Malicious PDF — malware analysis report

Static analysis result for SHA-256 07d0ea829876802b…

MALICIOUS

PDF

45.0 KB Created: 2021-06-07 06:30:19 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: d5d9c22f54d083f97bd1465528131341 SHA-1: 4d23c545bb0a72a52f2c31f3b1fa49aaa5347fe1 SHA-256: 07d0ea829876802bc849562a6441e9f13bdb1921433e7d0986c891a1e7ec3e47
82 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1203 Exploitation for Client Execution

The document contains a lure related to game hacks and includes a high-risk heuristic for security bypass, suggesting an attempt to trick the user into disabling security measures. The embedded URL likely leads to a second-stage payload, which is a common tactic for malware distribution. The ML classifier also strongly indicated maliciousness.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9865

Heuristics 4

  • Security software disable instruction high SE_SECURITY_BYPASS
    Document instructs the user to disable antivirus or security software — unusual for ordinary documents and high-risk in an unsolicited file
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://netcdn.tw/app/431946152/j
    • https://pneukalousek.cz/images/roblox-free-robux-generator_GM431946152.pdf
    • https://pneukalousek.cz/images/free-roblox-executor_GM431946152.pdf
    • https://pneukalousek.cz/images/can-you-make-a-minecraft-server-for-free_GM479516143.pdf
    • https://pneukalousek.cz/images/coin-master-game-hacks_GM406889139.pdf
    • https://pneukalousek.cz/images/free-robux-website_GM431946152.pdf
    • https://pneukalousek.cz/images/coin-master-hack-without-human-verification-2021_GM406889139.pdf
    • https://pneukalousek.cz/images/coin-master-daily-spin-free_GM406889139.pdf
    • https://pneukalousek.cz/images/how-do-i-get-free-robux-on-roblox_GM431946152.pdf
    • https://pneukalousek.cz/images/coin-master-free-spins-link-blogspot_GM406889139.pdf
    • https://pneukalousek.cz/images/is-minecraft-free-on-switch_GM479516143.pdf
    • https://pneukalousek.cz/images/is-coin-master-hacks-safe_GM406889139.pdf
    • https://pneukalousek.cz/images/free-robux-no-downloading-apps_GM431946152.pdf
    • https://pneukalousek.cz/images/how-to-get-robux-for-free-2021_GM431946152.pdf
    • https://pneukalousek.cz/images/bux-free-robux_GM431946152.pdf
    • https://pneukalousek.cz/images/free-robux-discord-servers_GM431946152.pdf
    • https://pneukalousek.cz/images/legit-coin-master-hack-no-human-verification_GM406889139.pdf
    • https://pneukalousek.cz/images/minecraft-free-download-ipad_GM479516143.pdf
    • https://pneukalousek.cz/images/coin-master-hack-xyz-apk-download_GM406889139.pdf
    • https://pneukalousek.cz/images/apps-for-free-robux_GM431946152.pdf
    • https://pneukalousek.cz/images/minecraft-svg-free_GM479516143.pdf
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_004_off0000523b.bin
d45b4e7ea54cb7f9965594d7150cb128114369894e091361cbf71c0b4bd3f326
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x523B 24520 bytes
font_01_sfnt_off00008aac.bin
37ac7c406db79a109341829a5eba783a79be88ca82d978d9ec7486910def89c2
pdf-font-stream PDF embedded font (sfnt) at offset 0x8AAC 19184 bytes