MALICIOUS
164
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
This PDF file was detected as malicious by ClamAV and an ML classifier, indicating a high likelihood of malicious intent. It functions as a link farm, presenting numerous URLs that likely lead to further malicious content or downloads, disguised as free book downloads. The presence of multiple compromised CMS upload links suggests a tactic to host and distribute malicious files.
Machine Learning
- Nyx PDF Classifier malicious score 0.9995
Heuristics 7
-
ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
-
PDF link farm points to compromised-WordPress upload storage medium PDF_COMPROMISED_CMS_UPLOAD_LINK_FARMPDF contains multiple clickable links, across many distinct hosts, whose targets are random-slug files parked in the upload directories of vulnerable WordPress form plugins (FormCraft, Super Forms). This is the hallmark of the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains hosted on compromised sites. The PDF itself carries no exploit — the risk is the linked destinations.
-
Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARMSmall PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
-
Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTONDocument contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://oneremote.ru/wp-content/plugins/super-forms/uploads/php/files/66eb6baea200ef5eab8bc444b41a27ff/18469764605.pdf
- https://lea-inc.com/wp-content/plugins/super-forms/uploads/php/files/11bf04b0027b08de89f4dbd05f115de9/poxutedixojaparime.pdf
- https://purpleleafestatebuyers.com/wp-content/plugins/formcraft/file-upload/server/content/files/1606ca6ca1cc78---98206104226.pdf
- http://www.opencalgary.org/wp-content/plugins/formcraft/file-upload/server/content/files/1608d93fbc9d20---35893942691.pdf
- https://desertflying.club/wp-content/plugins/formcraft/file-upload/server/content/files/16079402a6e3a2---xukodowotaz.pdf
- http://www.bestlifepolicy.co.uk/wp-content/plugins/formcraft/file-upload/server/content/files/160862b3448d62---korevumadepubiwapuwitales.pdf
- http://counterreaction.net/wp-content/plugins/formcraft/file-upload/server/content/files/160805db6ef828---fukenuwigene.pdf
- http://trenermichal.pl/wp-content/plugins/formcraft/file-upload/server/content/files/16075a2b163199---givefari.pdf
- https://ifacemount.com/wp-content/plugins/super-forms/uploads/php/files/k3j9pvmihbe39i0sd9hvmpss62/gafijesadowituxipo.pdf
- https://www.modianodesign.com/wp-content/plugins/formcraft/file-upload/server/content/files/1606ccff06ed3d---saxefamevibudirolovala.pdf
- http://grupogmec.com/wp-content/plugins/formcraft/file-upload/server/content/files/1606cd3048a632---33676519548.pdf
- https://hmv.ir/wp-content/plugins/formcraft/file-upload/server/content/files/1609b3930ae0ae---jadef.pdf
- https://baodinhsolar.com/wp-content/plugins/super-forms/uploads/php/files/2ksut2b0j12msu3jpkkj6npunk/25204661665.pdf
- http://espacioschillout.es/images/admin/file/dufaregimeliladif.pdf
- http://www.majorisinvestimentos.com.br/wp-content/plugins/formcraft/file-upload/server/content/files/16080d1827aa72---suwasewikoremefumitubo.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- http://fedorahosted.org/lohit
- https://feedproxy.google.com/~r/1eyvgo/aqOO/~3/A3Ryygt5BCM/uplcv?utm_term=rukmini+prakashan+computer+books+pdf+free+download+in+hindi
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
- http://dejavu.sourceforge.net
- http://dejavu.sourceforge.net/wiki/index.php/License
Extracted artifacts 5
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000e606.bin68645cd6d45f9e4fbb9a5c9c7c27815e2b3413d9b9123fb4cbbd8d372555a460 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xE606 | 3288 bytes |
font_01_sfnt_off0000f1c9.bin3fcaf242d0db57bd084e731b7fffbae8fce613bba95a3485478be3e0e69a7272 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xF1C9 | 5696 bytes |
font_02_sfnt_off00010513.bin62241883dc7dbba3a09708007bb880a6b4d1ce23097e31671e2158d7079ada4b |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x10513 | 11768 bytes |
font_03_sfnt_off00012d57.bin292b67320f20e7e38814323bff47001ccb55b5eebb397aea8a254f3e91f57b87 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x12D57 | 16096 bytes |
font_04_sfnt_off0001425d.binbdaa0ca1d85594c0c5a0f4142509176d8c9de107e1e1fb71a8b73b262e6be668 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x1425D | 2916 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.