MALICIOUS
114
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
The PDF file is identified as malicious by ClamAV and an ML classifier. It employs an image-only lure, typical of phishing, where a screenshot masquerades as a document to entice users to click embedded links. The primary malicious URL identified is https://baarspo.ru/award?keyword=synonym+worksheet+2nd+grade+pdf, which is likely used to deliver a secondary payload or redirect to a phishing page.
Machine Learning
- Nyx PDF Classifier malicious score 0.7468
Heuristics 4
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
Image-only document with action trigger (screenshot lure) medium PDF_IMAGE_LUREPDF has 1 image(s), only 0 text block(s), carries a click-outward action, and is only 43 KB — typical shape of a phishing lure where a full-page screenshot hides a clickable button that launches or submits to an attacker URL.
-
External URI info PDF_URIPDF contains an external URL action
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://baarspo.ru/award?keyword=synonym+worksheet+2nd+grade+pdf
- http://antinomi.design/69466463441pjqqz.pdf
- http://cookwellbakewell.com/angularjs_tutorial_for_beginners_step_by_step_free_downloadad1my.pdf
- http://spoonnumberone.xyz/26568888415ibojv.pdf
- http://brumbum2.xyz/latest_3d_games_for_laptop_free7y8hf.pdf
- https://cdn-cms.f-static.net/uploads/4388825/normal_600a10f0d87ad.pdf
- https://cdn-cms.f-static.net/uploads/4388422/normal_5fd118868e1c1.pdf
- http://richteam.site/55252120931w4qe0.pdf
- http://de-bewertung-889562.icu/attendance_management_solution_x100c3sx6k.pdf
- http://negozio50sconto.info/bipezekitatuwefud1e9v8.pdf
- https://uploads.strikinglycdn.com/files/e03881ce-8696-45be-ba57-d30b9e48d10e/10520610135.pdf
- https://uploads.strikinglycdn.com/files/3f2ac0cf-92cb-4d8d-82fc-8c153bb8ff53/pexokoz.pdf
- https://uploads.strikinglycdn.com/files/3672eb37-41c2-49c3-b5e4-70a6e2aa3943/tefutibelojikova.pdf
- https://uploads.strikinglycdn.com/files/38bb6fa7-331c-40ef-b781-32339a927229/the_talented_tenth.pdf
- https://uploads.strikinglycdn.com/files/d34a873a-fa2f-47da-86ea-1596d9d84d35/what_does_brayton_cycle_mean.pdf
- https://uploads.strikinglycdn.com/files/33790529-3366-41d5-b426-06178f80ad95/gubibefobulivajeg.pdf
- https://uploads.strikinglycdn.com/files/b086711c-3b74-45f9-8cad-4a40ce927208/a_connecticut_yankee_in_king_arthurs_court_how_many_pages.pdf
- https://uploads.strikinglycdn.com/files/4f6887be-5801-4b2b-be80-10bd42172bf5/ultimate_ears_boom_3_bluetooth_waterproof_portable_speaker_ultraviolet_purple.pdf
- https://uploads.strikinglycdn.com/files/0f496a9e-5961-429e-a780-86ab1abe33ed/what_university_is_best_for_business.pdf
Open this report in the interactive analyzer, or submit your own file for analysis.