MALICIOUS
256
Risk Score
Malware Insights
MITRE ATT&CK
T1059.001 PowerShell
T1566.001 Spearphishing Attachment
The PDF contains an embedded script that references 'Powershell script manual' and points to a URL that also contains 'powershell+script+manual'. This indicates an attempt to trick the user into running a malicious PowerShell script disguised as a legitimate update tool. The presence of multiple links to compromised CMS uploads and disposable hosting further supports a phishing or malware distribution scheme.
Machine Learning
- Nyx PDF Classifier malicious score 0.9973
Heuristics 9
-
ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
-
Embedded script payload in PDF stream high PDF_EMBEDDED_SCRIPT_PAYLOADPDF stream bytes contain script execution markers such as ActiveXObject/CreateObject, WScript.Shell, PowerShell, or shell-exec primitives. This is stronger than ordinary PDF JavaScript because it indicates a staged external script payload hidden in stream bytes.
-
LOLBin token sequence in document text high SE_LOLBIN_RUN_COMMANDExtracted document text contains a Windows script/execution tool name (PowerShell, mshta, cmd, rundll32, regsvr32, …) within 220 characters of a dangerous flag, command verb, or URL. This is a visible 'run this' instruction in HTML/PDF/RTF lure bodies, or — in macro-laden Office files — the macro's own string-pool entries appearing adjacent in extracted text.
-
PDF link farm points to compromised-WordPress upload storage medium PDF_COMPROMISED_CMS_UPLOAD_LINK_FARMPDF contains multiple clickable links, across many distinct hosts, whose targets are random-slug files parked in the upload directories of vulnerable WordPress form plugins (FormCraft, Super Forms). This is the hallmark of the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains hosted on compromised sites. The PDF itself carries no exploit — the risk is the linked destinations.
-
Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARMSmall PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
-
Suspicious extracted artifact medium EXTRACTED_FILE_STATIC_TRIAGEOne or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL http://xn--ob0bjxt9h99icicrvkksa421cwwp7hiv4d6a.com/ckfinder/userfiles/files/xifafezexebudop.pdf In macro / runtime command snippet
- http://studiopiergentili.it/userfiles/files/xufavalogimanatudo.pdfIn PDF document text
- https://llibreriaha.com/img/events/file/21095291962.pdfIn PDF document text
- http://hemeringen.de/ckeditor_ablage/userfiles/files/23673745730.pdfIn PDF document text
- https://systematix.pl/userfiles/file/16529125245.pdfIn PDF document text
- https://loppisidjupdalen.se/images/uploaded/file/90081570534.pdfIn PDF document text
- http://bizbecho.com/pa/trainstation/uploads/image/file/76732628198.pdfIn PDF document text
- http://www.smartlandgroup.com/ckfinder/userfiles/files/xigubevij.pdfIn PDF document text
- http://www.gieskestukadoors.nl/ckfinder/files/files/faralozenug.pdfIn PDF document text
- https://avflash.nl/upload/files/18850371347.pdfIn PDF document text
- https://www.greenlakecruises.com/ckfinder/userfiles/files/niwijemapiwubaviju.pdfIn PDF document text
- http://www.majorisinvestimentos.com.br/wp-content/plugins/formcraft/file-upload/server/content/files/160856f38cb5c4---kotujimukobumifizu.pdfIn PDF document text
- http://sacoorhealth.pt/site/upload/file/24907410181.pdfIn PDF document text
- https://betonwerkendejonge.nl/wp-content/plugins/formcraft/file-upload/server/content/files/1611a5db09798a---56251361321.pdfIn PDF document text
- https://samiznojmo.cz/wp-content/plugins/super-forms/uploads/php/files/5444b9be6a2993c341fe7c0bbd208b4c/19962256038.pdfIn PDF document text
- http://lafayetteconnections.com/clients/52818/File/kofabosagul.pdfIn PDF document text
- http://www.mostenpo.jp/userfiles/files/tegisugarasi.pdfIn PDF document text
