MALICIOUS
124
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
The file is a PDF document that contains a large number of links pointing to various websites, many of which appear to be compromised or disposable hosting. The ClamAV detection indicates this is a phishing trojan. The heuristic firings suggest the PDF is acting as a link farm, likely to redirect users to malicious sites for phishing or malware delivery.
Machine Learning
- Nyx PDF Classifier suspicious score 0.3806
Heuristics 5
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
PDF link farm points to compromised-WordPress upload storage medium PDF_COMPROMISED_CMS_UPLOAD_LINK_FARMPDF contains multiple clickable links, across many distinct hosts, whose targets are random-slug files parked in the upload directories of vulnerable WordPress form plugins (FormCraft, Super Forms). This is the hallmark of the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains hosted on compromised sites. The PDF itself carries no exploit — the risk is the linked destinations.
-
Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARMSmall PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
-
External URI info PDF_URIPDF contains an external URL action
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://archism.ru/uplcv?utm_term=how+to+find+maximum+velocity+on+a+velocity+time+graph PDF link annotation
- https://m-co.de/wp-content/plugins/super-forms/uploads/php/files/3o5edvkkvbavndsjg50u3msv9u/wekozadefaxebirivom.pdfIn PDF document text
- https://www.olympusnorge.no/wp-content/plugins/super-forms/uploads/php/files/dib325ljtbne859n4kj5qhf3ht/xutiwanixivivefulaxo.pdfIn PDF document text
- https://g-ortho.com.br/wp-content/plugins/formcraft/file-upload/server/content/files/160be5f32c88aa---lazuguragekegabagov.pdfIn PDF document text
- https://www.hauptsache.cc/wp-content/plugins/formcraft/file-upload/server/content/files/1608ced5c51aee---desaterebevibanisesi.pdfIn PDF document text
- http://perfekttorun.pl/pliki/81911362612.pdfIn PDF document text
- https://sunwayhk.com/louis/STARKGROUP/ckfinder/userfiles/files/butagovumojanugi.pdfIn PDF document text
- http://dlt-nkp.com/fileupload//file/7809183109.pdfIn PDF document text
- http://skikk.nl/app/webroot/files/userfiles/files/46043745341.pdfIn PDF document text
- https://bindazzled.com.au/wp-content/plugins/super-forms/uploads/php/files/fcc712cebb0c5a5792166140ca8ed5b9/webekexereninulaxabovaxe.pdfIn PDF document text
- https://businessincasey.com.au/application/third_party/ckfinder/userfiles/files/lumeso.pdfIn PDF document text
- https://advancedbusiness.co/wp-content/plugins/super-forms/uploads/php/files/e687d848d2708246fd2e686e4d9c40d0/fisonemeruwuver.pdfIn PDF document text
- http://championshipsportsrings.com/clients/23492/File/wadunow.pdfIn PDF document text
- https://gpagroup.in/wp-content/plugins/formcraft/file-upload/server/content/files/16076111d83a76---vikobukipusijekapogozeli.pdfIn PDF document text
- https://szallas-karpatalja.net/upload/99387453790.pdfIn PDF document text
- http://grani-tonkogo-mira.ru/wp-content/plugins/super-forms/uploads/php/files/62b8b2c14494043faea6aca37ca8941c/podefomap.pdfIn PDF document text
- http://rubensova16.cz/files/file/xajula.pdfIn PDF document text
- http://www.microsinusectomi.com/wp-content/plugins/formcraft/file-upload/server/content/files/160784bd0c88ab---8496545916.pdfIn PDF document text
- http://suachuathietbi.com/upload/files/85931131901.pdfIn PDF document text
- http://hurtowniagrafit.pl/userfiles/file/zebisajugudetobosatob.pdfIn PDF document text
- https://conexusinternational.com/ckfinder/userfiles/file/bunusumotisalimikilis.pdfIn PDF document text
- https://xn--80aaaglcftt5alesfkk7f.xn--p1ai/wp-content/plugins/super-forms/uploads/php/files/09bc0ae3afc72e501ba2fd675fea79a2/83353071929.pdfIn PDF document text
- http://technoculture.cz/admin/upload/file/duruwifamemavozanodosopo.pdfIn PDF document text
- https://fundacionamigosdelmarcaribe.ong/ckfinder/userfiles/files/35041166978.pdfIn PDF document text
- https://jbdclothiers.net/emailer/userfiles/file/xibiwezaj.pdfIn PDF document text
- https://serviceservice.eu/userfiles/file/35325798601.pdfIn PDF document text
Open this report in the interactive analyzer, or submit your own file for analysis.