Malicious PDF — malware analysis report

Static analysis result for SHA-256 9176e1cec2529a96…

MALICIOUS

PDF

357.3 KB Created: 2015-08-24 04:40:09 +03:00 Authoring application: wkhtmltopdf 0.12.2.4 (via Qt 4.8.6)
MD5: 0cca77b0b125217bdbf57d88f0b36723 SHA-1: 03e27bbbd751a9301999119068db3224dcf576b3 SHA-256: 9176e1cec2529a960f2753d9e8bdacdae1b4d0c62e9fb14e52360fafa57336d9
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a critical heuristic firing for a malicious redirector link pointing to botcraftman.ru. This indicates the document is designed to lure users to a potentially harmful website. The ML classifier also strongly flagged this PDF as malicious. No scripts were extracted from this sample, but the embedded URL is sufficient evidence of malicious intent.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9951

Heuristics 2

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://botcraftman.ru/?lip&keyword=%D1%81%D0%B0%D0%BC%D1%8B%D0%B5+%D0%BD%D0%BE%D0%B2%D1%8B%D0%B5+%D1%83%D0%B7%D0%B1%D0%B5%D0%BA%D1%81%D0%BA%D0%B8%D0%B5+%D1%84%D0%B8%D0%BB%D1%8C%D0%BC%D1%8B+2015+%D0%BD%D0%B0+%D1%80%D1%83%D1%81%D1%81%D0%BA%D0%BE%D0%BC+%D1%8F%D0%B7%D1%8B%D0%BA%D0%B5&charset=utf-8
    • http://img0.liveinternet.ru/images/attach/c/6//4698/4698907_aktivator__windows__7_.pdf
    • http://img0.liveinternet.ru/images/attach/c/6//4692/4692981_skachat__igru__god_.pdf
    • http://img1.liveinternet.ru/images/attach/c/6//4697/4697832_spyhunter__skachat__besplatno_.pdf

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000549e2.bin
39dbf0bb2087596b9ea17808260ff49f24ccc8ba87fef7f213770522edf5077b
pdf-font-stream PDF embedded font (sfnt) at offset 0x549E2 8928 bytes
font_01_sfnt_off0005644b.bin
e031f6b0d1bcb07fa1c37309ab9a92a895feefa23faa92d7a33eac9f8e1d73f9
pdf-font-stream PDF embedded font (sfnt) at offset 0x5644B 16188 bytes