Malicious PDF — malware analysis report

Static analysis result for SHA-256 c6846a8abed50e08…

MALICIOUS

PDF

187.7 KB Created: 2015-08-06 13:24:46 +03:00 Authoring application: wkhtmltopdf 0.12.2.1 (via Qt 4.8.6) First seen: 2021-10-02
MD5: a6589fef56a2479ec2a7ddcf4ac43f68 SHA-1: 9b9b3c59698524e3774dc3a6241c7cd98aff8fa7 SHA-256: c6846a8abed50e08e28d282e06f30d55f679cc22aacd2e4bbd156a4d513c0817
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

This PDF document was flagged as malicious by an ML classifier. The file routes users through malicious redirector infrastructure. Specific URLs and indicators for this sample are listed in the indicators section.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9980

Heuristics 2

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://botcraftman.ru/?lip&keyword=%D1%81%D0%BA%D0%B0%D1%87%D0%B0%D1%82%D1%8C+%D0%BF%D0%BB%D0%B5%D0%B5%D1%80+%D0%B4%D0%BB%D1%8F+%D0%BF%D1%80%D0%BE%D1%81%D0%BC%D0%BE%D1%82%D1%80%D0%B0+%D0%B2%D0%B8%D0%B4%D0%B5%D0%BE+%D0%B2%D1%81%D0%B5%D1%85+%D1%84%D0%BE%D1%80%D0%BC%D0%B0%D1%82%D0%BE%D0%B2+%D0%B4%D0%BB%D1%8F+%D0%B0%D0%BD%D0%B4%D1%80%D0%BE%D0%B8%D0%B4&charset=utf-8 In PDF document text
    • http://fastpic.ru/In PDF document text
    • http://www.liveinternet.ru/clickIn PDF document text
    • http://img1.liveinternet.ru/images/attach/c/6//4305/4305192_konfiguraciya_1s_82_torgovlya_i_sklad_skachat.pdfIn PDF document text
    • http://img1.liveinternet.ru/images/attach/c/6//4305/4305440_programmuy_besplatno_skachat_bez_registracii.pdfIn PDF document text
    • http://img1.liveinternet.ru/images/attach/c/6//4309/4309857_gta_4_skachat_torrent_na_kompyuter.pdfIn PDF document text
    • http://www.microsoft.com/typography/fonts/In PDF document text
    • http://www.microsoft.com/typography/fonts/YouIn PDF document text

Extracted artifacts 6

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00024b19.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x24B19 3556 bytes
SHA-256: 880e53e6f12106514012eaabb19a261b9f8ae03d695445fc59a5b9b5a1293281
font_01_sfnt_off0002589c.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x2589C 14440 bytes
SHA-256: c1e7c74901246c7898ee412aa2bfca71e5771629f6e1d0cc3c0c61ba7f5373df
font_02_sfnt_off000285cc.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x285CC 14532 bytes
SHA-256: a6626c0bd3595dc776735a93968cf26fa9368d0e017313712711ccf7ec06347e
font_03_sfnt_off0002b0bc.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x2B0BC 7004 bytes
SHA-256: fcf0402067cdd4085baeaef27e396200f14cd3d3aee384e6db94acc7daf46ae1
font_04_sfnt_off0002c519.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x2C519 6084 bytes
SHA-256: 819f9cc5156bfe3dae03045446d677a19b5879270357875344f9514601da73e3
font_05_sfnt_off0002d4ae.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x2D4AE 3752 bytes
SHA-256: 9364d8c42993f0db1eb41a63b15a48dd56cef5056a611ab8e91dd81183a5a95e