MALICIOUS
154
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF contains numerous links, many pointing to compromised WordPress sites and disposable hosting, suggesting a link farm or SEO poisoning attack. The presence of 'utm_term' in one URL indicates a potential phishing lure. ClamAV detection and ML classification confirm maliciousness, with the PDF being identified as a phishing trojan.
Machine Learning
- Nyx PDF Classifier malicious score 0.9954
Heuristics 5
-
ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
-
PDF link farm points to compromised-WordPress upload storage medium PDF_COMPROMISED_CMS_UPLOAD_LINK_FARMPDF contains multiple clickable links, across many distinct hosts, whose targets are random-slug files parked in the upload directories of vulnerable WordPress form plugins (FormCraft, Super Forms). This is the hallmark of the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains hosted on compromised sites. The PDF itself carries no exploit — the risk is the linked destinations.
-
Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARMSmall PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
-
External URI info PDF_URIPDF contains an external URL action
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://pistant.ru/uplcv?utm_term=car+parking+multiplayer+mod+apk+for+iphone
- https://www.andyselfstorage.co.uk/wp-content/plugins/super-forms/uploads/php/files/9end5tuobor63pdoueakek58ps/wisetutuk.pdf
- http://www.restorationservice.ca/wp-content/plugins/formcraft/file-upload/server/content/files/160a8e3f29e04b---85522959273.pdf
- https://securityguardsupply.org/php/uploads/file/dopavajexevu.pdf
- https://deewo.de/wp-content/plugins/formcraft/file-upload/server/content/files/160aa159e91057---zozadonenafeduzexabezaguj.pdf
- http://albatrossmrn.com/konadnew/userfiles/file/42281990672.pdf
- http://famcareconnect.org/wp-content/plugins/formcraft/file-upload/server/content/files/1606cdcf3cf9fd---xibuxezokezelifinozaj.pdf
- https://sk-developers.com/wp-content/plugins/formcraft/file-upload/server/content/files/1606f27ebeeab7---mujegixurijug.pdf
- https://www.ideaklinik.com.tr/wp-content/plugins/formcraft/file-upload/server/content/files/1606d40d145c8c---30109754643.pdf
- http://www.onekaddy.com/wp-content/plugins/formcraft/file-upload/server/content/files/1607a9298da668---wotupopujedejipuxijalor.pdf
- http://middlegeorgiacoinclub.com/wp-content/plugins/formcraft/file-upload/server/content/files/1608e127966378---23601561532.pdf
- https://lakeshoresmilesdentistry.com/wp-content/plugins/super-forms/uploads/php/files/ng97jvkigjqsmvt1ijf3278a93/bozusulepafil.pdf
- https://encoregallery.us/wp-content/plugins/super-forms/uploads/php/files/24a2e1f3612ec419a5caf71ebefa9c93/50457708061.pdf
- http://steclotildehorton.ca/wp-content/plugins/formcraft/file-upload/server/content/files/16085d8b840a02---16624589261.pdf
- https://traveltokiev.com/wp-content/plugins/super-forms/uploads/php/files/6pvgupt7gs4jmnoaor1ecveqg5/95577489722.pdf
- https://xn--64-mlcufjjaii0l.xn--p1ai/wp-content/plugins/super-forms/uploads/php/files/75ae8d3d39153c6f500473c42b0359a7/bijekarupadikez.pdf
- https://www.properties-thassos.com/wp-content/plugins/super-forms/uploads/php/files/5m6es24lkbnqnmmlrvr2u4fv0j/rosona.pdf
- https://sonarmusic.hu/up_image/file/39962175851.pdf
- https://absolut-fit-and-dance.de/wp-content/plugins/super-forms/uploads/php/files/km9uj4knav3antvvvuumfpcj1r/sineveloki.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- http://scripts.sil.org/OFL
Extracted artifacts 1
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000e0f5.bin6a82873c7fcdd2459d3a578e5f9409fae8e772ec1a267d26f787f3d8f60faf33 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xE0F5 | 5348 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.