Malicious PDF — malware analysis report

Static analysis result for SHA-256 f678a65efcfafa1f…

MALICIOUS

PDF

355.5 KB Created: 2015-08-27 15:25:38 +03:00 Authoring application: wkhtmltopdf 0.12.2.4 (via Qt 4.8.6)
MD5: c6add2db30388be169089fa811755c46 SHA-1: 8433cc57b9071028074e5c586cd17aef93f61e84 SHA-256: f678a65efcfafa1f8964c7b10df99a18367bbe6d9773930a40916b99186f83ff
90 Risk Score

Malware Insights

MITRE ATT&CK
T1204.002 Malicious Link

The PDF contains a heuristic firing for a malicious redirector link, pointing to botcraftman.ru. This URL is likely intended to deliver unwanted software or lead to further malicious content. The ML classifier also strongly indicated maliciousness. No scripts were extracted, and the document body was unreadable.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9897

Heuristics 2

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://botcraftman.ru/?lip&keyword=%D0%A1%D0%BA%D0%B0%D1%87%D0%B0%D1%82%D1%8C+3ds+max+2014+torrent&charset=utf-8
    • http://img0.liveinternet.ru/images/attach/c/7//4778/4778601_disciples__2__dark_.pdf
    • http://img1.liveinternet.ru/images/attach/c/7//4777/4777281_raspisanie__avtobusov__samara_.pdf
    • http://img1.liveinternet.ru/images/attach/c/7//4777/4777795_microsoft__flight__simulator_.pdf

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00053e21.bin
bcf5f9df2bd29304fc02f9aba5452c424de46c9e5237022ee5bfe1472166f475
pdf-font-stream PDF embedded font (sfnt) at offset 0x53E21 10124 bytes
font_01_sfnt_off00055a6b.bin
3fe1669e19df45a33b441ce33db75bc5f2c98574190236f20faa243407d37623
pdf-font-stream PDF embedded font (sfnt) at offset 0x55A6B 17516 bytes