MALICIOUS
156
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1203 Exploitation for Client Execution
The PDF was flagged by ClamAV as Pdf.Phishing.Trojan and an ML classifier indicated a high probability of maliciousness. Heuristics identified it as a link farm pointing to compromised CMS upload directories and disposable hosting, suggesting a phishing or malware distribution scheme. The embedded URLs, while numerous, do not contain direct executable content but serve as lures to external malicious sites.
Machine Learning
- Nyx PDF Classifier malicious score 0.9974
Heuristics 6
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
PDF link farm points to compromised-WordPress upload storage medium PDF_COMPROMISED_CMS_UPLOAD_LINK_FARMPDF contains multiple clickable links, across many distinct hosts, whose targets are random-slug files parked in the upload directories of vulnerable WordPress form plugins (FormCraft, Super Forms). This is the hallmark of the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains hosted on compromised sites. The PDF itself carries no exploit — the risk is the linked destinations.
-
Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARMSmall PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://aadhaarretail.com/administrator/imagetemp/file/8738679038.pdf In PDF document text
- http://elitvorota.ru/f/file/13140636281.pdfIn PDF document text
- https://www.hed-endo.hr/wp-content/plugins/formcraft/file-upload/server/content/files/160c87efdef15b---sametiguguzid.pdfIn PDF document text
- https://ensegun2.com/ckfinder/userfiles/files/nikimukexagiro.pdfIn PDF document text
- http://velapower.com/glwh/UploadFile/file/2021072219040773499.pdfIn PDF document text
- http://cityhigh78.com/clients/2/2d/2ddbae4fb74c169819b3574d76e4e264/File/97391178894.pdfIn PDF document text
- http://n2nnetworks.com/files/others/bonumejogefisulijajotun.pdfIn PDF document text
- http://irk-yoga.ru/upload/files/97304436980.pdfIn PDF document text
- http://harnettcountyhba.com/userfiles/file/65527839052.pdfIn PDF document text
- http://xsteelstock.com/d/files/86121094044.pdfIn PDF document text
- https://udachi.co.th/wp-content/plugins/super-forms/uploads/php/files/p5ok1kt91lc71s32f127gjbgf1/gemarotoxinowoporopef.pdfIn PDF document text
- http://noahjohnsonsark.com/clients/e/ef/ef24418f2336b9480f3353ee42fa3f58/File/61347177495.pdfIn PDF document text
- http://dh-life.com/ckfinder/userfiles/files/66501175462.pdfIn PDF document text
- https://cncostruzioni.com/userfiles/file/guliram.pdfIn PDF document text
- https://monarchwinemerchants.com/wp-content/plugins/super-forms/uploads/php/files/d37f0b5242339cbc880176d5150a1dce/57930325063.pdfIn PDF document text
- http://tweedehandswikkelaar.nl/app/webroot/files/userfiles/files/9578265961.pdfIn PDF document text
- https://voyageaventurenepal.com/upload/files/kerorugijejuvubexob.pdfIn PDF document text
- https://ibliberia.com/ckfinder/userfiles/files/vutuwojosadulegamexapufa.pdfIn PDF document text
- http://skupka23.ru/upload/m/43502216599.pdfIn PDF document text
- https://www.ezhealthcheck.com/wp-content/plugins/super-forms/uploads/php/files/ca8m43jttv40tfj8bcbim31aho/92052512369.pdfIn PDF document text
- https://plswa.com/wp-content/plugins/super-forms/uploads/php/files/6d90281ee03343525f93c54989c994fa/basotataduruxu.pdfIn PDF document text
- http://boletos.luzservicos.com/ckfinder/userfiles/files/8695302719.pdfIn PDF document text
- http://travelci.ru/ckfinder/userfiles/files/totudijezixojenafumibikat.pdfIn PDF document text
- https://hcs1000.org/wp-content/plugins/super-forms/uploads/php/files/9d3f4082b31d9736629c946021231dec/befibin.pdfIn PDF document text
- https://feedproxy.google.com/~r/1eyvgo/aqOO/~3/BkSY9tpko7c/uplcv?utm_term=iso+27001+checklist+pdfPDF link annotation
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/xap/1.0/rights/In PDF document text
- http://dejavu.sourceforge.netIn PDF document text
- http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text
Extracted artifacts 3
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000e6f3.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xE6F3 | 10736 bytes |
SHA-256: d7461c9eac87e09a5622cfbd53f14f769bd1dc96a9502d5ed05e09e2aebc8c1b |
|||
font_01_sfnt_off0000ffe5.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xFFE5 | 16792 bytes |
SHA-256: 9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1 |
|||
font_02_sfnt_off000117f7.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x117F7 | 16968 bytes |
SHA-256: 3e8bbece9928f3f5397f49cbf75886f99d24268fb4657c6ad257d9ceb4462304 |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.