MALICIOUS
156
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1204.002 Malicious File
This PDF was flagged by multiple heuristics as malicious, including a critical ClamAV detection for 'Pdf.Phishing.Trojan'. The file contains numerous links pointing to compromised CMS upload directories, suggesting it is part of a link farm designed to distribute further malicious content. The ML classifier also strongly indicated maliciousness.
Machine Learning
- Nyx PDF Classifier malicious score 0.9765
Heuristics 6
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
PDF link farm points to compromised-WordPress upload storage medium PDF_COMPROMISED_CMS_UPLOAD_LINK_FARMPDF contains multiple clickable links, across many distinct hosts, whose targets are random-slug files parked in the upload directories of vulnerable WordPress form plugins (FormCraft, Super Forms). This is the hallmark of the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains hosted on compromised sites. The PDF itself carries no exploit — the risk is the linked destinations.
-
Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARMSmall PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://www.carlosfunes.es/wp-content/plugins/formcraft/file-upload/server/content/files/160a6c21473a91---kekuvogoja.pdf
- http://locthanhwindow.com/img_duhoc/files/dimowinamajefix.pdf
- http://www.pirac.org/wp-content/plugins/super-forms/uploads/php/files/810bab9db5d04dfbef6e1155730ba27e/1695957395.pdf
- http://vtracauto.com/wp-content/plugins/formcraft/file-upload/server/content/files/160ae0a2faef0b---38984658360.pdf
- http://www.carolglassman.com/wp-content/plugins/formcraft/file-upload/server/content/files/160c0f99371c2b---60790960957.pdf
- http://aite-materials.com/upfiles/file/80883634632.pdf
- http://flyingcarpetclementines.com/userfiles/files/borilimezuxakojo.pdf
- https://weblative.com/wp-content/plugins/super-forms/uploads/php/files/hoeuj5ocaaasq5dqta43g7s2ur/82014953059.pdf
- https://urbanplace.me/wp-content/plugins/super-forms/uploads/php/files/660f3abad11195d1412dcb5e3ebb90f5/lodirekiwu.pdf
- http://yonezawanet.jp/units/24250/zcycom/files/90976995440.pdf
- http://www.primalegal.eu/wp-content/plugins/super-forms/uploads/php/files/q9re0h7khtou9515ncpuljk691/36071666905.pdf
- http://barrarioservicos.com.br/wp-content/plugins/formcraft/file-upload/server/content/files/160c6b4de94172---nasax.pdf
- https://sp-pir.ru/wp-content/plugins/super-forms/uploads/php/files/94de5dfc87d77f4c5b23297a20aea20f/28644506418.pdf
- https://www.hotel-palladium.gr/wp-content/plugins/super-forms/uploads/php/files/c9tv2u30m9aug7hrpd1fqj2uol/niwuzupiwigowol.pdf
- https://broodjedenbosch.nl/ckfinder/userfiles/files/nujera.pdf
- http://www.k-24.com/wp-content/plugins/formcraft/file-upload/server/content/files/160c5b168c3485---75655636479.pdf
- https://gbeequestriansurfaces.com/wp-content/plugins/super-forms/uploads/php/files/ictuemse1v1h52pp1mb4amf2fg/piden.pdf
- http://bioscipublisher.com/files/upfiles/file/4433884738.pdf
- http://sanmargholidays.com/ckfinder/userfiles/files/12864604916.pdf
- http://www.idenet.net/wp-content/plugins/formcraft/file-upload/server/content/files/1606c9057f1041---4279868462.pdf
- https://www.alertgy.com/wp-content/plugins/super-forms/uploads/php/files/eb41f6d8899cf1180c28df972d58cad3/vanalubodopujazubes.pdf
- https://matskaren.se/anvandarbilder/203/files/vedetobasuwatatopa.pdf
- http://www.evisiontiendaonline.com/ckfinder/userfiles/files/kokofofitivejogo.pdf
- https://wecafephuket.com/wp-content/plugins/super-forms/uploads/php/files/i4ph65pfdcs1tgddd90lh0p5u0/jebivimik.pdf
- https://cutletsmeat.com/wp-content/plugins/formcraft/file-upload/server/content/files/16089a20b80598---lozubokorimikijogumasusot.pdf
- https://feedproxy.google.com/~r/1eyvgo/aqOO/~3/YTWXjIUwRh0/uplcv?utm_term=weather+dates+sword+and+shield
- http://lovewhereyoulv.wpengine.com/wp-content/plugins/super-forms/uploads/php/files/0a52385701e5a4a2963604086f2e1a0e/ruwabuverusiwavifup.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://dejavu.sourceforge.net
- http://dejavu.sourceforge.net/wiki/index.php/License
Extracted artifacts 4
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000f074.bina2580cf69c87d6f6694bc7b7f398d6d426feef39b01e764481aa7c0d28c28cb0 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xF074 | 17636 bytes |
font_01_sfnt_off00011edf.bin6b2cb54920b8a7c3da3ca827f04bb0247f5f31b5c9b01f7a2855ddf7ad3f52dd |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x11EDF | 1904 bytes |
font_02_sfnt_off000127b9.bin16dcc832fb897813f50d4a84adad4e10af46ff2d35c99d35e94c94b7fff0d490 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x127B9 | 10424 bytes |
font_03_sfnt_off00013f58.bin9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x13F58 | 16792 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.