MALICIOUS
126
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1203 Exploitation for Client Execution
The file was detected as malicious by a ML classifier and ClamAV, indicating a high likelihood of malicious intent. It contains numerous links, with at least one pointing to a compromised WordPress upload storage, suggesting it's used to redirect users to malicious sites. The PDF structure and embedded links are consistent with phishing or malware distribution campaigns.
Machine Learning
- Nyx PDF Classifier malicious score 0.9852
Heuristics 5
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
PDF link farm points to compromised-WordPress upload storage medium PDF_COMPROMISED_CMS_UPLOAD_LINK_FARMPDF contains multiple clickable links, across many distinct hosts, whose targets are random-slug files parked in the upload directories of vulnerable WordPress form plugins (FormCraft, Super Forms). This is the hallmark of the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains hosted on compromised sites. The PDF itself carries no exploit — the risk is the linked destinations.
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://biocoils.com/img/file/56213249436.pdf
- https://www.chinacimctrailer.com/wp-content/plugins/super-forms/uploads/php/files/84369adc5b96a864c707b241de3303b2/40794660834.pdf
- https://www.mclarenpress.com/wp-content/plugins/formcraft/file-upload/server/content/files/160755408403d8---81849562432.pdf
- http://lowchens.org/userfiles/file/xazudotisadisoteni.pdf
- http://saovietgroup.com/upload/FCK/file/8976830248.pdf
- https://www.femregenx.co.za/wp-content/plugins/super-forms/uploads/php/files/4avr1m5aao7gse8l1aip3gld3k/30323172775.pdf
- https://vieclamkinhdoanh247.com/upload/files/33502539093.pdf
- https://www.sevgiliyevideo.net/wp-content/plugins/formcraft/file-upload/server/content/files/160b9ddf66655d---roxivuj.pdf
- https://trucraftsmanship.com/wp-content/plugins/formcraft/file-upload/server/content/files/1609ef5f341553---vusogozivujan.pdf
- http://windcampus.com/wp-content/plugins/formcraft/file-upload/server/content/files/160791062cb97f---95504370420.pdf
- http://www.fliesen-brill.de/wp-content/plugins/formcraft/file-upload/server/content/files/160ac032b41f13---17881368883.pdf
- http://www.jimenez-casquet.com/wp-content/plugins/formcraft/file-upload/server/content/files/160a0fbba70635---62777637419.pdf
- https://finestblogger.de/wp-content/plugins/super-forms/uploads/php/files/102vnpbqdj701nqr9v7s6eirab/85559744781.pdf
- http://mijneigenlift.nl/wp-content/plugins/formcraft/file-upload/server/content/files/160833b92c5f60---xuzaxodinorada.pdf
- https://www.lokalesichtbarkeit.de/wp-content/plugins/super-forms/uploads/php/files/or3bfp5vhl5tjomvr5h7eaiadm/sureraxanenejosepedo.pdf
- http://akcjonariusz.com/UserFiles/file/rovusonatenufoda.pdf
- https://rrvchefs.com/wp-content/plugins/super-forms/uploads/php/files/fe8ef0ccc2bb5614fba949ddd6398764/lejokipesasowexaf.pdf
- http://bochosushi.com/wp-content/plugins/formcraft/file-upload/server/content/files/160a02a3d368d9---rikagopewilisotetobefew.pdf
- https://dfa-finanz.de/wp-content/plugins/formcraft/file-upload/server/content/files/160aba49d5f68f---wiroximokudusumonobuzava.pdf
- https://ventana-sur.com/wp-content/plugins/formcraft/file-upload/server/content/files/16075f62fbdf04.pdf
- http://tovicetour.com/FileData/ckfinder/files/20210605_7A9CE91D482776A5.pdf
- https://proff-doors.ru/wp-content/plugins/super-forms/uploads/php/files/a31896641ea15b6b99ca742ea01f63b2/toragesugib.pdf
- http://www.rlktechniek.nl/wp-content/plugins/formcraft/file-upload/server/content/files/1607d523f808b9---bavusug.pdf
- http://primaneighbors.com/userimages/kopud.pdf
- http://budaikepkeret.hu/uploads/file/72018799531.pdf
- https://feedproxy.google.com/~r/Uplcv/~3/zMnd8XtcwSM/uplcv?utm_term=weeding+and+hoeing
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://dejavu.sourceforge.net
- http://dejavu.sourceforge.net/wiki/index.php/License
Extracted artifacts 3
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0002f588.bin67c468b54952b6feec4a01e5b7f910cee260337bee022591cb2bd221d4c64a6c |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x2F588 | 19816 bytes |
font_01_sfnt_off00032a2f.bin9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x32A2F | 16792 bytes |
font_02_sfnt_off00034246.bin53e4d675bea9881ba5f658966ea29fffbd6e96c798ed3c3e463e57cdb036abcc |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x34246 | 10108 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.