Malicious PDF — malware analysis report

Static analysis result for SHA-256 0b931422870ac3e8…

MALICIOUS

PDF

36.3 KB Created: 2021-05-20 22:05:29 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: 6a38b9698886448d762633e16224764e SHA-1: 6e4114041a02eea5715b9997b47f5dbd2d952ab5 SHA-256: 0b931422870ac3e889a5f207467ef06bf3593db629ae890a79a626cc59f79edb
82 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious File

The PDF document contains a lure for free TikTok followers, instructing the user to click a link or download content, which is a common social engineering tactic. The heuristic 'SE_BROWSER_INSTALL_LURE' strongly indicates the intent to trick users into installing malicious browser extensions or viewers. Multiple embedded URLs point to sites offering similar 'free' services, likely serving as download locations for malware or phishing pages.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9648

Heuristics 4

  • Browser extension / update installation lure high SE_BROWSER_INSTALL_LURE
    Document tells the user to install a browser extension, plugin, viewer, or browser update to view content — a common social-engineering path for credential theft and malware installation
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://netcdn.xyz/app/835599320/free-tiktok-followers-no-human-verification-game-hack
    • https://quatangphongthuy.vn/upload/UploadFiles/files/robuxmatchcom-free-robux_GM431946152.pdf
    • https://quatangphongthuy.vn/upload/UploadFiles/files/free-spin-link-coin-master_GM406889139.pdf
    • https://quatangphongthuy.vn/upload/UploadFiles/files/minecraft-download-free-download_GM479516143.pdf
    • https://quatangphongthuy.vn/upload/UploadFiles/files/free-coin-master-hacks_GM406889139.pdf
    • https://quatangphongthuy.vn/upload/UploadFiles/files/free-robux-no-verification-2021-ios_GM431946152.pdf
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_002_off00003138.bin
9fecf742be54faac8219068496f93c3f25077be2b74dfa01944d7351073b924d
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x3138 26536 bytes
font_01_sfnt_off00006c25.bin
6fa1441c1a321216f6114c799401e851ec7285796cff0c56691a74954fdf2722
pdf-font-stream PDF embedded font (sfnt) at offset 0x6C25 18456 bytes