MALICIOUS
126
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF file was flagged by ML classifiers and ClamAV as malicious, specifically as a phishing trojan. It contains numerous embedded URLs, with one prominent URL pointing to 'nipisod.ru' and containing 'audient+asp4816+manual' in the query parameters, suggesting a lure. The document body, though heavily obfuscated, contains fragments that align with this lure. The presence of multiple external URIs and the link farm heuristic indicate a strong intent to redirect the user to potentially malicious content.
Machine Learning
- Nyx PDF Classifier malicious score 0.9997
Heuristics 5
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARMSmall PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://nipisod.ru/123?utm_term=audient+asp4816+manual
- https://cdn-cms.f-static.net/uploads/4405193/normal_5fd678d762b2b.pdf
- https://static.s123-cdn-static.com/uploads/4371808/normal_5fe11b2b1d303.pdf
- http://chunyoo.com/willingness_letter_format_to_continue_the_jobnrs1z.pdf
- http://sandwichhq.club/piveworihx4.pdf
- http://hookup154.site/wedding_veil_length_guidea3xxx.pdf
- http://fesupopimos.66ghz.com/banaras_hindu_university_varanasi_application_form.pdf
- http://pipavinekiga.mywebcommunity.org/appareil_de_golgi.pdf
- http://legegapepapo.medianewsonline.com/synthesis_of_silver_nanoparticles.pdf
- http://bu-markett.com/what_is_national_autonomy_meanings6j6r.pdf
- http://jewakololinifi.22web.org/49190693680.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://8271b8e8-1520-4b18-8785-2fafc8cd33e6.filesusr.com/ugd/efc97f_6577684c490348a1bc09d7042af9ed2c.pdf?index=true
- http://fotopokidag.epizy.com/28073031695.pdf
- http://xenilesaripesu.epizy.com/business_card_holder_app_for_android.pdf
- http://tafoboverel.epizy.com/rulunise.pdf
- https://uploads.strikinglycdn.com/files/6b1fcc7d-39fd-4a01-981d-579a58ae9ee7/kazexi.pdf
- https://uploads.strikinglycdn.com/files/a206fab0-5e8c-48c5-ab2c-cc2e95113f6f/81168127081.pdf
- https://uploads.strikinglycdn.com/files/df8801e3-f9c9-41eb-bfe3-c9b4de0aaf54/jazoxaz.pdf
- https://d5fd0048-bb8d-45a1-ba21-28d1cb0b7162.filesusr.com/ugd/5e8de6_23e98a58b6564b049a8aea81b6f45bdc.pdf?index=true
- https://30383b9b-b26a-44f4-9a26-03873af8f03c.filesusr.com/ugd/fdee49_6205b2a775d84300911f6a6edadbc9c5.pdf?index=true
- https://uploads.strikinglycdn.com/files/a7c3a997-4384-4d2a-bfd1-cc98affed49d/what_do_i_need_to_bring_to_my_road_test_ma.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000e3ec.binf730a94a3032fe1a82f734f890d92c7ecc4ae40f84ed253d3750e3b80ce409ca |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xE3EC | 5488 bytes |
font_01_sfnt_off0000f693.bina5d060aa25737be2bb6794aa047081c00e78d281242e81d4dd9abe4e9c8c7b3a |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xF693 | 11164 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.