Malicious PDF — malware analysis report

Static analysis result for SHA-256 3764674a8702a79a…

MALICIOUS

PDF

43.2 KB Created: 2021-05-14 01:00:16 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: bec2d175f5f31d32d37e1916c5ea712e SHA-1: 0b0d5594bcdb365bc72b4da96e36cd6f131896a2 SHA-256: 3764674a8702a79ad2a71c099e4508a81dff6a0849afc6243ee33fdd2033138b
82 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1203 Exploitation for Client Execution

The PDF document contains a fake CAPTCHA lure to trick users into clicking embedded links, which is a common social engineering tactic. The primary embedded URL, https://netcdn.xyz/app/431946152/how-to-get-free-robux-website-game-hack, likely leads to a malicious payload or phishing page. While no scripts were directly extracted, the PDF structure and heuristics suggest it's designed to exploit user interaction for malicious purposes, potentially leading to client execution.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9969

Heuristics 4

  • Fake CAPTCHA / human verification prompt high SE_FAKE_CAPTCHA
    Document displays a fake CAPTCHA or human-verification prompt — used to trick users into running commands or pressing keyboard shortcuts
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://netcdn.xyz/app/431946152/how-to-get-free-robux-website-game-hack
    • http://suaedy-library.net/repository/how-to-setup-a-minecraft-server-for-free_GM479516143.pdf
    • http://suaedy-library.net/repository/coin-master-free-spins-2021-hack_GM406889139.pdf
    • http://suaedy-library.net/repository/hacks-roblox_GM431946152.pdf
    • http://suaedy-library.net/repository/coin-master-jackpot-madness-hack_GM406889139.pdf
    • http://suaedy-library.net/repository/coin-master-exchange-40-free-spins_GM406889139.pdf
    • http://suaedy-library.net/repository/roblox-games-com-free_GM431946152.pdf
    • http://suaedy-library.net/repository/robux-hack-me_GM431946152.pdf
    • http://suaedy-library.net/repository/win-free-robux_GM431946152.pdf
    • http://suaedy-library.net/repository/coin-master-2021-free-spins_GM406889139.pdf
    • http://suaedy-library.net/repository/hack-coin-master-using-pc_GM406889139.pdf
    • http://suaedy-library.net/repository/get-free-robux-generator_GM431946152.pdf
    • http://suaedy-library.net/repository/free-robux-promo-codes-2021_GM431946152.pdf
    • http://suaedy-library.net/repository/free-coin-master-spins-for-today_GM406889139.pdf
    • http://suaedy-library.net/repository/60-free-spins-on-coin-master_GM406889139.pdf
    • http://suaedy-library.net/repository/roblox-hack-me_GM431946152.pdf
    • http://suaedy-library.net/repository/roblox-skin-free_GM431946152.pdf
    • http://suaedy-library.net/repository/coin-master-unlimited-coins-hack-apk-download_GM406889139.pdf
    • http://suaedy-library.net/repository/coin-master-free-coins-link-facebook_GM406889139.pdf
    • http://suaedy-library.net/repository/coin-master-free-coins-and-spins-daily_GM406889139.pdf
    • http://suaedy-library.net/repository/how-to-get-spins-on-coin-master-hack_GM406889139.pdf
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_003_off000049bb.bin
1bfdb7e333c0ae624669efc19a0a6ae3fe698aa2531e09880729112437358758
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x49BB 25992 bytes
font_01_sfnt_off00008566.bin
ac0d4502235c23175446595a7cf8e817a77a023a22f0524dfc344b6b051bbd29
pdf-font-stream PDF embedded font (sfnt) at offset 0x8566 18600 bytes