MALICIOUS
154
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
This PDF document is identified as malicious by ClamAV and an ML classifier, indicating it is likely a phishing or trojan delivery mechanism. It contains numerous links to compromised WordPress upload directories, suggesting it is part of a link farm designed to redirect users to malicious content. The document body, though heavily obfuscated, contains metadata related to 'wkhtmltopdf' and a calculator lure, reinforcing the phishing pretext.
Machine Learning
- Nyx PDF Classifier malicious score 0.6232
Heuristics 5
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
PDF link farm points to compromised-WordPress upload storage medium PDF_COMPROMISED_CMS_UPLOAD_LINK_FARMPDF contains multiple clickable links, across many distinct hosts, whose targets are random-slug files parked in the upload directories of vulnerable WordPress form plugins (FormCraft, Super Forms). This is the hallmark of the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains hosted on compromised sites. The PDF itself carries no exploit — the risk is the linked destinations.
-
Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARMSmall PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
-
External URI info PDF_URIPDF contains an external URL action
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://oniceh.ru/uplcv?utm_term=finding+missing+angles+in+triangles+calculator PDF link annotation
- https://flycam.com.tr/wp-content/plugins/formcraft/file-upload/server/content/files/160c7254f45540---58900969449.pdfIn PDF document text
- http://www.rolstoellift.com/wp-content/plugins/formcraft/file-upload/server/content/files/160c6933997ebe---rigozabazibuwedosubib.pdfIn PDF document text
- https://messianic.live/wp-content/plugins/super-forms/uploads/php/files/f87dd6cc550d559577d4e895341f4378/4236268575.pdfIn PDF document text
- http://www.kzhep.in.ua/wp-content/plugins/super-forms/uploads/php/files/3rrglrr4kgak98blaouoebo6d6/94734536029.pdfIn PDF document text
- https://hcs1000.org/wp-content/plugins/super-forms/uploads/php/files/1f45064855a4cf2a697e18aa803c482a/riwerifipasaxa.pdfIn PDF document text
- http://deckdreams.ca/clients/3/34/34055ef41782f8f15ebf372c1e39ecad/File/voligemonoduliduxukivuv.pdfIn PDF document text
- https://seitonsolutions.com/ci/files/fowapufitonenedu.pdfIn PDF document text
- https://bettenbaehren.de/wp-content/plugins/formcraft/file-upload/server/content/files/16087ca6f630c2---98610314991.pdfIn PDF document text
- https://bayardplaza.co.uk/wp-content/plugins/super-forms/uploads/php/files/nsvbbuv56vt49eqsfqdvmojsit/39757209497.pdfIn PDF document text
- http://jointrilogy.com/wp-content/plugins/formcraft/file-upload/server/content/files/1606d4d57845bf---29938669086.pdfIn PDF document text
- http://www.1000ena.com/wp-content/plugins/formcraft/file-upload/server/content/files/160b6e2c5dadf1---pijuz.pdfIn PDF document text
- http://drvision.org/wp-content/plugins/formcraft/file-upload/server/content/files/160b25563274f7---mozasivi.pdfIn PDF document text
- http://pulsrmedia.com/wp-content/plugins/formcraft/file-upload/server/content/files/160722d9157f62---giledumalowidoxi.pdfIn PDF document text
- https://jdbailbonds.com/wp-content/plugins/super-forms/uploads/php/files/0885d0ab6fbda6dd2403f1d41cee3ab2/78341007647.pdfIn PDF document text
- http://hanleyresources.com/images/megalakofopekigeji.pdfIn PDF document text
Open this report in the interactive analyzer, or submit your own file for analysis.