MALICIOUS
124
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
The PDF document contains numerous links to external websites, many of which are hosted on compromised CMS platforms or disposable domains, indicating a link farm designed to redirect users. ClamAV detection as 'Pdf.Phishing.Trojan' further supports a malicious intent. No scripts were extracted, but the structure and URL patterns suggest a phishing or malware distribution campaign.
Machine Learning
- Nyx PDF Classifier suspicious score 0.3186
Heuristics 5
-
ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
-
PDF link farm points to compromised-WordPress upload storage medium PDF_COMPROMISED_CMS_UPLOAD_LINK_FARMPDF contains multiple clickable links, across many distinct hosts, whose targets are random-slug files parked in the upload directories of vulnerable WordPress form plugins (FormCraft, Super Forms). This is the hallmark of the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains hosted on compromised sites. The PDF itself carries no exploit — the risk is the linked destinations.
-
Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARMSmall PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
-
External URI info PDF_URIPDF contains an external URL action
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://krisoc.ru/uplcv?utm_term=air+force+abbreviation+for+lieutenant+colonel PDF link annotation
- https://adasms.fr/userfiles/file/71057640965.pdfIn PDF document text
- http://bizwd.com/wp-content/plugins/formcraft/file-upload/server/content/files/160bc00c721352---pifuzum.pdfIn PDF document text
- http://www.veronicaneal.com/wp-content/plugins/formcraft/file-upload/server/content/files/1/16099c526b054c---840790658.pdfIn PDF document text
- https://balance-global.com/wp-content/plugins/super-forms/uploads/php/files/d3mmhdiek28pckknt2ejhi0jb9/88203219197.pdfIn PDF document text
- https://bursakaynak.net/userfiles/file/5835091568.pdfIn PDF document text
- https://coil.hk/upload/files/51610327433.pdfIn PDF document text
- https://www.inter-tube.co.uk/wp-content/plugins/super-forms/uploads/php/files/4fc91fb8a2c0acca5e045d9863d99e85/debibebikozunojek.pdfIn PDF document text
- http://alexanderjamesbackcatalogue.com/userfiles/file/17858415385.pdfIn PDF document text
- https://hotelristorantenovecento.it/wp-content/plugins/super-forms/uploads/php/files/2d790ca19868cb1b02698c977a83d73c/zevetexosipezujulasodi.pdfIn PDF document text
- https://akemi.ro/hirek/file/99557739239.pdfIn PDF document text
- http://parkwestresidences.com/wp-content/plugins/formcraft/file-upload/server/content/files/16072cd4e93a6a---72123270081.pdfIn PDF document text
- https://www.vigo.co.za/wp-content/plugins/formcraft/file-upload/server/content/files/160b059dd82486---wopesozenumiwovot.pdfIn PDF document text
- http://www.jhannahs.com/wp-content/plugins/formcraft/file-upload/server/content/files/160838c855f249---pelezumavagurofopanatus.pdfIn PDF document text
- https://www.elektrobetrieb-scholz.de/wp-content/plugins/formcraft/file-upload/server/content/files/160bc7b44423da---vosijawozaratepukatar.pdfIn PDF document text
- https://divorcioconsensual.com.br/wp-content/plugins/super-forms/uploads/php/files/88913d1ad00fe3ead859d202fc2a6e40/4852015425.pdfIn PDF document text
- http://envisystem.com/upload/userfile/files/geloxojogilebomawomuneze.pdfIn PDF document text
- http://bigdoughpizza.com/uploads/files/22764776765.pdfIn PDF document text
- http://adaviestransportltd.com/userfiles/file/48868171954.pdfIn PDF document text
- http://maekuangudomthara.com/ckfinder/userfiles/files/50798339675.pdfIn PDF document text
- http://abwva.com/uploads/files/16072368722.pdfIn PDF document text
- https://soechi.net/userfiles/file/movewux.pdfIn PDF document text
- http://africansafaris-spain.com/FCKeditor/editor/filemanager/connectors/php/connector.php?Command=FileUpload&Type=File&CurrentFolder=%2Ffile/nixenofuriwoxekezuzom.pdfIn PDF document text
- http://www.linkkorea.co.kr/wp-content/plugins/formcraft/file-upload/server/content/files/160cb4c0ce034b---4926463488.pdfIn PDF document text
- https://koratspring.com/upload/file/63572383826.pdfIn PDF document text
- http://hotelbelleepoque.bg/userfiles/file/xegow.pdfIn PDF document text
- https://www.horisunmauritius.com/wp-content/plugins/super-forms/uploads/php/files/da48bf0f4e7c4572ff5d5a34b5c8be59/12117428301.pdfIn PDF document text
Open this report in the interactive analyzer, or submit your own file for analysis.