Malicious PDF — malware analysis report

Static analysis result for SHA-256 fc3953cf259bfd69…

MALICIOUS

PDF

342.6 KB Created: 2015-08-23 21:07:13 +03:00 Authoring application: wkhtmltopdf 0.12.2.4 (via Qt 4.8.6)
MD5: 94fdb72ee01c4b70d830f5b5b2b38acb SHA-1: a9a73f85059210b8b8ab92b868d0e41649fb372d SHA-256: fc3953cf259bfd6946fbd7011b2834a24a3e23c70a1a82910308af855d311403
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a critical heuristic firing indicating a link to known malicious redirector infrastructure. The embedded URL points to 'botcraftman.ru', which is flagged as malicious. The document body, though heavily obfuscated, appears to contain keywords related to the URL, suggesting a lure. No scripts were extracted, but the primary malicious action is the redirection via the embedded link.

Heuristics 2

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://botcraftman.ru/?lip&keyword=autoaccepter+dota+2+%D1%81%D0%BA%D0%B0%D1%87%D0%B0%D1%82%D1%8C&charset=utf-8
    • http://img0.liveinternet.ru/images/attach/c/6//4690/4690095_img2ozf__303_.pdf
    • http://img0.liveinternet.ru/images/attach/c/6//4690/4690153_marinina__tot__kto_.pdf
    • http://img0.liveinternet.ru/images/attach/c/6//4690/4690188_stiven__king__temnaya_.pdf

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00051362.bin
2af7ad1ed3929c8e15f5707e8cfba9654d97e8a161530d1a78989cc7ca585624
pdf-font-stream PDF embedded font (sfnt) at offset 0x51362 9328 bytes
font_01_sfnt_off00052cfd.bin
f73f6597af63d4c313125bc595d91af16a69c908274b58c9db80217753df0e86
pdf-font-stream PDF embedded font (sfnt) at offset 0x52CFD 15232 bytes