MALICIOUS
154
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
This PDF file is identified as malicious by multiple heuristics and a machine learning classifier, with ClamAV detecting it as Pdf.Phishing.Trojan. The numerous embedded URLs, many hosted on compromised WordPress sites, suggest a link farm designed to redirect users to malicious content, likely a phishing page or a further malware download. The document body, though heavily obfuscated, contains references to 'wkhtmltopdf' and a game download, indicating a lure to trick users into accessing malicious links.
Machine Learning
- Nyx PDF Classifier malicious score 0.8467
Heuristics 5
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
PDF link farm points to compromised-WordPress upload storage medium PDF_COMPROMISED_CMS_UPLOAD_LINK_FARMPDF contains multiple clickable links, across many distinct hosts, whose targets are random-slug files parked in the upload directories of vulnerable WordPress form plugins (FormCraft, Super Forms). This is the hallmark of the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains hosted on compromised sites. The PDF itself carries no exploit — the risk is the linked destinations.
-
Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARMSmall PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
-
External URI info PDF_URIPDF contains an external URL action
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://krisoc.ru/uplcv?utm_term=bow+and+arrow+old+pc+game+download PDF link annotation
- http://terapie-psi.ro/wp-content/plugins/formcraft/file-upload/server/content/files/16099cc0828e3d---15632841401.pdfIn PDF document text
- https://ambientltg.com/wp-content/plugins/super-forms/uploads/php/files/f2ee51f7a645fbc478bf3b0a8102d02c/kebexob.pdfIn PDF document text
- http://akgikorea.com/file_upload/fck_upfile/file/sijuwolezukipaxuxi.pdfIn PDF document text
- http://gagutp.com/sa_upload/userfiles/file/20210515080421.pdfIn PDF document text
- https://narimasu-chintai.net/jcfiles/file/45739112714.pdfIn PDF document text
- https://www.formwork.co.uk/wp-content/plugins/super-forms/uploads/php/files/p0a833vlr93ijki04jko8m30if/ditijexedolozebaxulazix.pdfIn PDF document text
- http://kaufdeinauto.de/wp-content/plugins/formcraft/file-upload/server/content/files/16075159e0b891---45036258997.pdfIn PDF document text
- https://autosofortkauf.ch/wp-content/plugins/super-forms/uploads/php/files/v4qbhe6fqp07ftqve0kj2h3het/77072150597.pdfIn PDF document text
- https://www.hontoys.com.au/wp-content/plugins/super-forms/uploads/php/files/d92sqfen1vvn7cflbroa2gafmu/rumixojoluxisozovise.pdfIn PDF document text
- http://prodesign31.ru/wp-content/plugins/formcraft/file-upload/server/content/files/160815e6a911a4---zuzalamemu.pdfIn PDF document text
- https://glosunspa.com/wp-content/plugins/formcraft/file-upload/server/content/files/1608522a706b7a---memitefu.pdfIn PDF document text
- http://amdind.com/userfiles/file/mafumomagomisijibe.pdfIn PDF document text
- https://messianic.live/wp-content/plugins/super-forms/uploads/php/files/9a7be39988b0ee2743c3ffe48116a599/miwefukirelefe.pdfIn PDF document text
- http://becro-plast.hr/wp-content/plugins/formcraft/file-upload/server/content/files/1606cb18cb0694---51991709271.pdfIn PDF document text
- https://www.revistadefiesta.com/wp-content/plugins/formcraft/file-upload/server/content/files/160a04be6586be---19265116399.pdfIn PDF document text
- http://www.circoloaletrium.it/wp-content/plugins/formcraft/file-upload/server/content/files/1609443122b287---68458378183.pdfIn PDF document text
- http://romanakladatelstvi.cz/userfiles/file/tifimugepaxa.pdfIn PDF document text
Open this report in the interactive analyzer, or submit your own file for analysis.