Malicious PDF — malware analysis report

Static analysis result for SHA-256 a44b4be7bcbd7d8a…

MALICIOUS

PDF

370.7 KB Created: 2015-08-25 22:20:35 +03:00 Authoring application: wkhtmltopdf 0.12.2.4 (via Qt 4.8.6)
MD5: fefcd3bdcea343d3dba70ab4a3d4e8cd SHA-1: e9dea6553e8509e34118ffcaaa77a1a1501d0980 SHA-256: a44b4be7bcbd7d8a04d09092ea91ef9bf242d83945b9e3a8216fee33501ed1ab
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF file contains a critical heuristic firing indicating a link to a known malicious redirector. The embedded URL http://botcraftman.ru/ is identified as malicious infrastructure. No scripts were extracted from this sample, and the document body was heavily obfuscated and truncated, preventing further analysis of its specific lure. The primary threat appears to be redirection to a malicious site.

Heuristics 2

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://botcraftman.ru/?lip&keyword=powerwolf+%D0%BD%D0%BE%D0%B2%D1%8B%D0%B9+%D0%B0%D0%BB%D1%8C%D0%B1%D0%BE%D0%BC&charset=utf-8
    • http://img0.liveinternet.ru/images/attach/c/7//4740/4740748_skachat__audioknigi__andreya_.pdf
    • http://img0.liveinternet.ru/images/attach/c/7//4740/4740650_skachat__obnovlenie__eset_.pdf
    • http://img0.liveinternet.ru/images/attach/c/7//4740/4740549_win__7__32_.pdf

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000582ff.bin
c7f32cbfd30e445c32b721fad1714e35cd6a1b3cd3b73baff0ae9b54d84bc87f
pdf-font-stream PDF embedded font (sfnt) at offset 0x582FF 8496 bytes
font_01_sfnt_off00059b1a.bin
69d286e782d3e3a98ec0f310bfa71c9a916ac63b627637b509c1eb9b5b9c06cb
pdf-font-stream PDF embedded font (sfnt) at offset 0x59B1A 16192 bytes