Malicious PDF — malware analysis report

Static analysis result for SHA-256 110a297a2d810aa1…

MALICIOUS

PDF

354.7 KB Created: 2015-08-28 13:43:27 +03:00 Authoring application: wkhtmltopdf 0.12.2.4 (via Qt 4.8.6)
MD5: d14f2679f0faea98afd15a07ec4a48a5 SHA-1: e7dbc1a2ba94be40b46aab0878e003322e3ad094 SHA-256: 110a297a2d810aa1efec087fdceb5f3e767a368e966b761335e237489cb4fac9
152 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF file was flagged by multiple heuristics, including ClamAV and an ML classifier, as malicious. It contains an embedded URL pointing to 'botcraftman.ru', which is identified as a known malicious redirector. This suggests the document's primary purpose is to lure the user to this malicious site, likely to initiate a download or phishing attempt. No scripts were extracted, but the presence of a malicious redirector strongly indicates a dropper or downloader functionality.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9800

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • ClamAV: Pdf.Dropper.Agent-8954570-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Dropper.Agent-8954570-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://botcraftman.ru/?lip&keyword=%D1%81%D0%BA%D0%B0%D1%87%D0%B0%D1%82%D1%8C+%D0%BF%D1%80%D0%BE%D0%B3%D1%80%D0%B0%D0%BC%D0%BC%D1%83+%D0%B4%D0%BB%D1%8F+%D0%B7%D0%B0%D0%BF%D0%B8%D1%81%D0%B8+%D0%BF%D0%B5%D1%81%D0%B5%D0%BD+%D0%BD%D0%B0+%D1%80%D1%83%D1%81%D1%81%D0%BA%D0%BE%D0%BC&charset=utf-8
    • http://img0.liveinternet.ru/images/attach/c/7//4804/4804365_skachat__igru__papinuy_.pdf
    • http://img0.liveinternet.ru/images/attach/c/7//4804/4804092_mne__tebya__obeschali_.pdf
    • http://img1.liveinternet.ru/images/attach/c/7//4803/4803200_anatomicheskiy__atlas__cheloveka_.pdf

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000546b7.bin
f19429786c14af0362e0bc608d24677e6ac9b07187e77b64f6ded72cc094889d
pdf-font-stream PDF embedded font (sfnt) at offset 0x546B7 7960 bytes
font_01_sfnt_off00055e0e.bin
f36ec336063241bc7aed078ac2398e3700c009f5e3500a634ae09029966f0e97
pdf-font-stream PDF embedded font (sfnt) at offset 0x55E0E 14256 bytes