Malicious PDF — malware analysis report

Static analysis result for SHA-256 a6bcfed1602bb2b7…

MALICIOUS

PDF

361.0 KB Created: 2015-08-26 09:52:05 +03:00 Authoring application: wkhtmltopdf 0.12.2.4 (via Qt 4.8.6)
MD5: 0eac1ac1bc3fc635ac300f735975b34b SHA-1: 161ec6b5ae59034fa4e1db54cfafc7a80b4e4668 SHA-256: a6bcfed1602bb2b77981b3b5c0fae76862ffefe1c30ee461ad051bde5cc95eed
90 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell T1204.002 Malicious Link

The PDF file contains a link to a known malicious redirector, indicating an attempt to deliver a payload. The ML classifier also flagged the document with high confidence. The document body is heavily obfuscated and unreadable, but the presence of the malicious link is sufficient to determine the attack pattern. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9979

Heuristics 2

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://botcraftman.ru/?lip&keyword=%D1%81%D0%BA%D0%B0%D1%87%D0%B0%D1%82%D1%8C+%D0%B1%D0%B5%D1%81%D0%BF%D0%BB%D0%B0%D1%82%D0%BD%D0%BE+%D0%B0%D0%BD%D1%82%D0%B8%D0%B2%D0%B8%D1%80%D1%83%D1%81+avast+%D0%BD%D0%B0+%D1%80%D1%83%D1%81%D1%81%D0%BA%D0%BE%D0%BC+%D1%8F%D0%B7%D1%8B%D0%BA%D0%B5&charset=utf-8
    • http://img0.liveinternet.ru/images/attach/c/7//4752/4752002_skachat__temuy__dlya_.pdf
    • http://img1.liveinternet.ru/images/attach/c/7//4751/4751783_peterson__raz__stupenka_.pdf
    • http://img1.liveinternet.ru/images/attach/c/7//4751/4751919_sugar__bytes__cyclop_.pdf

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00055cf1.bin
6d5f1bdf835da24ee2e0499de48144b41eab8d7fdf18a3e00f863562148eb099
pdf-font-stream PDF embedded font (sfnt) at offset 0x55CF1 8540 bytes
font_01_sfnt_off00057535.bin
ae74f831f167815434048f6aa0f04c6f2c072f310a4b271c12be8c05766af276
pdf-font-stream PDF embedded font (sfnt) at offset 0x57535 15768 bytes