Malicious PDF — malware analysis report

Static analysis result for SHA-256 01dfa0e762359b60…

MALICIOUS

PDF

44.6 KB Created: 2021-05-14 01:37:08 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: efac35e945d6e71be39e9d2a88714eb3 SHA-1: 8c0f6d481147c2f80804054e630ce90ab97d9266 SHA-256: 01dfa0e762359b6042b3db52d1382e32eb4ae334277c860d33c3ff44ccc8e6fd
82 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious File

The PDF document contains a lure for downloading game hacks, specifically mentioning Minecraft and Roblox. It includes a prominent external URI pointing to a download page, which is a strong indicator of a malicious intent to trick users into downloading potentially harmful files. The 'ClickFix' heuristic further suggests the document is designed to bypass security measures by instructing users to execute commands.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9632

Heuristics 4

  • ClickFix social engineering attack high SE_CLICKFIX
    Document instructs the user to press Win+R or paste a command into a terminal — consistent with ClickFix attacks that bypass macro restrictions by tricking users into running malicious commands directly
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://netcdn.xyz/app/479516143/how-to-download-minecraft-for-free-on-windows-10-game-hack
    • https://datavoiz.com/images/roblox-earn-robux_GM431946152.pdf
    • https://datavoiz.com/images/free-limiteds-roblox_GM431946152.pdf
    • https://datavoiz.com/images/minecraft-rtx-download-free_GM479516143.pdf
    • https://datavoiz.com/images/free-minecraft-printables_GM479516143.pdf
    • https://datavoiz.com/images/mc-hacks_GM479516143.pdf
    • https://datavoiz.com/images/roblox-hack-client_GM431946152.pdf
    • https://datavoiz.com/images/minecraft-free-download-android_GM479516143.pdf
    • https://datavoiz.com/images/free-roblox-executor-no-key_GM431946152.pdf
    • https://datavoiz.com/images/show-me-how-to-get-free-robux_GM431946152.pdf
    • https://datavoiz.com/images/free-robux-codes-2021_GM431946152.pdf
    • https://datavoiz.com/images/coin-master-free-spins-and-coins_GM406889139.pdf
    • https://datavoiz.com/images/coin-master-free-coins-and-spins-link_GM406889139.pdf
    • https://datavoiz.com/images/coun-master_GM406889139.pdf
    • https://datavoiz.com/images/static-moonactive-net-rewards_GM406889139.pdf
    • https://datavoiz.com/images/coin-master-today_GM406889139.pdf
    • https://datavoiz.com/images/free-coinmaster-spins_GM406889139.pdf
    • https://datavoiz.com/images/easypoints-gg-roblox_GM431946152.pdf
    • https://datavoiz.com/images/minecraft-wurst-hacked-client_GM479516143.pdf
    • https://datavoiz.com/images/free-robux-no-anti-bot-verification_GM431946152.pdf
    • https://datavoiz.com/images/free-spin-online-tool-coin-master_GM406889139.pdf
    • https://playhack.in/minecraft
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_003_off00004862.bin
a1ad3ce00d206a6bbf4e14f4981846f152deb6bc73ed1cf7b24c53ee0e9b1a19
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x4862 25144 bytes
font_01_sfnt_off000080ba.bin
972979c3a46100cf5f8fd289bc6fbd2496ff75fec0e3f6753648c72ec6eba714
pdf-font-stream PDF embedded font (sfnt) at offset 0x80BA 2820 bytes
font_02_sfnt_off00008a5a.bin
9bdb117d767bc2a1616d4a29922a75f9c947f24666684502a0f0c13caa6f66a1
pdf-font-stream PDF embedded font (sfnt) at offset 0x8A5A 18764 bytes