MALICIOUS
164
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
The file was detected as malicious by ClamAV and an ML classifier, indicating a high likelihood of malicious intent. The presence of numerous links pointing to compromised CMS uploads and disposable hosting suggests a link farm designed to distribute further malicious content or phish users. Although no scripts were explicitly extracted, the PDF structure and embedded URLs are indicative of a malicious document, likely used as a lure for spearphishing.
Machine Learning
- Nyx PDF Classifier malicious score 0.9927
Heuristics 7
-
ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
-
PDF link farm points to compromised-WordPress upload storage medium PDF_COMPROMISED_CMS_UPLOAD_LINK_FARMPDF contains multiple clickable links, across many distinct hosts, whose targets are random-slug files parked in the upload directories of vulnerable WordPress form plugins (FormCraft, Super Forms). This is the hallmark of the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains hosted on compromised sites. The PDF itself carries no exploit — the risk is the linked destinations.
-
Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARMSmall PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
-
Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTONDocument contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL http://mouaumfb.com/wp-content/plugins/formcraft/file-upload/server/content/files/160bdc86975ea6---pebijezowunuk.pdf
- https://emilline.dk/ckfinder/userfiles/files/vajazetilibuguzizuz.pdf
- https://leicht-spb.ru/wp-content/plugins/super-forms/uploads/php/files/338ff6d926e89b24cf3bcf88cc64ec4a/53812000318.pdf
- https://earthideasawnings.com/wp-content/plugins/formcraft/file-upload/server/content/files/160a926d69fac7---bogiraxuxupazezenumuve.pdf
- http://www.thediethub.in/wp-content/plugins/formcraft/file-upload/server/content/files/160982a46a9f58---xerukifunikuz.pdf
- http://trackeg.com/en/wp-content/plugins/formcraft/file-upload/server/content/files/160877ff56c365---72784241064.pdf
- http://quickfix-poland.com/wp-content/plugins/formcraft/file-upload/server/content/files/160ac6c07aa68e---rirupi.pdf
- https://givemeit.ru/wp-content/plugins/super-forms/uploads/php/files/ccb3c78b7fbbb1ec07c53540e31a433e/naguzeluvexukezuregopo.pdf
- https://sidexsideaudio.com/wp-content/plugins/formcraft/file-upload/server/content/files/1609ab06cd682d---38441740805.pdf
- http://asirius.su/wp-content/plugins/super-forms/uploads/php/files/18bc013165b65cd63d0a15a845439454/pejizofa.pdf
- http://shopcloud.cloud//ckfinder/userfiles/files/20077672202.pdf
- https://www.helpfulhunks.com.au/wp-content/plugins/formcraft/file-upload/server/content/files/1607f6a6a13a91---88135134988.pdf
- http://3handseg.com/wp-content/plugins/formcraft/file-upload/server/content/files/1608c10e7c35a4---julil.pdf
- http://serendipityorlando.com/wp-content/plugins/formcraft/file-upload/server/content/files/160c40641070f6---80206962029.pdf
- http://www.sparkprototypes.com/wp-content/plugins/formcraft/file-upload/server/content/files/160945ff33c401---9921620630.pdf
- http://www.asejnrtigers.co.uk/wp-content/plugins/formcraft/file-upload/server/content/files/160adb57d37052---wuwadumosu.pdf
- http://auburn-properties.com/userfiles/files/12754100083.pdf
- https://refour.dk/wp-content/plugins/super-forms/uploads/php/files/c20a163ccdd38eb1d18692223ace2269/bixuwalulukam.pdf
- http://www.medical-psychology.gr/wp-content/plugins/formcraft/file-upload/server/content/files/160c8861b106a4---segelomaneragosadilani.pdf
- http://israel-aliya.com/wp-content/plugins/super-forms/uploads/php/files/4c4834e2aa2c7c2142a0a8ea90ea0954/62786191582.pdf
- http://le-lemniscus-incandescent.fr/ckeditor/upload/files/zobixefopubupoziko.pdf
- http://c2mag.com/wp-content/plugins/formcraft/file-upload/server/content/files/1607a5a775330e---63232705307.pdf
- https://www.mclarenpress.com/wp-content/plugins/formcraft/file-upload/server/content/files/16089229216516---58173654516.pdf
- https://feedproxy.google.com/~r/skout/mBVl/~3/YTWXjIUwRh0/uplcv?utm_term=practicing+the+power+of+now+pdf+download
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://dejavu.sourceforge.net
- http://dejavu.sourceforge.net/wiki/index.php/License
Extracted artifacts 4
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000f49e.bin1433fded29aae041a3fd2a7c201252c8006738d9b88bdf90fb1975ecd3ac5d65 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xF49E | 17004 bytes |
font_01_sfnt_off00010d2e.bin3ce81dbda128a740ea4eb53f9e5aa875ad13b7b3b912584a5f09d14967c14437 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x10D2E | 10820 bytes |
font_02_sfnt_off000125e5.bin703edd1d49e894739a9c993c7e97915b82cf9a2f0e89e8823a1d18fcd1f78a2c |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x125E5 | 17172 bytes |
font_03_sfnt_off00015244.bin9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x15244 | 16792 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.