Malicious PDF — malware analysis report

Static analysis result for SHA-256 a3f4a61af26a57e7…

MALICIOUS

PDF

185.6 KB Created: 2015-07-27 14:02:20 +03:00 Authoring application: wkhtmltopdf 0.12.2.1 (via Qt 4.8.6)
MD5: 2bb4bcfc2425683d4a65a92197424994 SHA-1: 0a76d108c5d70adb41b2beb86c6af25e9bbe45f5 SHA-256: a3f4a61af26a57e7bd139b9b8c2e0be4d9c7ed5e037f1e1f0789d6b1abdd3639
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF document was flagged by a critical heuristic for linking to known malicious redirector infrastructure. The ML classifier also strongly indicated maliciousness. The embedded URL points to botcraftman.ru, which is associated with malicious redirects. No scripts were extracted, but the primary attack vector appears to be the malicious link within the PDF.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9982

Heuristics 2

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://botcraftman.ru/?lip&keyword=%D1%81%D0%BA%D0%B0%D1%87%D0%B0%D1%82%D1%8C+%D0%B1%D1%80%D0%B0%D1%83%D0%B7%D0%B5%D1%80+tor+%D0%BD%D0%B0+%D1%80%D1%83%D1%81%D1%81%D0%BA%D0%BE%D0%BC+%D1%8F%D0%B7%D1%8B%D0%BA%D0%B5&charset=utf-8
    • http://fastpic.ru/
    • http://www.liveinternet.ru/click
    • http://img0.liveinternet.ru/images/attach/c/5//4214/4214392_rimskie_priklyucheniya_skachat_torrent.pdf
    • http://img1.liveinternet.ru/images/attach/c/5//4205/4205956_fotofusion_skachat_besplatno_russkaya_versiya_torrent.pdf
    • http://img1.liveinternet.ru/images/attach/c/5//4191/4191636_skachat_antivirus_dlya_windows_phone_8.pdf

Extracted artifacts 6

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00024108.bin
880e53e6f12106514012eaabb19a261b9f8ae03d695445fc59a5b9b5a1293281
pdf-font-stream PDF embedded font (sfnt) at offset 0x24108 3556 bytes
font_01_sfnt_off00024e8b.bin
792915573bc8b2806d74aac5989996ee6a22943ae5b71093e02c31a969bf15a9
pdf-font-stream PDF embedded font (sfnt) at offset 0x24E8B 14844 bytes
font_02_sfnt_off00027d03.bin
3a3ff6537071da6d467eaf54d531e0e4d26fc3444f24e79a32bbb0659052416d
pdf-font-stream PDF embedded font (sfnt) at offset 0x27D03 14576 bytes
font_03_sfnt_off0002a815.bin
850ec1d7dbe9701f301d822a18f219f1e95da9114139fed15fcaa32a82749255
pdf-font-stream PDF embedded font (sfnt) at offset 0x2A815 7104 bytes
font_04_sfnt_off0002bcc9.bin
819f9cc5156bfe3dae03045446d677a19b5879270357875344f9514601da73e3
pdf-font-stream PDF embedded font (sfnt) at offset 0x2BCC9 6084 bytes
font_05_sfnt_off0002cc5e.bin
9364d8c42993f0db1eb41a63b15a48dd56cef5056a611ab8e91dd81183a5a95e
pdf-font-stream PDF embedded font (sfnt) at offset 0x2CC5E 3752 bytes