MALICIOUS
134
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
This PDF was detected as malicious by ClamAV and an ML classifier, indicating a high likelihood of malicious intent. The presence of numerous links pointing to compromised WordPress sites suggests a phishing or malware distribution campaign. The heuristic 'SE_URGENCY_LURE' indicates the document likely uses time-sensitive language to prompt user action, further supporting a phishing attack pattern.
Machine Learning
- Nyx PDF Classifier malicious score 0.7293
Heuristics 6
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
PDF link farm points to compromised-WordPress upload storage medium PDF_COMPROMISED_CMS_UPLOAD_LINK_FARMPDF contains multiple clickable links, across many distinct hosts, whose targets are random-slug files parked in the upload directories of vulnerable WordPress form plugins (FormCraft, Super Forms). This is the hallmark of the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains hosted on compromised sites. The PDF itself carries no exploit — the risk is the linked destinations.
-
Urgency / deadline lure low SE_URGENCY_LUREDocument contains urgency or deadline language ('account will be terminated', 'action required within 24 hours', etc.) — useful context, but low-signal without other findings
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://pistant.ru/uplcv?utm_term=tooth+108+dog PDF link annotation
- https://grafitpoint.ru/wp-content/plugins/super-forms/uploads/php/files/93fb0b0cfa913c6f63b216eb07b70120/17492460423.pdfIn PDF document text
- https://hcs1000.org/wp-content/plugins/super-forms/uploads/php/files/6eb5c4ddabc69afc994c162fd61ec6df/kunofoparemipup.pdfIn PDF document text
- http://thefutureofgolf.eu/wp-content/plugins/formcraft/file-upload/server/content/files/160aab640876c6---makirowiromizenolos.pdfIn PDF document text
- http://sad-azov.ru/wp-content/plugins/super-forms/uploads/php/files/2f4e43c3abf4ed0d5259d89e8bb034b5/dapofowowasasiz.pdfIn PDF document text
- http://accomplishtheimpossible.com/userfiles_ati/file/18936686118.pdfIn PDF document text
- http://antwerp-rentals.com/wp-content/plugins/formcraft/file-upload/server/content/files/160a0f06be323d---sugis.pdfIn PDF document text
- https://www.schroedersales.com/wp-content/plugins/super-forms/uploads/php/files/ba49193d4adb9c2fdc56af12574eb4d7/38665214779.pdfIn PDF document text
- http://www.nandomoraes.com.br/wp-content/plugins/formcraft/file-upload/server/content/files/1609841cc4d7eb---pivug.pdfIn PDF document text
- http://kaufdeinauto.de/wp-content/plugins/formcraft/file-upload/server/content/files/1607ead68a2a30---11308106126.pdfIn PDF document text
- https://winston-woodward.com/wp-content/plugins/super-forms/uploads/php/files/ea62ee97da2b0f20c5fc1bbe9189e8c3/luwinokekolewufunumuwewu.pdfIn PDF document text
- http://lezeckastenakosice.sk/upload/files/gezuvilabuzatitawow.pdfIn PDF document text
- https://www.hotel-palladium.gr/wp-content/plugins/super-forms/uploads/php/files/c04vq1ppj02ekur3r8h76i7ehm/pulur.pdfIn PDF document text
- http://www.zulfugar.nl/wp-content/plugins/formcraft/file-upload/server/content/files/1606e310fd27db---9669912806.pdfIn PDF document text
- https://neavocats.com/wp-content/plugins/super-forms/uploads/php/files/6745a84d8dd333e684fed15b8d060f83/fepexitidowopitipudebe.pdfIn PDF document text
- http://automotiveenergy.cz/userfiles/file/nokarowexed.pdfIn PDF document text
- https://414movement.com/wp-content/plugins/super-forms/uploads/php/files/a6e2476e134d27e5f013ed6fa9a2c62c/47505243887.pdfIn PDF document text
- http://anpo.vn/upload/files/paxasobufi.pdfIn PDF document text
- http://veronicanealhome.com/wp-content/plugins/formcraft/file-upload/server/content/files/2/1607575d22dab6---93099494552.pdfIn PDF document text
- http://www.fotografoeventimilano.com/wp-content/plugins/formcraft/file-upload/server/content/files/16093a391e8889---37045399445.pdfIn PDF document text
- http://orderkai.com/uploads/files/pabimetapiw.pdfIn PDF document text
- http://okeefesreef.com/ckfinder/userfiles/files/9839054880.pdfIn PDF document text
- https://teenvolunteerdallas.org/wp-content/plugins/super-forms/uploads/php/files/89bb92ecb6efafa6d68c3624052bf9f2/1904537727.pdfIn PDF document text
- http://verkoop-je-wagen.be/wp-content/plugins/formcraft/file-upload/server/content/files/1609bcb382349d---sirojuvanepebetiruxes.pdfIn PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/xap/1.0/rights/In PDF document text
- http://dejavu.sourceforge.netIn PDF document text
- http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text
Extracted artifacts 3
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off000708d5.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x708D5 | 16792 bytes |
SHA-256: 9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1 |
|||
font_01_sfnt_off000720ec.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x720EC | 10068 bytes |
SHA-256: aba9d4d3b28dc85dc64e822b27a73165362ab756e888ed2e653e76034657032d |
|||
font_02_sfnt_off0007373f.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x7373F | 21300 bytes |
SHA-256: 41b13247a558c6504b6e8e54b70a5a5877b77f9274a7ca2b0c37f940a81119cd |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.