Malicious PDF — malware analysis report

Static analysis result for SHA-256 b548f0e30411d1c2…

MALICIOUS

PDF

373.2 KB Created: 2022-05-28 02:43:44 +03:00 Authoring application: mPDF 7.1.0 First seen: 2023-12-06
MD5: 543c547586ef9043c8e12d0f39f99a01 SHA-1: 79e6573416ed28c9f223bd2f65cd5cc19dbb5237 SHA-256: b548f0e30411d1c23d9d17be3bd47b61c9e06c0dd658eddb7a31b8e7672fcbf8
172 Risk Score

Machine Learning

  • Nyx PDF Classifier clean score 0.0018

Heuristics 6

  • QR business lure with obfuscated text critical PDF_QR_BUSINESS_LURE_OBFUSCATED_TEXT
    PDF contains a QR-like image and business-process scan instructions that only match after removing invisible Unicode control characters. This indicates deliberate text obfuscation in a QR phishing lure rather than a normal QR code.
  • Secondary embedded PDF body has suspicious static findings critical POLYGLOT_CHILD_PDF_STATIC_TRIAGE
    A valid PDF body was found at a nonzero offset inside another container and its carved contents matched PDF exploit or lure heuristics. This catches polyglots where the top-level magic routes to ZIP/OLE while a PDF reader or downstream parser opens the hidden PDF payload.
  • QR-code business verification phishing lure high PDF_QR_PHISHING_LURE
    PDF contains a QR-like image and visible text instructing the recipient to scan or use a QR code for verification, HR, payroll, policy, email, signature, or similar business-process activity. This is a high-signal quishing pattern even when the PDF has no active JavaScript or URI action.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://filesoftclub.club/fc/784 PDF link annotation
    • http://cyyst.com/upfile/eltek-minipack-user-manual.xmlIn PDF document text
    • http://ekinyalitim.com/depo/sayfaresim/eltek-rectifier-flatpack2-manual.xmlIn PDF document text
    • http://www.familyreunionapp.com/family/events/bose-radio-user-manualIn PDF document text
    • http://asfgrup.com/images/canon-gx1-pdf-manual.pdfIn PDF document text
    • https://asidicelabiblia.com/images/canon-hdv-30-manual.pdfIn PDF document text
    • http://cedresarquitectura.com/wp-content/plugins/formcraft/file-upload/server/content/files/162751cb8846df---brother-mfc-8860-user-manual.pdfIn PDF document text
    • https://www.thebiketube.com/acros-bose-radio-remote-control-manualIn PDF document text
    • http://cedresarquitectura.com/wp-content/plugins/formcraft/file-upload/server/content/files/162751cIn PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://dejavu.sourceforge.netIn extracted file (stream_008_off00005316.bin)
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn extracted file (stream_008_off00005316.bin)
🗂 Part of campaign: secureserver.net 1471 samples

Extracted artifacts 6

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_008_off00005316.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x5316 19836 bytes
SHA-256: ad6d801f7554b4de8183daf312cecf2a3a65662328777b95eb4eaac8815799eb
font_01_sfnt_off00008893.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x8893 19964 bytes
SHA-256: 5154a7c8cf7a9b55c2f939ad6a4a8f8327cd6552b9f68a87c49d10dfc747eaa8
polyglot_child_pdf_off0000000f.pdf polyglot-child-pdf Secondary PDF body inside pdf container at offset 0xF 382105 bytes
SHA-256: c0dede7eb99099e6fdc2acf3987f4ff86cee93a3581ecda56ecadb9803fb63a4
polyglot_child_pdf_off0000001e.pdf polyglot-child-pdf Secondary PDF body inside pdf container at offset 0x1E 382090 bytes
SHA-256: 1461032b07654e09f341ad7f1b2ef7dfdcdc3d4bd1919a9181da45a5f0cd656d
polyglot_child_pdf_off0000002d.pdf polyglot-child-pdf Secondary PDF body inside pdf container at offset 0x2D 382075 bytes
SHA-256: 3ad651dc35d10f0571e00a4f360105cbfcdc90a766630542046fcfdfb5270ce3
polyglot_child_pdf_off0000003c.pdf polyglot-child-pdf Secondary PDF body inside pdf container at offset 0x3C 382060 bytes
SHA-256: f9327b404f7272d3a55a53ed52a1fe137e2b350b964b2358a6da3105cf2747a2