Malicious PDF — malware analysis report

Static analysis result for SHA-256 88a12472314ff9f2…

MALICIOUS

PDF

366.9 KB Created: 2015-08-23 21:05:59 +03:00 Authoring application: wkhtmltopdf 0.12.2.4 (via Qt 4.8.6)
MD5: f58674f2aac97319ec3443231d4a7c65 SHA-1: d95d2d62dce5a90c31fca5d72a08e9554f89d8c0 SHA-256: 88a12472314ff9f266fa272e8bf8f68d6f23162497dc8e85a1e205854dd06e2c
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a link to a known malicious redirector. The ML classifier also flagged this PDF with high confidence. The embedded URL is the primary indicator of malicious intent, likely serving as a lure to a phishing or malware distribution site.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9975

Heuristics 2

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://botcraftman.ru/?lip&keyword=%D1%81%D0%BA%D0%B0%D1%87%D0%B0%D1%82%D1%8C+%D0%B0%D0%BB%D1%8C%D0%B1%D0%BE%D0%BC+zippo+%D0%BD%D0%B5%D0%B7%D0%B0%D0%B1%D1%8B%D0%B2%D0%B0%D0%B5%D0%BC%D0%BE&charset=utf-8
    • http://img0.liveinternet.ru/images/attach/c/6//4690/4690190_portfolio__doshkolnika__shablonuy_.pdf
    • http://img0.liveinternet.ru/images/attach/c/6//4690/4690174_luchshaya__noch__tekst_.pdf
    • http://img0.liveinternet.ru/images/attach/c/6//4690/4690080_francuzskie__deti__ne_.pdf

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000573b2.bin
278f8df9f0a9c4833728a75e3f99e24407bdfcf724dd5205e8d8d83e90a3e932
pdf-font-stream PDF embedded font (sfnt) at offset 0x573B2 9648 bytes
font_01_sfnt_off00058f62.bin
af9925203c46c802fb2e59b424cfb7beb118cae9134529a13345bb81b0f4015e
pdf-font-stream PDF embedded font (sfnt) at offset 0x58F62 14120 bytes