Malicious PDF — malware analysis report

Static analysis result for SHA-256 74e3e036f2c2552e…

MALICIOUS

PDF

355.1 KB Created: 2015-08-22 08:54:18 +03:00 Authoring application: wkhtmltopdf 0.12.2.4 (via Qt 4.8.6)
MD5: 5db0cd7e65b1c2621e57bc002b8e3b4d SHA-1: 472752fd0423b3255dd3ec8e4e171df3feb2aaab SHA-256: 74e3e036f2c2552ef63d4a784a463d9e0203d1fc9e517c49d2be05af40f5a6e5
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains an embedded URL that is flagged as a known malicious redirector. The ML classifier also strongly indicated maliciousness. The document body is heavily obfuscated and unreadable, but the presence of the malicious URL suggests an attempt to lure the user to a harmful site, likely for phishing or malware delivery.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9980

Heuristics 2

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://botcraftman.ru/?lip&keyword=%D0%B2%D0%B0%D0%B4%D0%B8%D0%BC+%D0%BF%D0%B0%D0%BD%D0%BE%D0%B2+%D0%B4%D0%B8%D0%BA%D0%B8%D0%B5+%D0%BF%D0%B5%D1%80%D1%81%D1%8B+%D1%81%D0%BA%D0%B0%D1%87%D0%B0%D1%82%D1%8C+fb2&charset=utf-8
    • http://img0.liveinternet.ru/images/attach/c/6//4674/4674487_bonus_kod_world_of_tanks_2015_na_noyabr.pdf
    • http://img0.liveinternet.ru/images/attach/c/6//4674/4674503_allj_yeldzhey_skachat_albom_torrent.pdf
    • http://img0.liveinternet.ru/images/attach/c/6//4674/4674499_maykrosoft_ofis_2007_skachat_besplatno_bez_klyucha.pdf

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0005418a.bin
82cd424ad3492a4b36a62d915e53366e9f5a8bd58db17e7cda2d388098a34352
pdf-font-stream PDF embedded font (sfnt) at offset 0x5418A 8960 bytes
font_01_sfnt_off00055b2c.bin
77d58952408da184f5a44fbc8b481e8fdc3129c48e3a4927ac080151159326f2
pdf-font-stream PDF embedded font (sfnt) at offset 0x55B2C 16316 bytes