Malicious PDF — malware analysis report

Static analysis result for SHA-256 f3d8cc93c0d26484…

MALICIOUS

PDF

353.2 KB Created: 2015-08-28 11:42:57 +03:00 Authoring application: wkhtmltopdf 0.12.2.4 (via Qt 4.8.6)
MD5: 7d8d36b36d3d13862f21640fbf210ecb SHA-1: 594bd30f0731b1c2c360788bdc1fa5eeeec635c1 SHA-256: f3d8cc93c0d264847e4b91b0e08e76dc5f9fe25c4d11dd876c5c6a3e9ccc8377
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF file contains a critical heuristic firing indicating a link to a known malicious redirector. The embedded URL http://botcraftman.ru/?lip&keyword=%D1%81%D0%BA%D0%B0%D1%87%D0%B0%D1%82%D1%8C+%D1%88%D1%80%D0%B8%D1%84%D1%82+rotonda&charset=utf-8 is the primary indicator of malicious intent. The document body is heavily obfuscated and unreadable, providing no further context on the specific lure. No scripts were extracted from this sample.

Heuristics 2

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://botcraftman.ru/?lip&keyword=%D1%81%D0%BA%D0%B0%D1%87%D0%B0%D1%82%D1%8C+%D1%88%D1%80%D0%B8%D1%84%D1%82+rotonda&charset=utf-8
    • http://img0.liveinternet.ru/images/attach/c/7//4802/4802459_skachat__drayver__dlya_.pdf
    • http://img0.liveinternet.ru/images/attach/c/7//4802/4802604_skachat__igru__css_.pdf
    • http://img0.liveinternet.ru/images/attach/c/7//4802/4802400_zayavlenie__na__vozvrat_.pdf

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00053e3e.bin
20eb857e929004f88d0d98abd6abc916c894dc080d3eef002afb4ae02422d338
pdf-font-stream PDF embedded font (sfnt) at offset 0x53E3E 8668 bytes
font_01_sfnt_off00055670.bin
2039ec9baadbd9c4e154f52fe0c0795c2af12484b23152825a71e5b049388a08
pdf-font-stream PDF embedded font (sfnt) at offset 0x55670 15228 bytes