MALICIOUS
256
Risk Score
Malware Insights
MITRE ATT&CK
T1059.001 PowerShell
T1566.001 Spearphishing Attachment
T1203 Exploitation for Client Execution
The PDF contains an embedded script and multiple URLs, many of which point to compromised CMS uploads. The 'SE_CLIPBOARD_COMMAND_LURE' heuristic indicates the document instructs the user to copy/paste commands into a shell, likely to execute a PowerShell payload. The embedded script metadata mentions 'Powershell enumerate files', further supporting this attack vector. The ClamAV detection and ML classifier strongly indicate malicious intent.
Machine Learning
- Nyx PDF Classifier malicious score 0.9942
Heuristics 9
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
Embedded script payload in PDF stream high PDF_EMBEDDED_SCRIPT_PAYLOADPDF stream bytes contain script execution markers such as ActiveXObject/CreateObject, WScript.Shell, PowerShell, or shell-exec primitives. This is stronger than ordinary PDF JavaScript because it indicates a staged external script payload hidden in stream bytes.
-
Clipboard command execution lure high SE_CLIPBOARD_COMMAND_LUREDocument tells the user to copy or paste clipboard content into Run, PowerShell, cmd, or another shell-like execution context
-
PDF link farm points to compromised-WordPress upload storage medium PDF_COMPROMISED_CMS_UPLOAD_LINK_FARMPDF contains multiple clickable links, across many distinct hosts, whose targets are random-slug files parked in the upload directories of vulnerable WordPress form plugins (FormCraft, Super Forms). This is the hallmark of the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains hosted on compromised sites. The PDF itself carries no exploit — the risk is the linked destinations.
-
Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARMSmall PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
-
Suspicious extracted artifact medium EXTRACTED_FILE_STATIC_TRIAGEOne or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL http://iaestedresden.de/userfiles/file/kozegadabami.pdf In PDF document text
- http://zahradysnapady.cz/soubory/files/neroxizenepafatunerulewan.pdfIn PDF document text
- https://phase1acoustics.com/wp-content/plugins/formcraft/file-upload/server/content/files/1609cf5694a736---nidawatujukused.pdfIn PDF document text
- http://middlegeorgiacoinclub.com/wp-content/plugins/formcraft/file-upload/server/content/files/16078e64f26828---melosapozepufijesubi.pdfIn PDF document text
- http://pokorny-podlahy.cz/UserFiles/File/mafaxepubesavarivizum.pdfIn PDF document text
- https://robertmatzuzi-massagetherapist.co.uk/wp-content/plugins/formcraft/file-upload/server/content/files/160a217f6c77ca---72498390687.pdfIn PDF document text
- http://meble-tk.pl/userfiles/file/xixeminosadojerugad.pdfIn PDF document text
- http://www.timtransportes.com/home/wp-content/plugins/formcraft/file-upload/server/content/files/160a8c707eadea---20808451880.pdfIn PDF document text
- http://ivepe-elearning.gr/assets/UserFiles/mainHome/file/15883305446.pdfIn PDF document text
- http://doggystylzgrooming.com/admin/photos/file/fojolufepininivo.pdfIn PDF document text
- https://joepromenshealth.com/wp-content/plugins/super-forms/uploads/php/files/652a1ec8876f20e5600814c64f00a048/kabusejotuxurexe.pdfIn PDF document text
- https://nhaban24h.com.vn/wp-content/plugins/super-forms/uploads/php/files/n3bq16punnjn81kv1brv232fnb/61581562179.pdfIn PDF document text
- https://robinio.de/wp-content/plugins/super-forms/uploads/php/files/l928ineg6jgbsjt7810p8c24di/92979620886.pdfIn PDF document text
- http://interno-kazan.ru/upload/files/rolodubajoduw.pdfIn PDF document text
- https://stomatoloska-ordinacija-rijeka.com/files/dikuzeb.pdfIn PDF document text
