MALICIOUS
156
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1204.002 Malicious Link
The ML classifier and ClamAV detection strongly indicate maliciousness. The PDF contains numerous links, many pointing to compromised CMS uploads, suggesting a tactic to disguise malicious destinations. The document body is unreadable, but the heuristics and URLs indicate a likely phishing or malware distribution attempt.
Machine Learning
- Nyx PDF Classifier malicious score 0.9916
Heuristics 6
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
PDF link farm points to compromised-WordPress upload storage medium PDF_COMPROMISED_CMS_UPLOAD_LINK_FARMPDF contains multiple clickable links, across many distinct hosts, whose targets are random-slug files parked in the upload directories of vulnerable WordPress form plugins (FormCraft, Super Forms). This is the hallmark of the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains hosted on compromised sites. The PDF itself carries no exploit — the risk is the linked destinations.
-
Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARMSmall PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL http://www.oschouston.com/osc/wp-content/plugins/formcraft/file-upload/server/content/files/1608242efe9248---kefimuxexodo.pdf
- http://baschin-heizung.com/meineBilderAlbertGrundschule/file/51801169172.pdf
- http://gamax-motor.cz/data/dokumenty/renino.pdf
- https://humanistbeauty.com/wp-content/plugins/super-forms/uploads/php/files/ub1o0g4986dpdc8dr4sm6ji5q9/32314781966.pdf
- http://chocoenglish.com/_UploadFile/Images/file/gafedepepe.pdf
- https://www.vedaaz.com/wp-content/plugins/super-forms/uploads/php/files/10c65df75c0ec781db13d7eed2e4dc52/66219168210.pdf
- http://associacaoguainumbi.org.br/wp/wp-content/plugins/formcraft/file-upload/server/content/files/16078050af0deb---59124219592.pdf
- http://jingluo.net/uploadfiles/files/tusarasuz.pdf
- http://www.loockuniformes.com.br/home/wp-content/plugins/formcraft/file-upload/server/content/files/1606c6a6bdc5d4---65925752405.pdf
- http://klingende-zeder.de/wp-content/plugins/formcraft/file-upload/server/content/files/1609c1e14d1dbd---22444204100.pdf
- http://ekolojikweb.net/upld/userfiles/file/56182915347.pdf
- http://www.iamgoingto1996.com/wp-content/plugins/formcraft/file-upload/server/content/files/160c159849860f---64593055421.pdf
- https://georgiamusicpartners.org/wp-content/plugins/super-forms/uploads/php/files/ecf79f9f09e0042139af1397a870e5a2/xemixumufumewik.pdf
- https://gofropack.com/wp-content/plugins/super-forms/uploads/php/files/c3a5d0045b80b74ac42432803c726f46/55332024700.pdf
- http://israel-aliya.com/wp-content/plugins/super-forms/uploads/php/files/3c49992982587be72fa00e7d5f6c043b/dolofewugaronuwukapapa.pdf
- https://www.alignerco.ca/wp-content/plugins/super-forms/uploads/php/files/d93ea5ba355e48af2a1ca2343bcd8940/85358378225.pdf
- https://greshamgilessalon.com/wp-content/plugins/super-forms/uploads/php/files/69a63ec6481e33f50a3428cee4628c4e/77106540946.pdf
- http://www.niziointerior.pl/upload/file/47287393630.pdf
- https://auf.vn/wp-content/plugins/super-forms/uploads/php/files/5bme1dri8t176kh469thfvr5o4/21166372572.pdf
- https://www.adcgrain.com/wp-content/plugins/super-forms/uploads/php/files/b807af0e8d5254d9e40233f2bce83a1d/24353880817.pdf
- https://www.qlsny.com/wp-content/plugins/super-forms/uploads/php/files/e21d0b620254aeea9e13fde595e10ed5/79705154984.pdf
- https://deewo.de/wp-content/plugins/formcraft/file-upload/server/content/files/160926a3f34a26---36456728920.pdf
- http://localhomesales.com.au/wp-content/plugins/formcraft/file-upload/server/content/files/16074b95265033---wogolowewadiwu.pdf
- http://xperion.hu/wp-content/plugins/super-forms/uploads/php/files/5a36932ecce3cd64070ab60af2612698/fapibonupe.pdf
- https://feedproxy.google.com/~r/Uplcv/~3/1xuhb7AK25c/uplcv?utm_term=the+great+white+silence
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://dejavu.sourceforge.net
- http://dejavu.sourceforge.net/wiki/index.php/License
Extracted artifacts 3
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0001a917.bin9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x1A917 | 16792 bytes |
font_01_sfnt_off0001c12e.binae0ccc038553b1063fb43c5d98a55a9064abd721f834bc6391f733666e80b044 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x1C12E | 10436 bytes |
font_02_sfnt_off0001d8dc.bin55ee70f550c4995e06f24ab15c1d90fe24242c95ace4cdfb8143172af2ed8e8f |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x1D8DC | 18188 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.