Malicious PDF — malware analysis report

Static analysis result for SHA-256 f1a6407af9cc11b5…

MALICIOUS

PDF

186.7 KB Created: 2015-07-24 19:42:26 +03:00 Authoring application: wkhtmltopdf 0.12.2.1 (via Qt 4.8.6)
MD5: 6292862f977c8e060056821f3327b99e SHA-1: 37f6440c99fe6387b2ab64ae205b67b88824560b SHA-256: f1a6407af9cc11b5fb92ed5f337dc4f2bd57778060f64d69f7f53f07c77ffd85
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file was flagged for containing a link to a known malicious redirector. This indicates the document is likely a lure to direct users to a malicious website for phishing or malware delivery. No scripts were extracted, and the document body was largely unreadable binary data, limiting further analysis of the specific content. The primary threat identified is the malicious URL.

Heuristics 2

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://botcraftman.ru/?lip&keyword=%D0%B5%D0%B3%D1%8D+%D0%BF%D0%BE+%D0%BC%D0%B0%D1%82%D0%B5%D0%BC%D0%B0%D1%82%D0%B8%D0%BA%D0%B5+2015+%D0%BE%D0%BD%D0%BB%D0%B0%D0%B9%D0%BD+%D1%81+%D0%BE%D0%B1%D1%8A%D1%8F%D1%81%D0%BD%D0%B5%D0%BD%D0%B8%D0%B5%D0%BC&charset=utf-8
    • http://fastpic.ru/
    • http://www.liveinternet.ru/click
    • http://img1.liveinternet.ru/images/attach/c/5//4191/4191860_skachat_mph_leis_release_05_dlya_cs_16.pdf
    • http://img1.liveinternet.ru/images/attach/c/5//4189/4189721_7_sins_skachat_torrent_s_russkoy_ozvuchkoy.pdf
    • http://img0.liveinternet.ru/images/attach/c/5//4192/4192051_7data_android_recovery_skachat_torrent.pdf

Extracted artifacts 6

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00024593.bin
880e53e6f12106514012eaabb19a261b9f8ae03d695445fc59a5b9b5a1293281
pdf-font-stream PDF embedded font (sfnt) at offset 0x24593 3556 bytes
font_01_sfnt_off00025316.bin
848e55af24b3a51afc8b780ad9294cf48f4e1b666a7b2c1d4927b40ba8c1b872
pdf-font-stream PDF embedded font (sfnt) at offset 0x25316 14932 bytes
font_02_sfnt_off000280f9.bin
d79c01e38840bd03bbae91646ffd406e017c1a7b7ac732465e34f7473cfa0469
pdf-font-stream PDF embedded font (sfnt) at offset 0x280F9 14776 bytes
font_03_sfnt_off0002ac63.bin
fc986274fbe95e12fa5ee6de4178dd422eab99d4524b8d2540cf07d730418d8b
pdf-font-stream PDF embedded font (sfnt) at offset 0x2AC63 7084 bytes
font_04_sfnt_off0002c0eb.bin
819f9cc5156bfe3dae03045446d677a19b5879270357875344f9514601da73e3
pdf-font-stream PDF embedded font (sfnt) at offset 0x2C0EB 6084 bytes
font_05_sfnt_off0002d080.bin
9364d8c42993f0db1eb41a63b15a48dd56cef5056a611ab8e91dd81183a5a95e
pdf-font-stream PDF embedded font (sfnt) at offset 0x2D080 3752 bytes