Malicious PDF — malware analysis report

Static analysis result for SHA-256 3301892a65a447fa…

MALICIOUS

PDF

44.2 KB Created: 2021-06-11 12:18:04 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: 6122380cf2b246cf0b4c178503f895ee SHA-1: e584eff451b8060fce8c785a0a9b60c1e8ea046d SHA-256: 3301892a65a447fa8eb8ac84612cfcc4895c4c8e889a70e5a64e30eaf01d3444
82 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The document exhibits characteristics of an advance-fee scam, specifically luring users with the promise of free game-related items or hacks. It contains multiple embedded URLs that likely lead to malicious downloads or further phishing attempts. The ML classifier also flagged this PDF as malicious, supporting the assessment of a scam-based attack pattern.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9865

Heuristics 4

  • Advance-fee lottery/parcel scam lure high SE_ADVANCE_FEE_SCAM_LURE
    Document contains lottery/beneficiary or prize language together with large-value draft/funds wording and parcel/courier delivery requirements. This is a classic advance-fee fraud document shape.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://netcdn.tw/app/431946152/free-roblox-places-2021-game-hack
    • http://nsktu.ac.in/ckfinder/userfiles/files/oginject-co_GM406889139.pdf
    • http://nsktu.ac.in/ckfinder/userfiles/files/claim-free-robux-button_GM431946152.pdf
    • http://nsktu.ac.in/ckfinder/userfiles/files/https-rbx-place-rewards_GM431946152.pdf
    • http://nsktu.ac.in/ckfinder/userfiles/files/free-robux-kid-friendly-no-human-verification_GM431946152.pdf
    • http://nsktu.ac.in/ckfinder/userfiles/files/free-robux-easy-2021_GM431946152.pdf
    • http://nsktu.ac.in/ckfinder/userfiles/files/minecraft-bedrock-edition-download-pc-free_GM479516143.pdf
    • http://nsktu.ac.in/ckfinder/userfiles/files/free-robux-generator-no-survey_GM431946152.pdf
    • http://nsktu.ac.in/ckfinder/userfiles/files/free-robux-gift-card_GM431946152.pdf
    • http://nsktu.ac.in/ckfinder/userfiles/files/easy-robux-hack_GM431946152.pdf
    • http://nsktu.ac.in/ckfinder/userfiles/files/how-to-get-gamepasses-for-free-on-roblox-2021_GM431946152.pdf
    • http://nsktu.ac.in/ckfinder/userfiles/files/how-to-get-free-skins-in-roblox_GM431946152.pdf
    • http://nsktu.ac.in/ckfinder/userfiles/files/injector-hack-roblox_GM431946152.pdf
    • http://nsktu.ac.in/ckfinder/userfiles/files/free-coin-master-spins-hack_GM406889139.pdf
    • http://nsktu.ac.in/ckfinder/userfiles/files/robux-free-c_GM431946152.pdf
    • http://nsktu.ac.in/ckfinder/userfiles/files/coin-master-free-daily-spins_GM406889139.pdf
    • http://nsktu.ac.in/ckfinder/userfiles/files/free-roblox-passwords_GM431946152.pdf
    • http://nsktu.ac.in/ckfinder/userfiles/files/coin-master-free-spins-link-2021-app_GM406889139.pdf
    • http://nsktu.ac.in/ckfinder/userfiles/files/free-robux-games-on-roblox_GM431946152.pdf
    • http://nsktu.ac.in/ckfinder/userfiles/files/minecraft-free-unblocked_GM479516143.pdf
    • http://nsktu.ac.in/ckfinder/userfiles/files/free-5-tiktok-likes_GM835599320.pdf
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000051c9.bin
49ebb7dc3e69aae639edf4d3b53cf06753b277d3014dcbac108fa458a73de648
pdf-font-stream PDF embedded font (sfnt) at offset 0x51C9 24076 bytes
font_01_sfnt_off000088bf.bin
38f0d4e7723f2758e7e65e77e28217045aa3122a5dccd84b1113246cc3ed93ff
pdf-font-stream PDF embedded font (sfnt) at offset 0x88BF 18732 bytes