- https://diedacorporation.net/freesiafiles/file/suxofupesuputitutoti.pdfIn PDF document text
- http://yomamasushitogo.com/uploads/files/tetifokezisuliko.pdfIn PDF document text
- http://cuatro-pr.org/sites/default/files/file/majovusuxapuzomu.pdfIn PDF document text
- https://www.kbstephens.com/wp-content/plugins/super-forms/uploads/php/files/c64ad244432d32f229810370119ecc08/16094949793.pdfIn PDF document text
- https://principesgs.com/userfiles/file/bisugimewazisemozokijebu.pdfIn PDF document text
- http://www.asejnrtigers.co.uk/wp-content/plugins/formcraft/file-upload/server/content/files/16085105c0c584---vogito.pdfIn PDF document text
- https://realimpacto.com.br/wp-content/plugins/formcraft/file-upload/server/content/files/16089bb7f77055---tekajerase.pdfIn PDF document text
- https://euroroma-bg.org/files/file/86422948478.pdfIn PDF document text
- https://feedproxy.google.com/~r/1eyvgo/aqOO/~3/1xuhb7AK25c/uplcv?utm_term=powershell+enumerate+filesPDF link annotation
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/xap/1.0/rights/In PDF document text
- http://dejavu.sourceforge.netIn PDF document text
- http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text
Extracted artifacts 4
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
embedded_pdf_script_00016561.bin |
pdf-embedded-script | PDF raw stream script payload at offset 0x16561 | 1581 bytes |
SHA-256: 2aae10962afec70bdca46a9ea78ef09f3840621b0d2c1ed37ff9a06b722eaf3a |
|||
|
Detection
ClamAV:
No threats found
Obfuscation or payload:
likely
Carved artifact contains 3 shell/COM execution token(s).
|
|||
Preview scriptFirst 1,000 lines of the extracted script
<?xpacket begin='' id='W5M0MpCehiHzreSzNTczkc9d'?>
<x:xmpmeta xmlns:x='adobe:ns:meta/' x:xmptk='pdf-parser'>
<rdf:RDF xmlns:rdf='http://www.w3.org/1999/02/22-rdf-syntax-ns#'>
<rdf:Description rdf:about=''
xmlns:dc='http://purl.org/dc/elements/1.1/'
dc:format='application/pdf'>
<dc:creator>
<rdf:Seq>
<rdf:li>Weniwaya Lokojuzu</rdf:li>
</rdf:Seq>
</dc:creator>
<dc:description>
<rdf:Alt>
<rdf:li xml:lang='x-default'>Powershell enumerate files. The Get-ChildItem cmdlet supports wildcarding through three parameters: Path The -Path parameter i</rdf:li>
</rdf:Alt>
</dc:description>
<dc:subject>
<rdf:Bag>
<rdf:li>Powershell enumerate files. The Get-ChildItem cmdlet supports wildcarding through three parameters: Path The -Path parameter i</rdf:li>
</rdf:Bag>
</dc:subject>
<dc:title>
<rdf:Alt>
<rdf:li xml:lang='x-default'>Powershell enumerate files</rdf:li>
</rdf:Alt>
</dc:title>
</rdf:Description>
<rdf:Description rdf:about=''
xmlns:pdf='http://ns.adobe.com/pdf/1.3/'
pdf:Producer='pdf-parser'/>
<rdf:Description rdf:about=''
xmlns:xmp='http://ns.adobe.com/xap/1.0/'
xmp:CreateDate='2020-04-04T17:24:52'
xmp:CreatorTool='pdf-parser'/>
<rdf:Description rdf:about=''
xmlns:xmpMM='http://ns.adobe.com/xap/1.0/mm/'
xmpMM:DocumentID='20963dcb-843a-40d9-a614-a4cb3f0033a0'
xmpMM:InstanceID='c601f20a-c3a6-461b-a7c8-c712dc846e6d'/>
<rdf:Description rdf:about=''
xmlns:xmpRights='http://ns.adobe.com/xap/1.0/rights/'
xmpRights:Marked='True'/>
</rdf:RDF>
</x:xmpmeta>
<?xpacket end='w'?>
|
|||
font_00_sfnt_off0000fbd2.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xFBD2 | 16792 bytes |
SHA-256: 9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1 |
|||
font_01_sfnt_off000113e4.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x113E4 | 18552 bytes |
SHA-256: 3cb1b8ac82e4c9ead1bdc6e9ec3a66cb833e89a62f224f86013bfff5f0ecb1f5 |
|||
font_02_sfnt_off0001453d.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x1453D | 10664 bytes |
SHA-256: 537e8009be223ca569c99997f79d70a8fcb1808a4f90a14aab755c90a1815b78 |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.