Malicious PDF — malware analysis report

Static analysis result for SHA-256 2130c3353e5b5c20…

MALICIOUS

PDF

378.3 KB Created: 2015-08-28 18:25:09 +03:00 Authoring application: wkhtmltopdf 0.12.2.4 (via Qt 4.8.6)
MD5: f64ef3be3c4c5c481f01427e25b7fa3d SHA-1: 1fa170b9aa6f1cc216c13b5941afc47bfd50fde7 SHA-256: 2130c3353e5b5c201fa240da690f6d9a5ed25344b60ddafec8830c17926552f2
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains an embedded link to a known malicious redirector, botcraftman.ru. This indicates the document is designed to lure users to a malicious site, likely for phishing or malware delivery. The ML classifier also strongly flagged this PDF as malicious. No scripts were extracted, but the primary malicious functionality appears to be the redirection via the embedded URL.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9974

Heuristics 2

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://botcraftman.ru/?lip&keyword=%D0%B2+%D0%BA%D0%B5%D0%B9%D0%BF%D1%82%D0%B0%D1%83%D0%BD%D1%81%D0%BA%D0%BE%D0%BC+%D0%BF%D0%BE%D1%80%D1%82%D1%83+%D0%BD%D0%BE%D1%82%D1%8B&charset=utf-8
    • http://img0.liveinternet.ru/images/attach/c/7//4810/4810171_shtrih__kod_.pdf
    • http://img1.liveinternet.ru/images/attach/c/7//4809/4809320_skachat__navigator__na_.pdf
    • http://img1.liveinternet.ru/images/attach/c/7//4809/4809777_sled__salamandruy__skachat_.pdf

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0005a912.bin
bbcd76cd9895e371763a67d6dec31f5170ec00e0b797b5ab2ddf55cfd3e8399c
pdf-font-stream PDF embedded font (sfnt) at offset 0x5A912 7460 bytes
font_01_sfnt_off0005be24.bin
274b01700aeb178cfd8b4b5f172e144d331b5cfef1911cb6a3997790111f4864
pdf-font-stream PDF embedded font (sfnt) at offset 0x5BE24 13676 bytes