MALICIOUS
154
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
The sample is a PDF document identified as malicious by ClamAV and an ML classifier. It contains numerous embedded URLs, many pointing to compromised WordPress sites, suggesting it functions as a link farm to distribute phishing or malware. The PDF_SEO_DISPOSABLE_LINK_FARM heuristic indicates a pattern of using disposable hosting for these links. No scripts were extracted from this sample, but the overall structure and heuristics point to a malicious intent to redirect users to potentially harmful external sites.
Machine Learning
- Nyx PDF Classifier malicious score 0.8987
Heuristics 5
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
PDF link farm points to compromised-WordPress upload storage medium PDF_COMPROMISED_CMS_UPLOAD_LINK_FARMPDF contains multiple clickable links, across many distinct hosts, whose targets are random-slug files parked in the upload directories of vulnerable WordPress form plugins (FormCraft, Super Forms). This is the hallmark of the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains hosted on compromised sites. The PDF itself carries no exploit — the risk is the linked destinations.
-
Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARMSmall PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
-
External URI info PDF_URIPDF contains an external URL action
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL http://www.onegelha.com/wp-content/plugins/super-forms/uploads/php/files/73a1168e301e069fd03990414c707a79/mozuxotoxasikomijiru.pdf In PDF document text
- https://t2sc.me/userfiles/givafilodusi.pdfIn PDF document text
- https://audreyheselmans.com/_files/file/98437854525.pdfIn PDF document text
- http://www.northeastmarquees.com/wp-content/plugins/super-forms/uploads/php/files/9e352b888150bffebd86490e2619a87a/falav.pdfIn PDF document text
- http://24cvety.ru/upload/files/56399808928.pdfIn PDF document text
- http://cuatro-pr.org/sites/default/files/file/faboj.pdfIn PDF document text
- http://visualpaint.com/wp-content/plugins/formcraft/file-upload/server/content/files/160bb03d53de35---51386100618.pdfIn PDF document text
- https://dezsredstvompx.ru/wp-content/plugins/super-forms/uploads/php/files/f732abc441cef6ad4aab5fa2821c8a9b/xaxawebobinana.pdfIn PDF document text
- https://medicentrumnz.eu/medicentrum/files/file/jitapatimogeburez.pdfIn PDF document text
- https://www.crossfitparamaribo.com/wp-content/plugins/formcraft/file-upload/server/content/files/160c663dac6299---77415335158.pdfIn PDF document text
- https://www.hauptsache.cc/wp-content/plugins/formcraft/file-upload/server/content/files/160e8cb71db604---vinamunuk.pdfIn PDF document text
- http://xn--e1aaafipco3bk8gra3b.xn--p1ai/upload_picture/file/91194739476.pdfIn PDF document text
- http://akkoryazilim.com/userfiles/file/vebamoliwebaxasexale.pdfIn PDF document text
- https://fitness-sport.it/userfiles/file/gijorofobigumupowukolote.pdfIn PDF document text
- https://amezdigital.com/wp-content/plugins/super-forms/uploads/php/files/cabc20404755ec10abff1ca338d3658f/ludotezir.pdfIn PDF document text
- https://digireg.li/upload/lalazedodaratezukatewiwum.pdfIn PDF document text
- http://www.alexgis.com/siteuploads/editorimg/file/famener.pdfIn PDF document text
- https://dbjadow.pl/attachments/file/bowifirif.pdfIn PDF document text
- https://www.gml.de/wp-content/plugins/formcraft/file-upload/server/content/files/1608f47220939b---25439917964.pdfIn PDF document text
- https://metroguards.com.au/wp-content/plugins/formcraft/file-upload/server/content/files/16075aed898fd1---41726540116.pdfIn PDF document text
- https://webhostmurah.com/wp-content/plugins/formcraft/file-upload/server/content/files/1606fe2ce44852---kisunivasuwevutiwiwapuwix.pdfIn PDF document text
- https://humantouchtranslations.com/wp-content/plugins/formcraft/file-upload/server/content/files/1/1607fc50d34d9b---72234570573.pdfIn PDF document text
- https://sygimportaciones.com/wp-content/plugins/super-forms/uploads/php/files/4f91jcip40l8pb9h0da62makdr/vazitasewanev.pdfIn PDF document text
- http://danburyhighclassof1961.com/clients/b/b4/b42d7d7907ff1a67dd6fd366dd3c6775/File/gamin.pdfIn PDF document text
- http://a-range.ru/wp-content/plugins/formcraft/file-upload/server/content/files/160988300db1f6---14756865229.pdfIn PDF document text
- https://feedproxy.google.com/~r/Uplcv/~3/ngfLrbzwjls/uplcv?utm_term=actividades+de+primer+grado+de+secundaria+matematicasPDF link annotation
Open this report in the interactive analyzer, or submit your own file for analysis.