MALICIOUS
96
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The PDF file was detected as malicious by ML classifiers and ClamAV, indicating a high likelihood of malicious intent. It contains an embedded URL pointing to 'baarspo.ru', which is likely used to deliver a secondary payload or conduct phishing. The document's content, though heavily obfuscated, suggests a lure related to educational material to trick users into clicking the malicious link.
Machine Learning
- Nyx PDF Classifier malicious score 0.9998
Heuristics 4
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://baarspo.ru/award?keyword=author+s+purpose+worksheet+3rd+grade+pdf
- https://static.s123-cdn-static.com/uploads/4453105/normal_5ff006681a330.pdf
- https://cdn-cms.f-static.net/uploads/4425909/normal_60380d57da325.pdf
- https://cdn-cms.f-static.net/uploads/4390381/normal_6040db43c9afb.pdf
- https://cdn-cms.f-static.net/uploads/4387712/normal_5fd15eb21e6fb.pdf
- https://cdn-cms.f-static.net/uploads/4485828/normal_5fd8f7fe26e09.pdf
- https://static.s123-cdn-static.com/uploads/4416125/normal_5ff7082c18686.pdf
- https://cdn-cms.f-static.net/uploads/4413842/normal_5fdc3e1a5fe4d.pdf
- https://static.s123-cdn-static.com/uploads/4467322/normal_5fddce8f8d97b.pdf
- https://static.s123-cdn-static.com/uploads/4371806/normal_5fc959a802e1a.pdf
- http://wopazav.22web.org/32190466223.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- https://b84c3727-5d5a-4c5d-9d5d-21cac87b3a69.filesusr.com/ugd/fdd6c2_2039f16fac1f4740b8157089cab7795b.pdf?index=true
- https://8c56b32b-3398-45d6-9c0b-b55146621f16.filesusr.com/ugd/6924eb_d0c46548f52248cebcf84843579e535d.pdf?index=true
- http://zikefibuji.rf.gd/rilusoloxilofun.pdf
- http://momobolabewonu.epizy.com/jenozegogofudom.pdf
- https://s3.amazonaws.com/lorugipopuxe/personal_pronouns_worksheet_grade_3.pdf
- https://s3.amazonaws.com/vawoginele/42894759808.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000d501.bin1bf480d322bf0a73d0ffed2cd1e1e8fd9ca0705281c0e27f4ab12fe7e992d8c9 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xD501 | 5580 bytes |
font_01_sfnt_off0000e814.bincad551c51aa0c6966e68ca193175c6cdb82ef74b728a82a67ed541114cd4bac2 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xE814 | 10412 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.