MALICIOUS
96
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF file was flagged by ClamAV as 'Pdf.Phishing.Trojan' and a machine learning classifier indicated a high probability of maliciousness. An external URI pointing to 'nipisod.ru' was extracted, suggesting the document's purpose is to redirect users to a potentially malicious site. While no scripts were directly extracted, the PDF structure and the presence of external links indicate a phishing or malware distribution attempt.
Machine Learning
- Nyx PDF Classifier malicious score 0.9998
Heuristics 4
-
ClamAV: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://nipisod.ru/123?utm_term=beautiful+life+ost+goblin+ringtone
- http://lutekorudafu.iblogger.org/how_to_reset_chrono_on_ironman_watch.pdf
- http://sizijevoji.iblogger.org/77041089042.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://s3.amazonaws.com/wovedukevikov/zamejegofetomav.pdf
- https://uploads.strikinglycdn.com/files/0b790d1d-518a-42e0-8ae7-cc860536b46e/narabuwunabu.pdf
- https://s3.amazonaws.com/jeworurowam/gavaverogedab.pdf
- https://uploads.strikinglycdn.com/files/d784cb4b-4190-420c-8e47-6714e938669e/how_to_report_toxic_leadership_army.pdf
- https://uploads.strikinglycdn.com/files/c056cba1-b409-46e5-85b3-52a8566ca92b/is_it_better_to_boil_ribs_before_grilling.pdf
- https://uploads.strikinglycdn.com/files/95ee6032-6030-40e3-a77c-84c7e5323924/watinunekeguvisixagemene.pdf
- https://s3.amazonaws.com/lupuvogotog/api_testing_strategy.pdf
- https://uploads.strikinglycdn.com/files/44ad00d7-11af-488e-a674-47a95d655d3f/wujunoxawosegunorajitivu.pdf
- https://s3.amazonaws.com/viregujipowuru/sezuf.pdf
- https://s3.amazonaws.com/gifiz/what_is_an_example_of_a_calculus_problem.pdf
- https://s3.amazonaws.com/dowavelaxam/mazonipesidogalotubozivu.pdf
- https://uploads.strikinglycdn.com/files/2287e6c1-7f34-4e9d-a5f7-a5a71d460a67/what_is_the_nash_equilibrium_and_why_does_it_matter.pdf
- https://uploads.strikinglycdn.com/files/7d6a3152-65d2-46e7-a5ad-898dff9ebc4a/10282273119.pdf
- https://uploads.strikinglycdn.com/files/f0dae4c8-19e0-44ce-ac52-ed07bd1d33df/how_long_does_a_milwaukee_m18_5.0_battery_last.pdf
- https://s3.amazonaws.com/neporezofov/52668850008.pdf
- https://uploads.strikinglycdn.com/files/d20e00c0-ac20-482e-b265-3259fa1f7d86/jack_and_beanstalk_story_outline.pdf
- http://silapopo.epizy.com/66522471386.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 3
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000d59a.binf840540010e3abe1197488ef3601d3167ae5bf5781e6dbd821dcd2625511a9f3 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xD59A | 15024 bytes |
font_01_sfnt_off00010388.binb196727ac806b6aedf5234ba3ebee86c03ecdee2329b7829b1fbffe85d75dc0d |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x10388 | 5124 bytes |
font_02_sfnt_off00011506.bind66df964f028dbedbcb72f737b4b1b2dbf78fbdf8432f4776d74a61d0f2e4e0d |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x11506 | 14080 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.