Malicious PDF — malware analysis report

Static analysis result for SHA-256 44a469ad259a15a7…

MALICIOUS

PDF

200.9 KB Created: 2021-08-16 19:40:17 +03:00 Authoring application: mPDF 7.1.0 First seen: 2023-12-11
MD5: 46a1f0a1f911cc26eeca5d3e104cde8b SHA-1: f2699ddf96323d528fc184b6af0357cbb1fa29f1 SHA-256: 44a469ad259a15a77f77626aa4afcbca690554a2babcca11ac5457ef37293da7
248 Risk Score

Machine Learning

  • Nyx PDF Classifier clean score 0.0006

Heuristics 10

  • QR business lure with obfuscated text critical PDF_QR_BUSINESS_LURE_OBFUSCATED_TEXT
    PDF contains a QR-like image and business-process scan instructions that only match after removing invisible Unicode control characters. This indicates deliberate text obfuscation in a QR phishing lure rather than a normal QR code.
  • Secondary embedded PDF body has suspicious static findings critical POLYGLOT_CHILD_PDF_STATIC_TRIAGE
    A valid PDF body was found at a nonzero offset inside another container and its carved contents matched PDF exploit or lure heuristics. This catches polyglots where the top-level magic routes to ZIP/OLE while a PDF reader or downstream parser opens the hidden PDF payload.
  • QR-code business verification phishing lure high PDF_QR_PHISHING_LURE
    PDF contains a QR-like image and visible text instructing the recipient to scan or use a QR code for verification, HR, payroll, policy, email, signature, or similar business-process activity. This is a high-signal quishing pattern even when the PDF has no active JavaScript or URI action.
  • Brand-impersonation credential phishing lure high SE_BRAND_CREDENTIAL_PHISH
    Document impersonates a well-known consumer brand and uses account-security / verification language ('unusual activity', 'account on hold', 'verify your account') to steer the reader to a credential-harvesting link. Corroborated by: call-to-action link host does not match the impersonated brand: http://srwt.ru/pdf/carolina.
  • Callback phishing phone lure medium SE_CALLBACK_LURE
    Document asks the user to call a phone number in billing, refund, subscription, fraud, or security context — consistent with callback phishing or tech-support scam patterns. Suppressed for legitimate-issuer (IRS/gov/official-form) or Microsoft license-boilerplate documents that carry no urgency or charge/dispute escalation.
  • Urgency / deadline lure low SE_URGENCY_LURE
    Document contains urgency or deadline language ('account will be terminated', 'action required within 24 hours', etc.) — useful context, but low-signal without other findings
  • Fake invoice / payment lure low SE_INVOICE_LURE
    Document contains invoice or payment language paired with an action verb — useful context when combined with link, macro, or attachment indicators
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://srwt.ru/pdf/carolina PDF link annotation
    • http://riggi.ru/userfiles/bosch-sgs45c08gb-manual.xmlIn PDF document text
    • http://kco.su/userfiles/bosch-sgs45e02gb-dishwasher-service-manual.xmlIn PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://dejavu.sourceforge.netIn extracted file (stream_009_off00007526.bin)
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn extracted file (stream_009_off00007526.bin)
🗂 Part of campaign: secureserver.net 1471 samples

Extracted artifacts 6

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_009_off00007526.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x7526 19836 bytes
SHA-256: ad6d801f7554b4de8183daf312cecf2a3a65662328777b95eb4eaac8815799eb
font_01_sfnt_off0000aaa3.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xAAA3 19964 bytes
SHA-256: 5154a7c8cf7a9b55c2f939ad6a4a8f8327cd6552b9f68a87c49d10dfc747eaa8
polyglot_child_pdf_off0000000f.pdf polyglot-child-pdf Secondary PDF body inside pdf container at offset 0xF 205703 bytes
SHA-256: 0d09c9b27b8089bfa22d1e4267912cc4a837deb4a3b9a717cc247cc25e3b5157
polyglot_child_pdf_off0000001e.pdf polyglot-child-pdf Secondary PDF body inside pdf container at offset 0x1E 205688 bytes
SHA-256: dbaf3d576fb1d50b1517a76ad5ca8360d93223c382d688bfaf18d2d154809ae0
polyglot_child_pdf_off0000002d.pdf polyglot-child-pdf Secondary PDF body inside pdf container at offset 0x2D 205673 bytes
SHA-256: 01ea1d6c666282c96301f2333f4e06793e3ee85a8593e41713514c53990e3bef
polyglot_child_pdf_off0000003c.pdf polyglot-child-pdf Secondary PDF body inside pdf container at offset 0x3C 205658 bytes
SHA-256: af69e11203749288e15b2a672ff20f65b9a9ae4c6d9a5acf44b2bcbbaaeb5339