Malicious PDF — malware analysis report

Static analysis result for SHA-256 b69b6ceb38cf9cec…

MALICIOUS

PDF

82.7 KB Created: 2021-06-10 08:24:08 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: ab360e262970ca053f93d1240dd93059 SHA-1: 7af285f69665325365519a11969eed2daca87338 SHA-256: b69b6ceb38cf9ceced09334c14a79630f0a1be698e824ef02cb9919261a3faa1
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The ML classifier and ClamAV detection strongly indicate malicious intent. The PDF contains an embedded URI pointing to 'https://archism.ru/pbw?utm_term=anime+logo+quiz', likely a phishing lure disguised as a quiz. While no scripts were explicitly extracted, the PDF structure and embedded URLs suggest it's designed to redirect users to malicious content, potentially for credential harvesting or further malware delivery.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9925

Heuristics 4

  • ClamAV: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
  • External URI info PDF_URI
    PDF contains an external URL action
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://archism.ru/pbw?utm_term=anime+logo+quiz
    • https://static.s123-cdn-static.com/uploads/4374696/normal_6008d0a31cc80.pdf
    • https://cdn-cms.f-static.net/uploads/4406820/normal_6014ff4fb4b78.pdf
    • https://static.s123-cdn-static.com/uploads/4482849/normal_5fc76dedc2516.pdf
    • https://cdn-cms.f-static.net/uploads/4417305/normal_603eb5c99703c.pdf
    • https://cdn-cms.f-static.net/uploads/4454438/normal_605b4fb0c5e78.pdf
    • https://static.s123-cdn-static.com/uploads/4499636/normal_5fce206511cb9.pdf
    • https://static.s123-cdn-static.com/uploads/4467019/normal_5fe273ee93a7e.pdf
    • https://cdn-cms.f-static.net/uploads/4393204/normal_6012bb8b9810f.pdf
    • https://cdn-cms.f-static.net/uploads/4421352/normal_602da64e70b48.pdf
    • https://cdn-cms.f-static.net/uploads/4454973/normal_5fdb78b8b9825.pdf
    • https://cdn-cms.f-static.net/uploads/4465388/normal_603000ab9f951.pdf
    • https://static.s123-cdn-static.com/uploads/4367305/normal_6009abdaaf235.pdf
    • https://cdn-cms.f-static.net/uploads/4461767/normal_6054ecd010540.pdf
    • https://cdn-cms.f-static.net/uploads/4494677/normal_6016b8a7c13ad.pdf
    • https://cdn-cms.f-static.net/uploads/4481994/normal_60184911b6cbe.pdf
    • https://cdn-cms.f-static.net/uploads/4376874/normal_60384092a71da.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • http://fadoposapat.pbworks.com/f/37678880575.pdf
    • https://uploads.strikinglycdn.com/files/5bb9f4db-3099-4c45-abe1-a547751c13ea/vabafikubenir.pdf
    • http://dokajawema.pbworks.com/w/file/fetch/144908109/activate_uan_with_mobile_number.pdf
    • http://kiwuwas.pbworks.com/f/73950143695.pdf
    • https://uploads.strikinglycdn.com/files/1cefc3c1-43a0-4937-b426-9ba20d839b49/should_you_capitalize_medical_school.pdf
    • http://dutamaboxiwa.pbworks.com/f/xanadowapokedatet.pdf
    • https://uploads.strikinglycdn.com/files/034d14cd-e0c7-427f-b04e-e93b84469fca/leladize.pdf
    • https://uploads.strikinglycdn.com/files/a797943f-ce8e-40cf-9f51-3e06b4914de3/how_to_use_mainstays_cool_mist_ultrasonic_aroma_diffuser.pdf
    • http://gipomebepate.pbworks.com/f/58315376449.pdf
    • https://uploads.strikinglycdn.com/files/9c553497-edfb-4808-81bd-6c41ff44447a/hannah_arendt_la_banalidad_del_mal.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • https://savannah.gnu.org/projects/freefont/
    • http://www.gnu.org/licenses/
    • http://www.gnu.org/copyleft/gpl.html
    • http://scripts.sil.org/OFL
    • http://dejavu.sourceforge.net
    • http://dejavu.sourceforge.net/wiki/index.php/License

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000e01c.bin
e7f5b9a0c5ad66e3ce1df0e1b2e0193eca876227d73dc655b15a827f831a9d71
pdf-font-stream PDF embedded font (sfnt) at offset 0xE01C 6652 bytes
font_01_sfnt_off0000f0a8.bin
c9d3e9d5d4d95373a6035a13a556d6290929757ce9d8371792341699c7d3f214
pdf-font-stream PDF embedded font (sfnt) at offset 0xF0A8 4684 bytes
font_02_sfnt_off0001008d.bin
5dbbcf4054427a2cfe94bf864416ac76c4c428fa8bc2535b1c6d64ed04cfefb5
pdf-font-stream PDF embedded font (sfnt) at offset 0x1008D 11600 bytes
font_03_sfnt_off000127d4.bin
9b0113bd47d51e67e7d3a5b688c4474dacfd10e7a17bb9aa8112279be01621c9
pdf-font-stream PDF embedded font (sfnt) at offset 0x127D4 16180 bytes