JavaScript, which is a common technique for executing malicious code within PDFs. It also features a link farm pointing to compromised WordPress sites, suggesting an attempt to redirect users to malicious content. The ClamAV detection and ML classifier further support its malicious nature, likely as a phishing or malware delivery mechanism.
Machine Learning
- Nyx PDF Classifier malicious score 0.8131
Heuristics 6
-
ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
-
PDF link farm points to compromised-WordPress upload storage medium PDF_COMPROMISED_CMS_UPLOAD_LINK_FARMPDF contains multiple clickable links, across many distinct hosts, whose targets are random-slug files parked in the upload directories of vulnerable WordPress form plugins (FormCraft, Super Forms). This is the hallmark of the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains hosted on compromised sites. The PDF itself carries no exploit — the risk is the linked destinations.
-
Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARMSmall PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
-
Embedded JS stream low PDF_JSPDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
-
External URI info PDF_URIPDF contains an external URL action
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://nomylo.ru/uplcv?utm_term=electrical+measurements+and+measuring+instruments+books+pdf+free+download PDF link annotation
- https://pinotcar.com/wp-content/plugins/super-forms/uploads/php/files/9792e3fd89b5b9c4b835c313b7d59a4c/lejekevijogin.pdfIn PDF document text
- https://www.enviedecrire.com/wp-content/plugins/formcraft/file-upload/server/content/files/160c6fd4641b98---79536314883.pdfIn PDF document text
- http://sochi-riba.ru/ckfinder/userfiles/files/dutakatisusotuvagefere.pdfIn PDF document text
- http://whkmradio.com/userfiles/file/82982278108.pdfIn PDF document text
- https://www.ogblfrontaliers.fr/wp-content/plugins/super-forms/uploads/php/files/cs7segr3mi9vpntogah4e7a8d2/simetitedugajaj.pdfIn PDF document text
- http://www.sunargrup.com.tr/wp-content/plugins/super-forms/uploads/php/files/fntrjlhk8b0d2obhf7gsuaans3/fiwitapusamewudisiju.pdfIn PDF document text
- http://vasilii-orlov.fun/wp-content/plugins/super-forms/uploads/php/files/8bba7031881ad1df866f7e880fa50b2d/sikekepojowuxarokomam.pdfIn PDF document text
- https://mymovingestimate.com/wp-content/plugins/super-forms/uploads/php/files/6fc321ec5776aa41ecfb7e6bbedcac87/falokapumarud.pdfIn PDF document text
- http://texasstatealphaxialumnae.com/clients/f/fe/fe72632f573fdc77cca6b85875c63e8a/File/25124992462.pdfIn PDF document text
- http://eros-arena.com/eros/userfiles/file/18207893956.pdfIn PDF document text
- http://garagehayashi.com/js/upload/files/vavibatilubiguladudasabu.pdfIn PDF document text
- http://viaterrestre.com.br/wp-content/plugins/formcraft/file-upload/server/content/files/160765092e7582---9603742694.pdfIn PDF document text
- http://pc-driver.ru/userfiles/files/rewoxefu.pdfIn PDF document text
- http://laweasy.kr/userfiles/file/teduraveligexoli.pdfIn PDF document text
- http://chalappuram.com/userfiles/file/mitenede.pdfIn PDF document text
- https://xlspandoek.nl/userfiles/file/lobapinobizi.pdfIn PDF document text
- https://www.tangelo.no/wp-content/plugins/formcraft/file-upload/server/content/files/1608d5bf301881---95740882228.pdfIn PDF document text
- http://rheinmotel.com/userfiles/file/39059380427.pdfIn PDF document text
- https://amirep.com/wp-content/plugins/super-forms/uploads/php/files/b115fbbe5bb93f8394161f9dcc4eb14a/98123789964.pdfIn PDF document text
- http://dj-venci.com/uploads/pages/files/ramujivedafesero.pdfIn PDF document text
- http://piazzademarini3ge.com/userfiles/files/26384785310.pdfIn PDF document text
- https://istocdukkan.com/userfiles/files/28183802065.pdfIn PDF document text
- http://manisafar.com/basefile/marcosafarir/files/xugudekazawijukebizu.pdfIn PDF document text
- http://cuahuyhoang.com/media/ftp/file/gebafubabafagazuviwun.pdfIn PDF document text
- http://pvsystreports.com/wp-content/plugins/super-forms/uploads/php/files/019rqjj3bce81cusfk9r7fb9i0/13407852283.pdfIn PDF document text
- http://pizzeria-millemiglia.de/app/webroot/img/editor/file/10864596470.pdfIn PDF document text
- http://studioarchoggianiepartners.it/userfiles/files/kuxadobezunadinemokoposos.pdfIn PDF document text
- http://dejavu.sourceforge.netIn PDF document text
- http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text
Extracted artifacts 1
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000df3e.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xDF3E | 17476 bytes |
SHA-256: 67d2b9f8b954dff406618b28373bcbb0e688de80afba6c9cf618b59efae0d555 |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.