- http://thehawthornnyc.com/wp-content/plugins/formcraft/file-upload/server/content/files/160a43d7a4221e---popoli.pdfIn PDF document text
- http://casier-a-bouteilles.com/file/8011740297.pdfIn PDF document text
- http://www.pianoszimmermann.com.br/wp-content/plugins/formcraft/file-upload/server/content/files/1609a8554886a4---79386352484.pdfIn PDF document text
- http://www.dadosefatos.net.br/wp-content/plugins/formcraft/file-upload/server/content/files/1607c5f5b382a3---85341517856.pdfIn PDF document text
- https://alphacleanwashing.com/wp-content/plugins/super-forms/uploads/php/files/650d90e405290959d89a45a5e664ee06/41995129373.pdfIn PDF document text
- https://kakvkusno26.ru/wp-content/plugins/super-forms/uploads/php/files/d13847e2d763e6a72eec7276e02fbebe/77895764866.pdfIn PDF document text
- https://www.tangelo.no/wp-content/plugins/formcraft/file-upload/server/content/files/16072bb58d42cd---64787388998.pdfIn PDF document text
- http://re-media.ru/foto/ck/files/24084579019.pdfIn PDF document text
- https://feedproxy.google.com/~r/skout/mBVl/~3/3vuEKuznOb8/uplcv?utm_term=powershell+script+manualPDF link annotation
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/xap/1.0/rights/In PDF document text
- http://dejavu.sourceforge.netIn PDF document text
- http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text
Extracted artifacts 4
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
embedded_pdf_script_00012b81.bin |
pdf-embedded-script | PDF raw stream script payload at offset 0x12B81 | 1603 bytes |
SHA-256: b0a1efb7300a564805cb67a55bf68b9e3ae8ac3cc0e67c565c12b6f557b4fbf3 |
|||
|
Detection
ClamAV:
No threats found
Obfuscation or payload:
likely
Carved artifact contains 7 shell/COM execution token(s).
|
|||
Preview scriptFirst 1,000 lines of the extracted script
<?xpacket begin='' id='W5M0MpCehiHzreSzNTczkc9d'?>
<x:xmpmeta xmlns:x='adobe:ns:meta/' x:xmptk='SWFTools'>
<rdf:RDF xmlns:rdf='http://www.w3.org/1999/02/22-rdf-syntax-ns#'>
<rdf:Description rdf:about=''
xmlns:dc='http://purl.org/dc/elements/1.1/'
dc:format='application/pdf'>
<dc:creator>
<rdf:Seq>
<rdf:li>Fuvesoku Gojove</rdf:li>
</rdf:Seq>
</dc:creator>
<dc:description>
<rdf:Alt>
<rdf:li xml:lang='x-default'>Powershell script manual. <br><center><h2>Powershell script to manually install windows updates. Powershell script to set serv</rdf:li>
</rdf:Alt>
</dc:description>
<dc:subject>
<rdf:Bag>
<rdf:li>Powershell script manual. <br><center><h2>Powershell script to manually install windows updates. Powershell script to set serv</rdf:li>
</rdf:Bag>
</dc:subject>
<dc:title>
<rdf:Alt>
<rdf:li xml:lang='x-default'>Powershell script manual</rdf:li>
</rdf:Alt>
</dc:title>
</rdf:Description>
<rdf:Description rdf:about=''
xmlns:pdf='http://ns.adobe.com/pdf/1.3/'
pdf:Producer='SWFTools'/>
<rdf:Description rdf:about=''
xmlns:xmp='http://ns.adobe.com/xap/1.0/'
xmp:CreateDate='2020-03-08T11:50:58'
xmp:CreatorTool='SWFTools'/>
<rdf:Description rdf:about=''
xmlns:xmpMM='http://ns.adobe.com/xap/1.0/mm/'
xmpMM:DocumentID='cdd2249e-21ad-4243-a485-35114f9b859b'
xmpMM:InstanceID='c56acbe1-ebd2-433e-9ac2-c7b22e311189'/>
<rdf:Description rdf:about=''
xmlns:xmpRights='http://ns.adobe.com/xap/1.0/rights/'
xmpRights:Marked='True'/>
</rdf:RDF>
</x:xmpmeta>
<?xpacket end='w'?>
|
|||
font_00_sfnt_off0000c5c1.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xC5C1 | 10828 bytes |
SHA-256: 49770e18e166c59610be7bda9e4b6d998e785176062eda0791b5cdfcee11c91d |
|||
font_01_sfnt_off0000dea9.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xDEA9 | 16792 bytes |
SHA-256: 9d2294e344127da9ddc2b77d68b1576b6b78373885bc9da2859f180a98f2c1e1 |
|||
font_02_sfnt_off0000f6bb.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xF6BB | 17072 bytes |
SHA-256: 6807210f0ebb20c9ace5d48cff3d33b12addd32c2483412faf34eee37f5a4c56 |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.