Malicious PDF — malware analysis report

Static analysis result for SHA-256 19ab69fc3f63e760…

MALICIOUS

PDF

45.3 KB Created: 2021-05-15 22:37:12 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: 22dd0191b004be0804f4a9de105a68a2 SHA-1: 61aef8762b1dc1578565b528a08ff6ac7b4cdee6 SHA-256: 19ab69fc3f63e76096fd59d03a4bcf8f45f24dd3e4377318f75e60b8f1cb6f29
62 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF document contains lures related to hacking game accounts, directing users to external URLs. The presence of embedded URLs and the ML classifier's high confidence score indicate a malicious intent to trick users into downloading potentially harmful content. While no scripts were explicitly extracted, the document's structure and embedded URIs suggest it acts as a downloader or redirector for malicious payloads.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9551

Heuristics 4

  • Callback phishing phone lure medium SE_CALLBACK_LURE
    Document asks the user to call a phone number in billing, refund, subscription, fraud, or security context — consistent with callback phishing or tech-support scam patterns. Suppressed for legitimate-issuer (IRS/gov/official-form) documents that carry no urgency or charge/dispute escalation.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://netcdn.xyz/app/431946152/how-to-hack-roblox-accounts-on-phone-game-hack
    • http://pourvosvacances.com/images/coin-master-tool-hack_GM406889139.pdf
    • http://pourvosvacances.com/images/blox-fun-info_GM431946152.pdf
    • http://pourvosvacances.com/images/real-coin-master-hack_GM406889139.pdf
    • http://pourvosvacances.com/images/free-robux-just-enter-username_GM431946152.pdf
    • http://pourvosvacances.com/images/how-do-you-get-roblox-for-free_GM431946152.pdf
    • http://pourvosvacances.com/images/robux-codes-generator-no-human-verification_GM431946152.pdf
    • http://pourvosvacances.com/images/free-robux-videos_GM431946152.pdf
    • http://pourvosvacances.com/images/roblox-heroes-online_GM431946152.pdf
    • http://pourvosvacances.com/images/roblox-hackprogamers-com_GM431946152.pdf
    • http://pourvosvacances.com/images/free-spin-coin-master-game_GM406889139.pdf
    • http://pourvosvacances.com/images/how-to-get-free-roebucks-in-roblox_GM431946152.pdf
    • http://pourvosvacances.com/images/coin-master-game-hack-app-download_GM406889139.pdf
    • http://pourvosvacances.com/images/free-spins-for-coin-master-2021_GM406889139.pdf
    • http://pourvosvacances.com/images/free-robux-websites-that-actually-work_GM431946152.pdf
    • http://pourvosvacances.com/images/how-can-u-get-free-robux_GM431946152.pdf
    • http://pourvosvacances.com/images/hack-coin-master-343-apk_GM406889139.pdf
    • http://pourvosvacances.com/images/free-robux-no-survey-or-human-verification_GM431946152.pdf
    • http://pourvosvacances.com/images/coin-master-free-link_GM406889139.pdf
    • http://pourvosvacances.com/images/robux-free-online_GM431946152.pdf
    • http://pourvosvacances.com/images/coin-master-twitter-free-spins_GM406889139.pdf
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_003_off0000477e.bin
1f2533defa8e109a0d2dd81489d208d5a4b0037241c1ac0189a9de4806f5f4bb
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x477E 24864 bytes
font_01_sfnt_off00007fd3.bin
40b61f8938bd710dc29dc58ba3fde91c245a6a69596ec569b4d27c769ca417cf
pdf-font-stream PDF embedded font (sfnt) at offset 0x7FD3 3884 bytes
font_02_sfnt_off00008c7b.bin
92714a2af62378a1839a0ba08facac9787f9fdc52ffb1ff0f3d5734c2bdfa821
pdf-font-stream PDF embedded font (sfnt) at offset 0x8C7B 18908 bytes