Malicious PDF — malware analysis report

Static analysis result for SHA-256 74f9189a34c90615…

MALICIOUS

PDF

355.2 KB Created: 2015-08-23 20:59:40 +03:00 Authoring application: wkhtmltopdf 0.12.2.4 (via Qt 4.8.6)
MD5: de930cd10c8f3d053e4e8d5220555501 SHA-1: 85a6eb2ae607046997262608ec8d3f4b675c1bc5 SHA-256: 74f9189a34c90615673a4aceade4cce0e3de1fb2fa9f9bc3d2e1ed58af796ce5
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a link to a known malicious redirector, indicating an attempt to lead the user to a harmful site. The ML classifier also flagged this PDF with high confidence. The embedded URL is likely intended to deliver a second-stage payload or phish for credentials.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9980

Heuristics 2

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://botcraftman.ru/?lip&keyword=borland+delphi+7+%D1%81%D0%BA%D0%B0%D1%87%D0%B0%D1%82%D1%8C+%D0%B1%D0%B5%D1%81%D0%BF%D0%BB%D0%B0%D1%82%D0%BD%D0%BE+%D0%BF%D1%80%D0%BE%D0%B3%D1%80%D0%B0%D0%BC%D0%BC%D1%83&charset=utf-8
    • http://img0.liveinternet.ru/images/attach/c/6//4690/4690125_temuy__dlya__nokia_.pdf
    • http://img0.liveinternet.ru/images/attach/c/6//4690/4690089_alen__de__botton_.pdf
    • http://img0.liveinternet.ru/images/attach/c/6//4690/4690112_adobe__illustrator__cs5_.pdf

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0005404d.bin
7cc8963aa4e5505c4cd56accb835729dd9e468c43cff14c90225052a9b1d0920
pdf-font-stream PDF embedded font (sfnt) at offset 0x5404D 10284 bytes
font_01_sfnt_off00055c43.bin
84ab201369885512cd3a1b0940e98efa7ea3c13c64cf6b2b87ed1306a01c276c
pdf-font-stream PDF embedded font (sfnt) at offset 0x55C43 16416 bytes