Malicious PDF — malware analysis report

Static analysis result for SHA-256 d3c2c8ba7f164591…

MALICIOUS

PDF

338.6 KB Created: 2015-08-20 14:09:03 +03:00 Authoring application: wkhtmltopdf 0.12.2.4 (via Qt 4.8.6)
MD5: 90d086c2856c2eed7f6621b651564fbb SHA-1: 7c39d873c5493759c55eaccfdf2e9e253f12233a SHA-256: d3c2c8ba7f1645917c89693fd86617a201f90afedf0ab5b45bea32158a527174
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains an embedded link to a known malicious redirector. This indicates the document is intended to lure users to a harmful website. The PDF itself appears to be malformed or obfuscated, making it difficult to extract meaningful document body content. The primary malicious indicator is the redirector URL, which is likely used to deliver a secondary payload or conduct phishing.

Heuristics 2

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://botcraftman.ru/?lip&keyword=%D1%8D%D0%BA%D1%81%D0%B5%D0%BB%D1%8C+2007+%D1%81%D0%BA%D0%B0%D1%87%D0%B0%D1%82%D1%8C+%D0%B1%D0%B5%D1%81%D0%BF%D0%BB%D0%B0%D1%82%D0%BD%D0%BE&charset=utf-8
    • http://img0.liveinternet.ru/images/attach/c/6//4644/4644637_andrey_dyakov_za_gorizont_audiokniga_torrent.pdf
    • http://img0.liveinternet.ru/images/attach/c/6//4642/4642565_fast_for_word_skachat_besplatno_2013.pdf
    • http://img0.liveinternet.ru/images/attach/c/6//4642/4642143_skachat_igru_morskoy_boy_na_kompyuter_besplatno_cherez_torrent.pdf

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00050601.bin
c406deb871d1ab296b8649ebb0827d1956c8a98a4ed618e702bf3a31748d185b
pdf-font-stream PDF embedded font (sfnt) at offset 0x50601 7756 bytes
font_01_sfnt_off00051cd1.bin
11caa14e1e6fd0664550f377c618ffadbbab5055a6e459d8bf84bd4daa59373f
pdf-font-stream PDF embedded font (sfnt) at offset 0x51CD1 14736 bytes