Malicious PDF — malware analysis report

Static analysis result for SHA-256 b5d41708c26cc506…

MALICIOUS

PDF

84.9 KB Created: 2022-09-21 13:22:19 +03:00 Authoring application: mPDF 7.1.0 First seen: 2026-07-06
MD5: cd881580fab020720b7b78c97754515e SHA-1: 7dd16c6f661a2a47566753055849578fbf266df6 SHA-256: b5d41708c26cc5069d714681f5b4836861f8bf64b8fad145e00e945f19cad933
72 Risk Score

Machine Learning

  • Nyx PDF Classifier clean score 0.0013

Heuristics 4

  • Secondary embedded PDF body has suspicious static findings critical POLYGLOT_CHILD_PDF_STATIC_TRIAGE
    A valid PDF body was found at a nonzero offset inside another container and its carved contents matched PDF exploit or lure heuristics. This catches polyglots where the top-level magic routes to ZIP/OLE while a PDF reader or downstream parser opens the hidden PDF payload.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://srwt.ru/mpdf/Countryman PDF link annotation
    • http://www.phobos.co.kr/data/editor/enfoques-student-activities-manual-4th-edition.xmlIn PDF document text
    • http://elreefelaraby.com/userfiles/epox-4pda5+-manual.xmlIn PDF document text
    • http://www.bouwdata.net/evenement/crown-amp-xls-602-manualIn PDF document text
    • https://www.abouttimetech.com/images/brevi-baby-walker-manual.pdfIn PDF document text
    • http://foot-five.com/images/breville-800cpxl-manual.pdfIn PDF document text
    • http://gbb.global/blog/crown-access-123-manualIn PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://dejavu.sourceforge.netIn extracted file (stream_007_off0000621c.bin)
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn extracted file (stream_007_off0000621c.bin)
🗂 Part of campaign: secureserver.net 1471 samples

Extracted artifacts 6

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_007_off0000621c.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x621C 19880 bytes
SHA-256: 1333de742ddcbfaca7a569e26cee61a317f00a78edbf54c87ca4b8d69fd04dd6
font_01_sfnt_off000097b9.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x97B9 19964 bytes
SHA-256: 5154a7c8cf7a9b55c2f939ad6a4a8f8327cd6552b9f68a87c49d10dfc747eaa8
polyglot_child_pdf_off0000000f.pdf polyglot-child-pdf Secondary PDF body inside pdf container at offset 0xF 86973 bytes
SHA-256: 0f5482fbdf83823a7704fc80aa4803e758726ea0f30b2f4636c8d94e130cdc43
polyglot_child_pdf_off0000001e.pdf polyglot-child-pdf Secondary PDF body inside pdf container at offset 0x1E 86958 bytes
SHA-256: 050440203050769124f0b7063941e7982d80722e5f1c264178515c4d5a59ea33
polyglot_child_pdf_off0000002d.pdf polyglot-child-pdf Secondary PDF body inside pdf container at offset 0x2D 86943 bytes
SHA-256: 0e50efddeeedb6ce0a8578fe4e66eed23347be00faf53bb18d4b2b5fdfc64da1
polyglot_child_pdf_off0000003c.pdf polyglot-child-pdf Secondary PDF body inside pdf container at offset 0x3C 86928 bytes
SHA-256: d861d41e9bf4d0906357faad8610b3a2797039d90a9d025ffd55bc3a425c0cea