Malicious PDF — malware analysis report

Static analysis result for SHA-256 180ef4b4bbeb8c9c…

MALICIOUS

PDF

34.5 KB Created: 2021-07-04 10:04:06 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: 10fb078e81e690bae2987c9824f8bb6b SHA-1: 502f6272a5f1b7d56d9497fd4afdec84888e2e71 SHA-256: 180ef4b4bbeb8c9c375ffd8b38575ad8542267c4a254a92f4537aba2fffef6c9
62 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF document contains numerous embedded URLs pointing to sites offering game hacks and cheats, such as Minecraft and Coin Master. The ML classifier strongly flagged this PDF as malicious, and the presence of these download lures suggests an attempt to trick users into downloading malware or engaging in other malicious activities. No scripts were extracted, but the overall pattern indicates a phishing or potentially unwanted software distribution attempt.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9980

Heuristics 4

  • Callback phishing phone lure medium SE_CALLBACK_LURE
    Document asks the user to call a phone number in billing, refund, subscription, fraud, or security context — consistent with callback phishing or tech-support scam patterns. Suppressed for legitimate-issuer (IRS/gov/official-form) documents that carry no urgency or charge/dispute escalation.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://netcdn.tw/app/479516143/minecraft-free-download-game-hack
    • http://libsmpn1balongpo.sch.id//repository/coin-master-hack-without-downloading-apps_GM406889139.pdf
    • http://libsmpn1balongpo.sch.id//repository/coins-master-hack_GM406889139.pdf
    • http://libsmpn1balongpo.sch.id/repository/tiktok-free-fans_GM835599320.pdf
    • http://libsmpn1balongpo.sch.id//repository/how-to-get-free-robux-2021_GM431946152.pdf
    • http://libsmpn1balongpo.sch.id//repository/free-robux-codes-2021_GM431946152.pdf
    • http://libsmpn1balongpo.sch.id//repository/facebook-coin-master-free-spins_GM406889139.pdf
    • http://libsmpn1balongpo.sch.id//repository/how-to-hack-coin-master-apple_GM406889139.pdf
    • http://libsmpn1balongpo.sch.id//repository/how-to-hack-roblox-accounts-on-phone_GM431946152.pdf
    • http://libsmpn1balongpo.sch.id//repository/toolbox-for-minecraft-windows-10_GM479516143.pdf
    • http://libsmpn1balongpo.sch.id//repository/how-to-scam-on-roblox_GM431946152.pdf
    • http://libsmpn1balongpo.sch.id/repository/roblox-free-level-7_GM431946152.pdf
    • http://libsmpn1balongpo.sch.id//repository/coin-master-daily-free-spins-link-facebook_GM406889139.pdf
    • http://libsmpn1balongpo.sch.id/repository/free-robux-hack-no-fake_GM431946152.pdf
    • http://libsmpn1balongpo.sch.id//repository/blox-land-free-robux_GM431946152.pdf
    • http://libsmpn1balongpo.sch.id/repository/roblox-account-hacker-no-download_GM431946152.pdf
    • http://libsmpn1balongpo.sch.id//repository/what-games-on-roblox-give-you-free-robux_GM431946152.pdf
    • http://libsmpn1balongpo.sch.id//repository/hacks-para-roblox_GM431946152.pdf
    • http://libsmpn1balongpo.sch.id/repository/get-free-robux-on-roblox-using-no-downloads_GM431946152.pdf
    • http://libsmpn1balongpo.sch.id//repository/roblox-girl-avatar_GM431946152.pdf
    • http://libsmpn1balongpo.sch.id/repository/ash-greninja-free-shopping-in-roblox_GM431946152.pdf
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000315f.bin
7764bc27971370fffc984198e603b3fe95b1bc50e982089f8ad534a82e7a64e7
pdf-font-stream PDF embedded font (sfnt) at offset 0x315F 22420 bytes
font_01_sfnt_off00006322.bin
06b239d8a28b1d5597486ea199a20c5d387b716390632991d2cfb7c0688950f5
pdf-font-stream PDF embedded font (sfnt) at offset 0x6322 18576 bytes