Malicious PDF — malware analysis report

Static analysis result for SHA-256 23b467f2e7ea7c53…

MALICIOUS

PDF

49.0 KB Created: 2021-06-03 06:52:56 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: 8e476be1504761cf3c9a5b98fb68a253 SHA-1: 34f56cb5d1684ff35be75500dc1f8fc60f1b0907 SHA-256: 23b467f2e7ea7c533d5d1e92944ec924f6a8c62d5005cffce25dd3ff734b9515
62 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The document contains an embedded URL and text promoting hacks for online games, strongly suggesting a lure for credential harvesting or malware distribution. The ML classifier also flagged this PDF as malicious. While no scripts were extracted, the presence of external URIs and the document's content indicate an attempt to redirect the user to a potentially harmful website.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9796

Heuristics 4

  • Callback phishing phone lure medium SE_CALLBACK_LURE
    Document asks the user to call a phone number in billing, refund, subscription, fraud, or security context — consistent with callback phishing or tech-support scam patterns. Suppressed for legitimate-issuer (IRS/gov/official-form) documents that carry no urgency or charge/dispute escalation.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://netcdn.online/app/431946152/how-to-hack-peoples-roblox-accounts-game-hack
    • http://lib-smansumsel.sch.id/repository/free-daily-coin-master-coins_GM406889139.pdf
    • http://lib-smansumsel.sch.id/repository/coin-master-hack-account_GM406889139.pdf
    • http://lib-smansumsel.sch.id/repository/robux-websites-2021_GM431946152.pdf
    • http://lib-smansumsel.sch.id/repository/can-you-make-a-minecraft-server-for-free_GM479516143.pdf
    • http://lib-smansumsel.sch.id/repository/hacks-de-roblox-descargar_GM431946152.pdf
    • http://lib-smansumsel.sch.id/repository/free-coin-master-spins-2021_GM406889139.pdf
    • http://lib-smansumsel.sch.id/repository/robux-hack-tools_GM431946152.pdf
    • http://lib-smansumsel.sch.id/repository/op-rewards-free-robux_GM431946152.pdf
    • http://lib-smansumsel.sch.id/repository/easy-coin-master-hack-without-verification_GM406889139.pdf
    • http://lib-smansumsel.sch.id/repository/free-robux-without-offers_GM431946152.pdf
    • http://lib-smansumsel.sch.id/repository/coin-master-how-to-get-free-pet-food_GM406889139.pdf
    • http://lib-smansumsel.sch.id/repository/coin-master-hack-2021-ios-download_GM406889139.pdf
    • http://lib-smansumsel.sch.id/repository/free-spins-and-coins-for-coin-master-game_GM406889139.pdf
    • http://lib-smansumsel.sch.id/repository/coin-master-daily-free-spin-and-coin_GM406889139.pdf
    • http://lib-smansumsel.sch.id/repository/how-to-get-free-robux-with-no-verification_GM431946152.pdf
    • http://lib-smansumsel.sch.id/repository/coin-master-mod_GM406889139.pdf
    • http://lib-smansumsel.sch.id/repository/roblox-hacks-for-mac_GM431946152.pdf
    • http://lib-smansumsel.sch.id/repository/how-to-hack-roblox-accounts-on-phone-2021_GM431946152.pdf
    • http://lib-smansumsel.sch.id/repository/free-robux-apps-that-work_GM431946152.pdf
    • http://lib-smansumsel.sch.id/repository/daily-coin-master-free-spins_GM406889139.pdf
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00005238.bin
aea11cdbb9affdccf662bdb37bcf5b94ab083197eec6d5a4c3f645c8cdf9cbde
pdf-font-stream PDF embedded font (sfnt) at offset 0x5238 26960 bytes
font_01_sfnt_off000090a2.bin
4adb8a917f49e7111d61a35b75f09762f191422f789e84659f5497848d60b01b
pdf-font-stream PDF embedded font (sfnt) at offset 0x90A2 2984 bytes
font_02_sfnt_off00009acf.bin
cd7407ef9aef6c4c50b1fdf01e763fd2e22944ade267215dee183f168e7b87f5
pdf-font-stream PDF embedded font (sfnt) at offset 0x9ACF 18920 bytes