Malicious PDF — malware analysis report

Static analysis result for SHA-256 2a505daafdb56921…

MALICIOUS

PDF

34.1 KB Created: 2021-07-05 09:51:16 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: 3606c921cc8bde7bef80ad76abe0fc83 SHA-1: 64e99d93f33478c5cb226df5473e153e27e9620f SHA-256: 2a505daafdb56921ffa2eac9fddd0cf805d0867b1604fa01362ec82382c30bd1
82 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell T1204.002 Malicious File

The PDF document contains embedded URLs and a lure to trick users into executing commands. The heuristic 'SE_CLIPBOARD_COMMAND_LURE' indicates the document instructs the user to copy and paste content into a shell, likely to download and execute a second-stage payload from the primary URL http://netcdn.tw/app/431946152/rbx-gg-free-robux-game-hack. The ML classifier strongly flagged this PDF as malicious.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9980

Heuristics 4

  • Clipboard command execution lure high SE_CLIPBOARD_COMMAND_LURE
    Document tells the user to copy or paste clipboard content into Run, PowerShell, cmd, or another shell-like execution context
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://netcdn.tw/app/431946152/rbx-gg-free-robux-game-hack
    • http://www.perpustakaan.unda.ac.id/repository/how-to-get-free-robux-easy-on-computer_GM431946152.pdf
    • http://www.perpustakaan.unda.ac.id/repository/hack-coin-master-no-human-verification_GM406889139.pdf
    • http://www.perpustakaan.unda.ac.id/repository/bad-minecraft-free_GM479516143.pdf
    • http://www.perpustakaan.unda.ac.id/repository/freespinandcoin-blogspot-com_GM406889139.pdf
    • http://www.perpustakaan.unda.ac.id/repository/how-to-hack-on-roblox-saber-wars_GM431946152.pdf
    • http://www.perpustakaan.unda.ac.id//repository/free-robux-ad_GM431946152.pdf
    • http://www.perpustakaan.unda.ac.id/repository/free-online-games-no-download-like-roblox_GM431946152.pdf
    • http://www.perpustakaan.unda.ac.id/repository/roblox-cheat-enginge_GM431946152.pdf
    • http://www.perpustakaan.unda.ac.id/repository/free-robux-for-kids-no-vertification_GM431946152.pdf
    • http://www.perpustakaan.unda.ac.id/repository/free-admin-roblox-2021_GM431946152.pdf
    • http://www.perpustakaan.unda.ac.id/repository/things-that-are-free-on-roblox_GM431946152.pdf
    • http://www.perpustakaan.unda.ac.id/repository/how-to-get-free-robux-generator_GM431946152.pdf
    • http://www.perpustakaan.unda.ac.id/repository/rbxoffers-earn-free-robux_GM431946152.pdf
    • http://www.perpustakaan.unda.ac.id/repository/free-robux-2021_GM431946152.pdf
    • http://www.perpustakaan.unda.ac.id/repository/app-for-pubg-uc_GM1330123889.pdf
    • http://www.perpustakaan.unda.ac.id/repository/hack-in-roblox-2021_GM431946152.pdf
    • http://www.perpustakaan.unda.ac.id/repository/how-to-get-free-robux-without-verifying_GM431946152.pdf
    • http://www.perpustakaan.unda.ac.id/repository/roblox-hack-site_GM431946152.pdf
    • http://www.perpustakaan.unda.ac.id/repository/coin-master-hack-coins_GM406889139.pdf
    • http://www.perpustakaan.unda.ac.id/repository/top-hat-roblox-free_GM431946152.pdf
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00002e06.bin
7349ea67ee29b634593b80416b6fa450df7b5c3502e7a200f9d2752b1653349d
pdf-font-stream PDF embedded font (sfnt) at offset 0x2E06 22808 bytes
font_01_sfnt_off0000613c.bin
5ed4a17f1e1f347672ac707c48d478a4e03b12aa7b666a188f58978ddccfd2a0
pdf-font-stream PDF embedded font (sfnt) at offset 0x613C 18716 bytes