Malicious PDF — malware analysis report

Static analysis result for SHA-256 28f640e69a4f4259…

MALICIOUS

PDF

47.7 KB Created: 2021-06-11 04:31:03 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: f842e45dfdde320abbe81e20bc173c41 SHA-1: 6aad3fbdc6b5e222072148f2e50cede09ae0ab86 SHA-256: 28f640e69a4f4259d3786b2662b607cb7f0f64ee8dc4cc050fe1afc61c697583
82 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1203 Exploitation for Client Execution

The PDF document contains a fake CAPTCHA lure, designed to trick users into interacting with the document. It also embeds external URLs, one of which is directly linked to a heuristic firing for external URI usage. The ML classifier also flagged this PDF as malicious with high confidence. The presence of these elements suggests the document is intended to facilitate the download of a second-stage payload.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9832

Heuristics 4

  • Fake CAPTCHA / human verification prompt high SE_FAKE_CAPTCHA
    Document displays a fake CAPTCHA or human-verification prompt — used to trick users into running commands or pressing keyboard shortcuts
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://netcdn.tw/app/431946152/discord-free-roblox-accounts-game-hack
    • http://library.umuslim.ac.id//repository/get-free-robux-today_GM431946152.pdf
    • http://library.umuslim.ac.id/repository/free-minecraft-skin-packs_GM479516143.pdf
    • http://library.umuslim.ac.id/repository/games-that-give-you-free-robux_GM431946152.pdf
    • http://library.umuslim.ac.id//repository/how-to-get-free-robux-website_GM431946152.pdf
    • http://library.umuslim.ac.id/repository/coin-master-computer-hack_GM406889139.pdf
    • http://library.umuslim.ac.id//repository/coin-master-400-spin-link-hack_GM406889139.pdf
    • http://library.umuslim.ac.id//repository/how-to-hack-and-get-free-robux_GM431946152.pdf
    • http://library.umuslim.ac.id/repository/coin-master-hack-game-download_GM406889139.pdf
    • http://library.umuslim.ac.id/repository/free-roblox-accounts-with-robux-that-work-not-banned_GM431946152.pdf
    • http://library.umuslim.ac.id//repository/how-to-change-your-username-in-roblox-for-free_GM431946152.pdf
    • http://library.umuslim.ac.id/repository/coin-master-promo-code-2021_GM406889139.pdf
    • http://library.umuslim.ac.id/repository/coinmasterdailyfreespins-com_GM406889139.pdf
    • http://library.umuslim.ac.id/repository/master-free-spin-and-coin-link_GM406889139.pdf
    • http://library.umuslim.ac.id/repository/spin-coin-master-hack_GM406889139.pdf
    • http://library.umuslim.ac.id//repository/roblox-booga-booga-hack_GM431946152.pdf
    • http://library.umuslim.ac.id/repository/how-to-get-free-robux-no-human-verification_GM431946152.pdf
    • http://library.umuslim.ac.id/repository/minecraft-tools_GM479516143.pdf
    • http://library.umuslim.ac.id/repository/free-robux-no-verify-2021_GM431946152.pdf
    • http://library.umuslim.ac.id/repository/how-to-get-5-robux-for-free-2021_GM431946152.pdf
    • http://library.umuslim.ac.id/repository/free-gamepass-roblox-pastebin_GM431946152.pdf
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_004_off000051da.bin
64e45a53bfdab7cb125bd457e5efc40b65c9b9776bb5111198a9b44788974af3
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x51DA 30980 bytes
font_01_sfnt_off000096f8.bin
f28151af00a98896560461081624f6416cad9a5813e3de9d95099f1330277a3b
pdf-font-stream PDF embedded font (sfnt) at offset 0x96F8 18656 bytes