MALICIOUS
136
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
This PDF file was detected as malicious by ClamAV and an ML classifier. It contains a lure related to 'Demon Slayer' and redirects to a phishing site. The PDF_SEO_UTM_REDIRECTOR_LINK heuristic indicates the primary purpose is to redirect users to a potentially malicious URL for phishing or malware distribution. No scripts were extracted from this sample, but the embedded URLs are the primary indicators of compromise.
Machine Learning
- Nyx PDF Classifier malicious score 0.9793
Heuristics 5
-
ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTIONClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
-
Image lure linking to an SEO redirector (free-download phishing) high PDF_SEO_UTM_REDIRECTOR_LINKPDF embeds an image with little or no body text and a clickable link to a multi-word utm_term / FeedBurner-proxied SEO redirector — the 'free ebook / solution-manual / document download' phishing family that ranks for natural-language search queries and routes the user into a payload/redirect chain. The PDF carries no exploit; the risk is the linked destination. Flagged structurally (image lure + SEO redirector) so it does not depend on a ClamAV/ML signature, and regardless of how many filler text pages the lure carries.
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://maypoin.ru/wix?keyword=demon+slayer+english+dub+crunchyroll PDF link annotation
- https://cdn-cms.f-static.net/uploads/4479470/normal_603c483dc6145.pdfIn PDF document text
- http://kolagozisil.mywebcommunity.org/71251025751.pdfIn PDF document text
- http://sedouche.xyz/budanezalodebixenamlag4l.pdfIn PDF document text
- https://cdn.sqhk.co/duxajoje/RjehiI3/octopus_apple_watch_band.pdfIn PDF document text
- http://cryogen.me/9739418656684jsr.pdfIn PDF document text
- https://static.s123-cdn-static.com/uploads/4412160/normal_600724822afeb.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4445104/normal_601469f492537.pdfIn PDF document text
- https://cdn.sqhk.co/buwuvibija/gihjrhb/53663045151.pdfIn PDF document text
- https://static.s123-cdn-static.com/uploads/4420238/normal_5feefffdb6505.pdfIn PDF document text
- https://static.s123-cdn-static.com/uploads/4404727/normal_5fdfb984c8c6d.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4459777/normal_602660cca482f.pdfIn PDF document text
- https://cdn.sqhk.co/zotenejek/Vid0Zif/majara.pdfIn PDF document text
- https://cdn-cms.f-static.net/uploads/4446921/normal_5fe6e30d04866.pdfIn PDF document text
- http://purpless.vip/muwopvy12y.pdfIn PDF document text
- https://cdn.sqhk.co/gepeduvo/fVYjhju/latest_bollywood_movies_2019_site.pdfIn PDF document text
- http://gomijexa.mywebcommunity.org/salmos_himnos_y_canticos_espirituales.pdfIn PDF document text
- http://www.ascendercorp.com/In PDF document text
- http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
- https://9a4b5e96-23fe-4021-9525-787506808755.filesusr.com/ugd/b3318b_a7d1799d0e3f455cbbf3557e15f3130b.pdf?index=trueIn PDF document text
- https://5a8aee2d-3d68-4c09-98ed-743c9c56d6fd.filesusr.com/ugd/460efe_f10f5c52e2474d7c9d311fd95b4001f0.pdf?index=trueIn PDF document text
- https://828c6a01-da61-4814-986a-f72e64f4f334.filesusr.com/ugd/cdfdba_ceca93dff9eb4ddf9c49d5ee8d8f3cbc.pdf?index=trueIn PDF document text
- http://nakixaxev.myartsonline.com/niwujugepaxuvoribiwaro.pdfIn PDF document text
- http://sukokovevaz.atwebpages.com/how_to_control_volume_with_xfinity_remote_app.pdfIn PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/xap/1.0/rights/In PDF document text
- http://scripts.sil.org/OFLIn PDF document text
- http://dejavu.sourceforge.netIn PDF document text
- http://dejavu.sourceforge.net/wiki/index.php/LicenseIn PDF document text
Extracted artifacts 5
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
stream_004_off0001a574.bin |
decompressed-pdf-stream | PDF FlateDecoded stream at offset 0x1A574 | 84688 bytes |
SHA-256: a8849b7e48b48bfd016398a03f0c68852310f19ae80a47394242f02cb80f3cd1 |
|||
font_01_sfnt_off0002a3bf.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x2A3BF | 5592 bytes |
SHA-256: adf99ef053ee8f80d0db860227ca94aae89fed84655c5e627d6a2477d2db3e3e |
|||
font_02_sfnt_off0002b699.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x2B699 | 3808 bytes |
SHA-256: bcf0525a7ff1c385a634afb4a0a8e98e8db92e66724ea927753ff641b0df7c6c |
|||
font_03_sfnt_off0002c57f.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x2C57F | 12588 bytes |
SHA-256: 9975949f881925a1e82326c1f9e710eca70afc39af60bd960d7045356bb0ca6e |
|||
font_04_sfnt_off0002efc6.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x2EFC6 | 16376 bytes |
SHA-256: 6cbe3ac9e172e8bae055fba86092fcd672f61555ab01df205b93e20211473cad |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.