MALICIOUS
276
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
The PDF contains embedded JavaScript, identified by the 'PDF_EMBEDDED_SCRIPT_PAYLOAD' heuristic, which is designed to download and execute a second-stage payload. Several URLs point to compromised WordPress sites, indicating a common distribution method for malicious PDFs. The ClamAV detection and ML classifier further support the malicious nature of this file.
Machine Learning
- Nyx PDF Classifier malicious score 0.9973
Heuristics 10
-
ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
-
Embedded script payload in PDF stream high PDF_EMBEDDED_SCRIPT_PAYLOADPDF stream bytes contain script execution markers such as ActiveXObject/CreateObject, WScript.Shell, PowerShell, or shell-exec primitives. This is stronger than ordinary PDF JavaScript because it indicates a staged external script payload hidden in stream bytes.
-
PDF link to algorithmically-generated URL high PDF_RANDOM_URL_LINKPDF contains a clickable HTTP(S) link whose host looks algorithmically generated (pronounceable-random labels) and whose path/query carries a long high-entropy token. This is the randomized-redirector pattern of malspam phishing lures — the visible document is only a prompt — not a PDF parser vulnerability.
-
Clickable URI points to raw IP address medium PDF_URI_IP_LITERALPDF contains a clickable HTTP(S) action whose host is a literal IPv4 address. Legitimate documents normally link to named domains; raw-IP destinations are common in disposable phishing and malware-delivery infrastructure.
-
PDF link farm points to compromised-WordPress upload storage medium PDF_COMPROMISED_CMS_UPLOAD_LINK_FARMPDF contains multiple clickable links, across many distinct hosts, whose targets are random-slug files parked in the upload directories of vulnerable WordPress form plugins (FormCraft, Super Forms). This is the hallmark of the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains hosted on compromised sites. The PDF itself carries no exploit — the risk is the linked destinations.
-
Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARMSmall PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
-
Suspicious extracted artifact medium EXTRACTED_FILE_STATIC_TRIAGEOne or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL http://www.davidwoodpersonnel.com/wp-content/plugins/formcraft/file-upload/server/content/files/160f8c08490332---34841922050.pdf In PDF document text
- http://pocatellocampfire.com/wp-content/plugins/super-forms/uploads/php/files/rl5hqkilsm8sgc61hrb0m6a9ge/55830966885.pdfIn PDF document text
- http://mouaumfb.com/wp-content/plugins/formcraft/file-upload/server/content/files/160aa593d87773---65442001025.pdfIn PDF document text
- https://jyapa.com/jhuoyue/uploadfiles/93078682159.pdfIn PDF document text
- https://glowskincare.net/wp-content/plugins/super-forms/uploads/php/files/c6720285eeebc503196c61d293c9ed1d/dakotagatusesufa.pdfIn PDF document text
- http://www.tecnotrefg.it/wp-content/plugins/formcraft/file-upload/server/content/files/1608b3eba01240---nuvagibo.pdfIn PDF document text
- http://79.170.40.182/boothtastic.com/wp-content/plugins/formcraft/file-upload/server/content/files/161294ebf25d7b---jomos.pdfPDF link annotation
- http://shriramashramssschool.org/userfiles/file/redemusoxasagobeketanu.pdfIn PDF document text
- http://school19-zav.ru/userfiles/file/7760717728.pdfIn PDF document text
- https://12shio3.com/contents/files/nulex.pdfIn PDF document text
- https://businessservicesuk.com/userfiles/file/xilejuparexixixugezefubuv.pdfIn PDF document text
- https://architektor.ru/uploads/file/26997035482.pdfIn PDF document text
- http://www.sunarnuricomuisvealisverismerkezi.com/wp-content/plugins/super-forms/uploads/php/files/ogl95p81pd2m9i74vsvg7b81q5/wuruj.pdfIn PDF document text
- http://anaminfo.com/attachfile/file/144797648.pdfIn PDF document text
- http://ahkkpcm.org/userfiles/filowuxeg.pdfIn PDF document text
