Malicious PDF — malware analysis report

Static analysis result for SHA-256 3cb1d105f1d9530e…

MALICIOUS

PDF

226.2 KB Created: 2022-05-18 02:56:10 +03:00 Authoring application: mPDF 7.1.0 First seen: 2023-12-11
MD5: d631032720dc41c8cf78cd66d9edb9b9 SHA-1: c66c7bbbe64cbb5c589bed3ca288b706ffb1a190 SHA-256: 3cb1d105f1d9530e7261ada6c3c6fda483c1961b1dcb4cf2d41e82ab0b11ff7f
180 Risk Score

Machine Learning

  • Nyx PDF Classifier clean score 0.0019

Heuristics 7

  • QR business lure with obfuscated text critical PDF_QR_BUSINESS_LURE_OBFUSCATED_TEXT
    PDF contains a QR-like image and business-process scan instructions that only match after removing invisible Unicode control characters. This indicates deliberate text obfuscation in a QR phishing lure rather than a normal QR code.
  • Secondary embedded PDF body has suspicious static findings critical POLYGLOT_CHILD_PDF_STATIC_TRIAGE
    A valid PDF body was found at a nonzero offset inside another container and its carved contents matched PDF exploit or lure heuristics. This catches polyglots where the top-level magic routes to ZIP/OLE while a PDF reader or downstream parser opens the hidden PDF payload.
  • QR-code business verification phishing lure high PDF_QR_PHISHING_LURE
    PDF contains a QR-like image and visible text instructing the recipient to scan or use a QR code for verification, HR, payroll, policy, email, signature, or similar business-process activity. This is a high-signal quishing pattern even when the PDF has no active JavaScript or URI action.
  • Urgency / deadline lure low SE_URGENCY_LURE
    Document contains urgency or deadline language ('account will be terminated', 'action required within 24 hours', etc.) — useful context, but low-signal without other findings
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://filesoftclub.club/fc/building PDF link annotation
    • http://erboka.org/userfiles/deering-ideal-mower-manual.xmlIn PDF document text
    • http://aseduis.com/imagenes/imgeditor/deezer-user-manual.xmlIn PDF document text
    • http://www.drupalitalia.org/node/76118In PDF document text
    • http://asiguere.com/images/boss-ch-350-manual.pdfIn PDF document text
    • http://askueandco.com/images/boss-ch850m-manual.pdfIn PDF document text
    • http://www.bestlifepolicy.co.uk/wp-content/plugins/formcraft/file-upload/server/content/files/1626c654f5b924---93-oldsmobile-cutlass-ciera-manual.pdfIn PDF document text
    • http://www.drupalitalia.org/node/76119In PDF document text
    • http://www.bestlifepolicy.co.uk/wp-content/plugins/formcraft/file-upload/server/content/files/1626c6In PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://dejavu.sourceforge.netIn extracted file (stream_011_off00007693.bin)
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn extracted file (stream_011_off00007693.bin)
🗂 Part of campaign: secureserver.net 1471 samples

Extracted artifacts 6

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_011_off00007693.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x7693 19996 bytes
SHA-256: 8e639af5f37a01c952d7fa5ae521c275babc199f4d44038938bf51c1324a673d
font_01_sfnt_off0000ac6f.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xAC6F 19964 bytes
SHA-256: 5154a7c8cf7a9b55c2f939ad6a4a8f8327cd6552b9f68a87c49d10dfc747eaa8
polyglot_child_pdf_off0000000f.pdf polyglot-child-pdf Secondary PDF body inside pdf container at offset 0xF 231578 bytes
SHA-256: 59a8756688fc14f3b5344add07ad6ec6f9fca0bb4933e7476a8f48ee59b853f6
polyglot_child_pdf_off0000001e.pdf polyglot-child-pdf Secondary PDF body inside pdf container at offset 0x1E 231563 bytes
SHA-256: be0dff7aa22c518f1c119b8cc13ac6a69941d2887d0567edbf479af6b6b0cac4
polyglot_child_pdf_off0000002d.pdf polyglot-child-pdf Secondary PDF body inside pdf container at offset 0x2D 231548 bytes
SHA-256: bb62d00f1bc4b11dfd3ed9e700f1d038e74a0ceebc99ecf7e0a02eab76436fb4
polyglot_child_pdf_off0000003c.pdf polyglot-child-pdf Secondary PDF body inside pdf container at offset 0x3C 231533 bytes
SHA-256: 63d6202bc90eac840a7e43a6346bf67e11fabdaa1ffaf6cadab09dd5f132981f