Malicious PDF — malware analysis report

Static analysis result for SHA-256 1beed381d1069bb5…

MALICIOUS

PDF

47.7 KB Created: 2021-05-19 20:34:33 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: 89eb510d4f5b2b3667f406f247fac869 SHA-1: 18e0bbcc229a9f8564b5f49169cfed9a301f7bba SHA-256: 1beed381d1069bb5b9b2d5794143ee3961a4384ad97c4557777a4556d28473b5
82 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1203 Exploitation for Client Execution

The PDF document contains a fake CAPTCHA lure, a common social engineering tactic to trick users into interacting with malicious content. It also embeds external URIs pointing to potentially malicious sites, suggesting an attempt to download further payloads. The ML classifier also flagged this PDF as malicious with high confidence.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9013

Heuristics 4

  • Fake CAPTCHA / human verification prompt high SE_FAKE_CAPTCHA
    Document displays a fake CAPTCHA or human-verification prompt — used to trick users into running commands or pressing keyboard shortcuts
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://netcdn.xyz/app/431946152/apps-that-give-you-free-robux-game-hack
    • https://www.campguru.co.za/images/blox-world-free-robux_GM431946152.pdf
    • https://www.campguru.co.za/images/i-need-more-free-spins-on-coin-master_GM406889139.pdf
    • https://www.campguru.co.za/images/free-roblox-premium_GM431946152.pdf
    • https://www.campguru.co.za/images/how-to-get-a-lot-of-robux_GM431946152.pdf
    • https://www.campguru.co.za/images/how-to-o-get-free-coin-master-spins_GM406889139.pdf
    • https://www.campguru.co.za/images/coin-master-daily-free-spins-2021_GM406889139.pdf
    • https://www.campguru.co.za/images/free-robux-meme_GM431946152.pdf
    • https://www.campguru.co.za/images/coin-master-bonus_GM406889139.pdf
    • https://www.campguru.co.za/images/minecraft-windows-10-edition-hacks_GM479516143.pdf
    • https://www.campguru.co.za/images/hacks-to-get-free-robux_GM431946152.pdf
    • https://www.campguru.co.za/images/how-to-get-a-refund-on-roblox-2021_GM431946152.pdf
    • https://www.campguru.co.za/images/coin-master-hacksco_GM406889139.pdf
    • https://www.campguru.co.za/images/robux-place-rewards_GM431946152.pdf
    • https://www.campguru.co.za/images/jailbreak-script_GM431946152.pdf
    • https://www.campguru.co.za/images/coin-master-daily-free-spins-and-coins-link_GM406889139.pdf
    • https://www.campguru.co.za/images/oprewards-login_GM431946152.pdf
    • https://www.campguru.co.za/images/free-minecraft-codes_GM479516143.pdf
    • https://www.campguru.co.za/images/free-robux-generator_GM431946152.pdf
    • https://www.campguru.co.za/images/coin-master-apk-mod-hack-download_GM406889139.pdf
    • https://www.campguru.co.za/images/how-to-get-minecraft-bedrock-edition-on-pc-for-free_GM479516143.pdf
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00004b64.bin
612297c93174021240ab98aa37ead556f5afa8fa99ed305dc7e19e570f3600c8
pdf-font-stream PDF embedded font (sfnt) at offset 0x4B64 27880 bytes
font_01_sfnt_off00008ba4.bin
10d025f04f706eb71cdda4f99784df1b9ccb52e48080e43095e0398eaef6f132
pdf-font-stream PDF embedded font (sfnt) at offset 0x8BA4 2880 bytes
font_02_sfnt_off0000958f.bin
837a639daa187fc447bd118567dc66774ab6c99c19a83daf34219dbfdd013636
pdf-font-stream PDF embedded font (sfnt) at offset 0x958F 19084 bytes