Malicious PDF — malware analysis report

Static analysis result for SHA-256 d2d515dbb99231a8…

MALICIOUS

PDF

76.4 KB Created: 2022-04-17 03:02:41 +03:00 Authoring application: mPDF 7.1.0 First seen: 2023-12-11
MD5: 192915e7414de7fea0ebfaa0fe99e808 SHA-1: 885bc01a04aed739c3bb525f959cdfca67da29e9 SHA-256: d2d515dbb99231a803a593055f782dd26f6d8d5cc5e54497b81a6e5ebcdc6c62
72 Risk Score

Machine Learning

  • Nyx PDF Classifier clean score 0.0015

Heuristics 4

  • Secondary embedded PDF body has suspicious static findings critical POLYGLOT_CHILD_PDF_STATIC_TRIAGE
    A valid PDF body was found at a nonzero offset inside another container and its carved contents matched PDF exploit or lure heuristics. This catches polyglots where the top-level magic routes to ZIP/OLE while a PDF reader or downstream parser opens the hidden PDF payload.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://srwt.ru/pdf/compass PDF link annotation
    • http://www.mklaassen.nl/images/6es5-421-manual.xmlIn PDF document text
    • http://medpressa.ru/files/file/6es5-441-7la11-manual.xmlIn PDF document text
    • http://directealgerie.com/images/calculus-howard-anton-solution-manual.pdfIn PDF document text
    • https://jdlgroup.ca/images/calculus-james-stewart-5th-edition-solution-manual-download.pdfIn PDF document text
    • http://ns.adobe.com/xap/1.0/In PDF document text
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
    • http://purl.org/dc/elements/1.1/In PDF document text
    • http://dejavu.sourceforge.netIn extracted file (stream_008_off000067d2.bin)
    • http://dejavu.sourceforge.net/wiki/index.php/LicenseIn extracted file (stream_008_off000067d2.bin)
🗂 Part of campaign: secureserver.net 1471 samples

Extracted artifacts 6

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_008_off000067d2.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x67D2 19836 bytes
SHA-256: ad6d801f7554b4de8183daf312cecf2a3a65662328777b95eb4eaac8815799eb
font_01_sfnt_off00009d4f.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x9D4F 19964 bytes
SHA-256: 5154a7c8cf7a9b55c2f939ad6a4a8f8327cd6552b9f68a87c49d10dfc747eaa8
polyglot_child_pdf_off0000000f.pdf polyglot-child-pdf Secondary PDF body inside pdf container at offset 0xF 78268 bytes
SHA-256: 68a76fa4443fc4f007c4e989651b698f36f9da225af4f1d01a7f92170d957768
polyglot_child_pdf_off0000001e.pdf polyglot-child-pdf Secondary PDF body inside pdf container at offset 0x1E 78253 bytes
SHA-256: 87c40e20f24e6a2c5d1c43553bce83182d4f86b4ff1fd1ffb9e20ada6f662a0d
polyglot_child_pdf_off0000002d.pdf polyglot-child-pdf Secondary PDF body inside pdf container at offset 0x2D 78238 bytes
SHA-256: 011a984051b3883426a49e70685377dc6ca350db405a799dbf00cd2530a65641
polyglot_child_pdf_off0000003c.pdf polyglot-child-pdf Secondary PDF body inside pdf container at offset 0x3C 78223 bytes
SHA-256: 36f51d3d7fe7808c9dffb0eeaf497ca3fc6fa8c6580cfd07e0d090fe8e081c39