Malicious PDF — malware analysis report

Static analysis result for SHA-256 f59ebc68e48e8f81…

MALICIOUS

PDF

353.0 KB Created: 2015-08-23 23:21:16 +03:00 Authoring application: wkhtmltopdf 0.12.2.4 (via Qt 4.8.6)
MD5: 9301a554a42ae95a942a76d110c66e2c SHA-1: 148551af6947aecc97fc370b61c3b9b55e188f84 SHA-256: f59ebc68e48e8f811d1da2d22e8d72b1c2692e118069fe001fe8288f892d5662
60 Risk Score

Malware Insights

MITRE ATT&CK
T1059.001 PowerShell

The PDF file contains a critical heuristic firing indicating a link to a known malicious redirector. This suggests the document is designed to lure users to a malicious website. No scripts were extracted, and the document body was heavily obfuscated and truncated, preventing further analysis of the specific lure. The primary IOC is the malicious redirector URL.

Heuristics 2

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://botcraftman.ru/?lip&keyword=%D0%9F%D0%BE%D0%B2%D0%B5%D1%81%D1%82%D0%BA%D0%B0+%D0%B2+%D1%81%D1%83%D0%B4+%D0%BD%D0%B0+%D1%80%D0%B0%D0%B7%D0%B2%D0%BE%D0%B4+%D0%BE%D0%B1%D1%80%D0%B0%D0%B7%D0%B5%D1%86&charset=utf-8
    • http://img0.liveinternet.ru/images/attach/c/6//4692/4692975_odinokiy__pastuh__notuy_.pdf
    • http://img0.liveinternet.ru/images/attach/c/6//4692/4692979_prototype__2__skachat_.pdf

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00053c86.bin
4bffc70fd9fba6adb063a6073f80a2f0d100144ccee151cad697a702b54b9338
pdf-font-stream PDF embedded font (sfnt) at offset 0x53C86 9660 bytes
font_01_sfnt_off000557f6.bin
09de61aba47bef514692d02caec02e1a9b1978cd476fb94331eca1fbb8c0c763
pdf-font-stream PDF embedded font (sfnt) at offset 0x557F6 14856 bytes