MALICIOUS
136
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
The sample is a PDF document flagged by ClamAV as a phishing trojan. Heuristics indicate it uses an advance-fee scam lure, attempting to trick the user with promises of prizes or funds. The document contains multiple embedded URLs, one of which is `https://xezojetit.ru/aws?utm_term=how+does+godfather+end`, likely serving as a malicious link or redirect.
Machine Learning
- Nyx PDF Classifier malicious score 0.9993
Heuristics 5
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
Advance-fee lottery/parcel scam lure high SE_ADVANCE_FEE_SCAM_LUREDocument contains lottery/beneficiary or prize language together with large-value draft/funds wording and parcel/courier delivery requirements. This is a classic advance-fee fraud document shape.
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://xezojetit.ru/aws?utm_term=how+does+godfather+end
- http://shtancircul.site/kedofixadutogon2rmjp.pdf
- http://usejus.pro/6208087886120g04.pdf
- http://junumidutuzakox.getenjoyment.net/which_engineering_course_has_more_job_opportunities.pdf
- http://digitalliteracyinstitute.com/all_my_sons_arthur_miller_full_movieo00ud.pdf
- http://pmaider.com/88536949593sl2cm.pdf
- http://kujamemapevubu.mypressonline.com/11733861486.pdf
- http://instapriz.site/190249190785f7un.pdf
- http://dragonflysagewellness.com/jumper_clothing_british3n2kt.pdf
- http://tonojodozif.mypressonline.com/lonekav.pdf
- http://nulatapukedu.scienceontheweb.net/dilenepiwomiloxerumilurut.pdf
- http://gsmall.space/chrysler_voyager_user_manual3e8gl.pdf
- http://tasiperop.medianewsonline.com/joxorokotiziz.pdf
- http://fupemagis.mywebcommunity.org/how_to_change_transmission_fluid_honda_accord.pdf
- http://1xbets-regs.site/harry_potter_fanfiction_lemon_minervai33nm.pdf
- http://bitcoinlearningcentre.online/science_vie_tv_izlee8ybr.pdf
- http://vixemifojetinag.sportsontheweb.net/how_to_use_a_hamilton_beach_roaster_oven.pdf
- http://www.ascendercorp.com/
- http://www.ascendercorp.com/typedesigners.html
- http://fepusum.onlinewebshop.net/assessment_tools_for_autism.pdf
- http://wozimape.onlinewebshop.net/61467939666.pdf
- http://tofalit.myartsonline.com/formulaire_declaration_de_cession_vehicule.pdf
- http://zitasixan.atwebpages.com/fokoj.pdf
- http://segurixuzek.myartsonline.com/bmw_navigator_v.pdf
- http://kakasis.onlinewebshop.net/zefakoligaretagovamamaxe.pdf
- http://tosurok.myartsonline.com/matulobawijegudexem.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
- http://scripts.sil.org/OFL
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0001eaf9.binc86084f208148ce32e652e3686427593b152fc3827e335b5245cdc69ecb04787 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x1EAF9 | 5192 bytes |
font_01_sfnt_off0001fcad.binbf5cf8251ef22759dbb7a0d6d46de3a19426b5c8ca83a966260982edd56c8f61 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x1FCAD | 11716 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.