Malware Insights
This PDF file was detected as malicious by ClamAV and an ML classifier, indicating a high likelihood of malicious intent. It contains a large number of external links, many pointing to disposable hosting, suggesting a link farm or phishing operation. The document body, though heavily obfuscated, contains text related to resetting an 'orbit hose timer', which is likely a lure to direct users to malicious URLs such as 'https://nipisod.ru/strik?utm_term=how+to+reset+orbit+hose+timer'. No scripts were extracted, but the PDF structure itself facilitates the redirection.
Machine Learning
- Nyx PDF Classifier malicious score 0.9998
Heuristics 6
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARMSmall PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
-
Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARMSmall PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://nipisod.ru/strik?utm_term=how+to+reset+orbit+hose+timer PDF link annotation
- https://cdn.sqhk.co/sisowufabo/jbyXgcD/crowd_control_warehouse_canada.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4419832/normal_60196b41dd879.pdfIn PDF document text
- https://cdn.sqhk.co/zuronenom/jhzhhLn/flight_to_hawaii_from_sfo_time.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4476927/normal_602744c5ae575.pdfIn PDF document text
- https://static.s123-cdn-static.com/uploads/4452154/normal_5fdf76a193b40.pdfIn PDF document text
- http://www.ascendercorp.com/In PDF document text
- http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
- https://8ab1a2d5-e5b1-44c5-a28c-e09959565f0d.filesusr.com/ugd/eb712c_8a6c2e249c684046aee3768167171495.pdf?index=trueIn PDF document text
- https://6db1e9a2-4282-4636-8d41-de07325ad911.filesusr.com/ugd/d97b38_a56d575c36b34f72b1870df2c57cab95.pdf?index=trueIn PDF document text
- http://nutajowaga.rf.gd/aha_guidelines_acls.pdfIn PDF document text
- https://3c8d80e7-2998-4b53-b1db-ea2053e4eee2.filesusr.com/ugd/5c8c55_821ed6a752b64060a5359f3514577a80.pdf?index=trueIn PDF document text
- http://vadeduvizutiv.rf.gd/25740174185.pdfIn PDF document text
- https://da4cb982-96ac-4827-b01c-1601b1c9977c.filesusr.com/ugd/b05c40_50b31f0fb6124011b48b17b288092415.pdf?index=trueIn PDF document text
- http://mejadub.epizy.com/11346828749.pdfIn PDF document text
- http://jodofinefurow.rf.gd/electronic_battleship_game_pieces_names.pdfIn PDF document text
- https://17500468-634e-4f48-81ad-48a4a068d6fa.filesusr.com/ugd/dcac76_987ceccc015a45c7b42b093d8f565bdd.pdf?index=trueIn PDF document text
- https://ff999131-262c-4f46-aa1e-84c50d3d9e43.filesusr.com/ugd/a474dd_0ea6deb62a764651bb1417cd41f41e1a.pdf?index=trueIn PDF document text
- http://nekexixi.epizy.com/periodic_table_definition_chemistry.pdfIn PDF document text
- https://0f7a2101-273c-4f7f-b1fd-079d1ad923c1.filesusr.com/ugd/a7ea6f_f6cfd8993a9844048cc46fb88fcf41d1.pdf?index=trueIn PDF document text
- https://8137cd1e-393d-4948-8193-eca935452849.filesusr.com/ugd/756799_f311975cdcdb43eb91056dda5824f8f8.pdf?index=trueIn PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/xap/1.0/rights/In PDF document text
- http://scripts.sil.org/OFLIn PDF document text
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000fe8e.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xFE8E | 4876 bytes |
SHA-256: 8733f877f17b02e5f3a1f0558469bd4c7571c666863a1ce050f34d2ff3cffb1d |
|||
font_01_sfnt_off00010f09.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x10F09 | 10800 bytes |
SHA-256: 891cb8be6b4c46998baf952fcb0ade119b073b82875b5b286b98a34282611a27 |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.