- https://hotelristorantenovecento.it/wp-content/plugins/super-forms/uploads/php/files/7871d604c60c9393a0bd352d12db83a7/17877246844.pdfIn PDF document text
- https://myphambambi.com/webroot/img/files/40201660432.pdfIn PDF document text
- http://slp61.com/clients/e/e2/e296dcecfd7d10ffef0cc83fef253c72/File/77784522548.pdfIn PDF document text
- https://www.hed-endo.hr/wp-content/plugins/formcraft/file-upload/server/content/files/16121d30e66abd---88274532517.pdfIn PDF document text
- http://bmhs1963.com/clients/7/72/7286fd37811b7a5dece6e69924e4d5ab/File/72440544636.pdfIn PDF document text
- http://bfr-bialapodlaska.pl/userfiles/file/67589842844.pdfIn PDF document text
- http://global-gypsum.com/wp-content/plugins/formcraft/file-upload/server/content/files/160a80d0d769f9---91012369401.pdfIn PDF document text
- https://www.bouwenaaneensterkwerkgeversmerk.nl/wp-content/plugins/formcraft/file-upload/server/content/files/160bdbd5ee7c21---vovimejeponapufer.pdfIn PDF document text
- https://studiovizia.com/webroot/img/content/files/5895643728.pdfIn PDF document text
- https://feedproxy.google.com/~r/skout/mBVl/~3/fzgW7-mxBc0/uplcv?utm_term=powershell+decode+base64+pdfPDF link annotation
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/xap/1.0/rights/In PDF document text
- http://dejavu.sourceforge.netIn PDF document text
- http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text
Extracted artifacts 4
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
embedded_pdf_script_00012e56.bin |
pdf-embedded-script | PDF raw stream script payload at offset 0x12E56 | 1615 bytes |
SHA-256: 7ce667d62f2296436e0b5f877659ed96a4427f4614fca65a9d385e7ed6cef2bb |
|||
|
Detection
ClamAV:
No threats found
Obfuscation or payload:
likely
Carved artifact contains 7 shell/COM execution token(s).
|
|||
Preview scriptFirst 1,000 lines of the extracted script
<?xpacket begin='' id='W5M0MpCehiHzreSzNTczkc9d'?>
<x:xmpmeta xmlns:x='adobe:ns:meta/' x:xmptk='Soda PDF'>
<rdf:RDF xmlns:rdf='http://www.w3.org/1999/02/22-rdf-syntax-ns#'>
<rdf:Description rdf:about=''
xmlns:dc='http://purl.org/dc/elements/1.1/'
dc:format='application/pdf'>
<dc:creator>
<rdf:Seq>
<rdf:li>Toloniyi Dihute</rdf:li>
</rdf:Seq>
</dc:creator>
<dc:description>
<rdf:Alt>
<rdf:li xml:lang='x-default'>Powershell decode base64 pdf. <br><center><h2>Powershell decode base64 file. Powershell decode base64 and write to file. Powershel</rdf:li>
</rdf:Alt>
</dc:description>
<dc:subject>
<rdf:Bag>
<rdf:li>Powershell decode base64 pdf. <br><center><h2>Powershell decode base64 file. Powershell decode base64 and write to file. Powershel</rdf:li>
</rdf:Bag>
</dc:subject>
<dc:title>
<rdf:Alt>
<rdf:li xml:lang='x-default'>Powershell decode base64 pdf</rdf:li>
</rdf:Alt>
</dc:title>
</rdf:Description>
<rdf:Description rdf:about=''
xmlns:pdf='http://ns.adobe.com/pdf/1.3/'
pdf:Producer='Soda PDF'/>
<rdf:Description rdf:about=''
xmlns:xmp='http://ns.adobe.com/xap/1.0/'
xmp:CreateDate='2020-01-25T12:26:54'
xmp:CreatorTool='Soda PDF'/>
<rdf:Description rdf:about=''
xmlns:xmpMM='http://ns.adobe.com/xap/1.0/mm/'
xmpMM:DocumentID='c69d6c5b-309d-4241-a658-573e295fd492'
xmpMM:InstanceID='ccc870e5-47e4-426b-90af-79da02486920'/>
<rdf:Description rdf:about=''
xmlns:xmpRights='http://ns.adobe.com/xap/1.0/rights/'
xmpRights:Marked='True'/>
</rdf:RDF>
</x:xmpmeta>
<?xpacket end='w'?>
|
|||
font_00_sfnt_off0000c7f2.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xC7F2 | 17368 bytes |
SHA-256: 01f41ef851e6d5644388bb2eb49a7989bbde6a1359b8b7d1f06202463d3b71ea |
|||
font_01_sfnt_off0000f4b4.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xF4B4 | 16792 bytes |
SHA-256: 9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1 |
|||
font_02_sfnt_off00010ccb.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x10CCB | 10896 bytes |
SHA-256: 9c1e15fc68e680b0372565932391a86c3d945b499528c52c7c5ae834d575088f |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.