Malicious PDF — malware analysis report

Static analysis result for SHA-256 b5feab7464f1e046…

MALICIOUS

PDF

144.7 KB Created: 2015-08-19 17:10:04 +03:00 Authoring application: wkhtmltopdf 0.12.2.4 (via Qt 4.8.6)
MD5: 0660ae95f78ff1c02eaff7c9ec925e2d SHA-1: 1cddc045c530e938bbb48563662a5464144327a9 SHA-256: b5feab7464f1e046531556e0cffe48bdb012861f59a2b9b1a152345efbc4bf36
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a link to a known malicious redirector, indicating a phishing or malware delivery attempt. The heuristic 'PDF_MALICIOUS_REDIRECTOR_LINK' directly supports this. The embedded URL 'http://botcraftman.ru/?lip&keyword=avangard&charset=utf-8' is flagged as malicious. No scripts were extracted, limiting further analysis of the payload.

Machine Learning

  • Nyx PDF Classifier clean score 0.1790

Heuristics 2

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://botcraftman.ru/?lip&keyword=avangard&charset=utf-8
    • http://img0.liveinternet.ru/images/attach/c/6//4628/4628485_zvezdnaya_elena_katriona_4_voshod_chernoy_zvezduy_chitat.pdf
    • http://img1.liveinternet.ru/images/attach/c/6//4627/4627956_annet_larkins_put_k_zdorovyu_skachat_knigu.pdf
    • http://img0.liveinternet.ru/images/attach/c/6//4628/4628150_kvn_luchshee_skachat_torrent.pdf

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0001fedc.bin
8b18cfb340591e07e0ec614512d63ac34012dd52374ceaf80cb7a4c09b7a6276
pdf-font-stream PDF embedded font (sfnt) at offset 0x1FEDC 8808 bytes
font_01_sfnt_off00021842.bin
92e904d4385106daa610952e4c6e2756a62318e1cc3180981290715f51ea946c
pdf-font-stream PDF embedded font (sfnt) at offset 0x21842 13972 bytes