Malicious PDF — malware analysis report

Static analysis result for SHA-256 e026195e94da048d…

MALICIOUS

PDF

348.6 KB Created: 2015-08-28 11:39:06 +03:00 Authoring application: wkhtmltopdf 0.12.2.4 (via Qt 4.8.6)
MD5: 22a524c3b98597232c878af3d9878753 SHA-1: b8caaef01e71ad4f375dbb8af870d5677e843466 SHA-256: e026195e94da048d36e864ee40c05399cd1ac41ff3ae4006df5312fe45627f85
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a link to a known malicious redirector, botcraftman.ru. This indicates an attempt to lure the user to a harmful site. The ML classifier also flagged this PDF with high confidence. No scripts were extracted, and the document body was heavily obfuscated, limiting further analysis of the specific lure.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9979

Heuristics 2

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://botcraftman.ru/?lip&keyword=%D1%81%D0%BA%D0%B0%D1%87%D0%B0%D1%82%D1%8C+%D1%81+e-disk+%D0%BF%D0%BE+ftp&charset=utf-8
    • http://img0.liveinternet.ru/images/attach/c/7//4802/4802519_super__su_.pdf
    • http://img0.liveinternet.ru/images/attach/c/7//4802/4802459_skachat__drayver__dlya_.pdf
    • http://img0.liveinternet.ru/images/attach/c/7//4802/4802533_skachat__hd__skin_.pdf

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0005254f.bin
dc4d0a4746f6ac23a169738692dfdc9cbadac293c7dbd05000e6a173957b2446
pdf-font-stream PDF embedded font (sfnt) at offset 0x5254F 8672 bytes
font_01_sfnt_off00053e1a.bin
dc99fe3a2e6e687ac65ebb7314dc984708d8533c3f311ff160b2e71733dc72b3
pdf-font-stream PDF embedded font (sfnt) at offset 0x53E1A 17540 bytes