Malicious PDF — malware analysis report

Static analysis result for SHA-256 3a37d998423c53ec…

MALICIOUS

PDF

341.4 KB Created: 2015-08-28 11:45:25 +03:00 Authoring application: wkhtmltopdf 0.12.2.4 (via Qt 4.8.6)
MD5: 65e201c916444a605b9e5474e1c2049f SHA-1: 7c866c9926da71b0230cf7d18f73d1fa2a26fe97 SHA-256: 3a37d998423c53ec9a5019e4f3d0fed566de1bc57615a4c2084b354b539253e2
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a link to a known malicious redirector, botcraftman.ru. This indicates the document is likely part of a phishing or malware distribution campaign. The presence of this malicious link is the primary indicator of compromise. No scripts were extracted from this sample, limiting further analysis of its behavior.

Heuristics 2

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://botcraftman.ru/?lip&keyword=Corel+photo+paint+%D1%81%D0%BA%D0%B0%D1%87%D0%B0%D1%82%D1%8C+%D0%B1%D0%B5%D1%81%D0%BF%D0%BB%D0%B0%D1%82%D0%BD%D0%BE+%D1%82%D0%BE%D1%80%D1%80%D0%B5%D0%BD%D1%82&charset=utf-8
    • http://img0.liveinternet.ru/images/attach/c/7//4802/4802524_skachat__shema__bloka_.pdf
    • http://img0.liveinternet.ru/images/attach/c/7//4802/4802440_kak__otklyuchit__cenzuru_.pdf
    • http://img0.liveinternet.ru/images/attach/c/7//4802/4802426_programma__dlya__nablyudeniya_.pdf

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00050ddf.bin
b83de82c6f99349805473bc161bff029acd8ec68f16ba2d71eca8d8c39494cbd
pdf-font-stream PDF embedded font (sfnt) at offset 0x50DDF 9164 bytes
font_01_sfnt_off000526f8.bin
2cb0c79aa57522527a9cf8fe909228bc8d36d075cde51f7e1fa8e527a7aa2e55
pdf-font-stream PDF embedded font (sfnt) at offset 0x526F8 15556 bytes