Malicious PDF — malware analysis report

Static analysis result for SHA-256 1994d46df8ca8d2d…

MALICIOUS

PDF

365.3 KB Created: 2015-08-25 22:09:34 +03:00 Authoring application: wkhtmltopdf 0.12.2.4 (via Qt 4.8.6)
MD5: df6ab384c5f2bbd91a9d9e08863bd314 SHA-1: ba47e3d91aeaf4273d2257edcb7216b7ec2d95a5 SHA-256: 1994d46df8ca8d2ddb243f057fde1a1184baf9a92301a47cb635196d9212a290
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a link to a known malicious redirector, botcraftman.ru, which is a strong indicator of malicious intent. The ML classifier also flagged this PDF with high confidence. While no scripts were extracted, the presence of a malicious URL suggests the document is designed to lure the user to a harmful site, likely for phishing or to download further malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9978

Heuristics 2

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://botcraftman.ru/?lip&keyword=%D0%B0%D0%BA%D1%82%D0%B8%D0%B2%D0%B0%D1%82%D0%BE%D1%80+windows+server+2012+r2&charset=utf-8
    • http://img0.liveinternet.ru/images/attach/c/7//4740/4740562_.pdf
    • http://img0.liveinternet.ru/images/attach/c/7//4740/4740568_klyuch__k__igre_.pdf
    • http://img0.liveinternet.ru/images/attach/c/7//4740/4740566_skachat__video__uroki_.pdf

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00056de4.bin
075a51872f85c1c07425778216fd3fa3019455f3ebdd42722f1221dff8b971c5
pdf-font-stream PDF embedded font (sfnt) at offset 0x56DE4 9280 bytes
font_01_sfnt_off000588cd.bin
247103d51a15bf3216657507d6a6b58363a6597f627f67905e5185d274304119
pdf-font-stream PDF embedded font (sfnt) at offset 0x588CD 14416 bytes