Malicious PDF — malware analysis report

Static analysis result for SHA-256 ab3fa1859856a272…

MALICIOUS

PDF

353.7 KB Created: 2015-08-28 11:40:32 +03:00 Authoring application: wkhtmltopdf 0.12.2.4 (via Qt 4.8.6)
MD5: a88470358dec0d1b975f24f0f230f2d0 SHA-1: 6929950fba46cca6ff90736677a1e856b0c593a9 SHA-256: ab3fa1859856a2720b8f30f9885dd46e3e0548d4bc5ed32fe47f06d3b13c7df5
98 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The PDF contains an embedded JavaScript stream and a link to known malicious infrastructure. The ML classifier also flagged this PDF with high confidence. The embedded link, http://botcraftman.ru/?lip&keyword=%D1%82%D0%B5%D0%BB%D0%B5%D1%84%D0%BE%D0%BD%D0%BD%D1%8B%D0%B9+%D1%81%D0%BF%D1%80%D0%B0%D0%B2%D0%BE%D1%87%D0%BD%D0%B8%D0%BA+%D0%BC%D1%8D%D1%80%D0%B8%D0%B8+%D0%B3%D0%BE%D1%80%D0%BE%D0%B4%D1%81%D0%BA%D0%BE%D0%B3%D0%BE+%D0%BE%D0%BA%D1%80%D1%83%D0%B3%D0%B0+%D1%82%D0%BE%D0%BB%D1%8C%D1%82%D1%82%D0%B8&charset=utf-8, likely serves as a redirector to a malicious payload. The presence of embedded JavaScript suggests potential for further malicious actions beyond a simple redirect.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9980

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://botcraftman.ru/?lip&keyword=%D1%82%D0%B5%D0%BB%D0%B5%D1%84%D0%BE%D0%BD%D0%BD%D1%8B%D0%B9+%D1%81%D0%BF%D1%80%D0%B0%D0%B2%D0%BE%D1%87%D0%BD%D0%B8%D0%BA+%D0%BC%D1%8D%D1%80%D0%B8%D0%B8+%D0%B3%D0%BE%D1%80%D0%BE%D0%B4%D1%81%D0%BA%D0%BE%D0%B3%D0%BE+%D0%BE%D0%BA%D1%80%D1%83%D0%B3%D0%B0+%D1%82%D0%BE%D0%BB%D1%8C%D1%8F%D1%82%D1%82%D0%B8&charset=utf-8
    • http://img0.liveinternet.ru/images/attach/c/7//4802/4802536_beatris__smoll__vnezapnuye_.pdf
    • http://img0.liveinternet.ru/images/attach/c/7//4802/4802474_skachat__proshivku__dlya_.pdf
    • http://img0.liveinternet.ru/images/attach/c/7//4802/4802412_vladimir__rackin_.pdf

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00053e62.bin
b2a9e613ca1df24b2c4f9b3a2cee21f19dd67da82aaa2057506d9dc8f2024b9c
pdf-font-stream PDF embedded font (sfnt) at offset 0x53E62 8876 bytes
font_01_sfnt_off0005582f.bin
afaa440fc2c6068746ed1b1d02a2cd319d95c1d9bc49cbb864b3293854327313
pdf-font-stream PDF embedded font (sfnt) at offset 0x5582F 15048 bytes