Malicious PDF — malware analysis report

Static analysis result for SHA-256 e0f7be48fa8cf372…

MALICIOUS

PDF

140.4 KB Created: 2015-08-26 09:49:39 +03:00 Authoring application: wkhtmltopdf 0.12.2.4 (via Qt 4.8.6)
MD5: 8e5807626e8fe8222f186b3efaa1bbe2 SHA-1: e0cb9b82634e0d3829174cfab901fb6fa49356a2 SHA-256: e0f7be48fa8cf372449718d378df7a1c1df1b0210ad7bce6e4c0ebb8208964e5
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file was flagged as malicious due to a link to a known malicious redirector infrastructure at botcraftman.ru. This suggests the document is designed to lure users to a harmful website. No scripts were extracted from this sample, and the document body was heavily obfuscated, preventing further analysis of its specific intent beyond the malicious link.

Heuristics 2

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://botcraftman.ru/?lip&keyword=720&charset=utf-8
    • http://img1.liveinternet.ru/images/attach/c/7//4751/4751991_honestech__claymation__studio_.pdf
    • http://img1.liveinternet.ru/images/attach/c/7//4751/4751936_skachat__programmu_.pdf
    • http://img1.liveinternet.ru/images/attach/c/7//4751/4751761_skachat__batman__arkham_.pdf

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0001ee85.bin
9c1f1144bd3f6e28d9745bfb9dca6aee6886814eebe40a34d8184588d2458534
pdf-font-stream PDF embedded font (sfnt) at offset 0x1EE85 8052 bytes
font_01_sfnt_off000205da.bin
756bec454b37e4e71311a41d3e9049e96d40e89f4510d9ecc0005336971a89ca
pdf-font-stream PDF embedded font (sfnt) at offset 0x205DA 14812 bytes