Malicious PDF — malware analysis report

Static analysis result for SHA-256 3952d04f8e84f541…

MALICIOUS

PDF

35.0 KB Created: 2021-07-06 02:17:20 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: 715c0a36d279688766e9c6ff3ad7974c SHA-1: 5a84fe110596bf45c8ac29f3381a9baebbf7c22b SHA-256: 3952d04f8e84f5417cf6478e1b2237b7d44f6813203e3cc5a2787a98ac16537b
62 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The document body and extracted URLs indicate a lure for free in-game currency (Robux, Coin Master spins), consistent with phishing or scamming operations. The presence of embedded URLs and the ML classifier's high confidence score suggest malicious intent. Although no scripts were explicitly extracted, the document's structure and content strongly imply it's designed to lead the user to download further malicious content or visit malicious websites.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9980

Heuristics 4

  • Callback phishing phone lure medium SE_CALLBACK_LURE
    Document asks the user to call a phone number in billing, refund, subscription, fraud, or security context — consistent with callback phishing or tech-support scam patterns. Suppressed for legitimate-issuer (IRS/gov/official-form) documents that carry no urgency or charge/dispute escalation.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://netcdn.tw/app/431946152/5-games-that-actually-give-you-free-robux-game-hack
    • https://lib-stie.yai.ac.id/repository/how-do-you-get-free-robux-on-roblox_GM431946152.pdf
    • https://lib-stie.yai.ac.id/repository/coin-master-spin-hack_GM406889139.pdf
    • https://lib-stie.yai.ac.id/repository/free-robux-with-no-verification_GM431946152.pdf
    • https://lib-stie.yai.ac.id/repository/free-robux-website_GM431946152.pdf
    • https://lib-stie.yai.ac.id/repository/how-to-get-free-robux-no-human-verification-no-waiting_GM431946152.pdf
    • https://lib-stie.yai.ac.id/repository/hi2-to-earn-free-robux-today_GM431946152.pdf
    • https://lib-stie.yai.ac.id/repository/coin-master-cards-free_GM406889139.pdf
    • https://lib-stie.yai.ac.id/repository/robux-free-online_GM431946152.pdf
    • https://lib-stie.yai.ac.id/repository/roblox-plaza-model-train-free_GM431946152.pdf
    • https://lib-stie.yai.ac.id/repository/coin-master-free-spins-and-coins-daily_GM406889139.pdf
    • https://lib-stie.yai.ac.id/repository/pokemon-go-free-bundle_GM1094591345.pdf
    • https://lib-stie.yai.ac.id/repository/how-to-get-free-robux-with-android_GM431946152.pdf
    • https://lib-stie.yai.ac.id/repository/free-robux-not-fake_GM431946152.pdf
    • https://lib-stie.yai.ac.id/repository/roblox-elemental-dragon-tycoon-cheat-codes_GM431946152.pdf
    • https://lib-stie.yai.ac.id/repository/10-ways-to-get-free-robux_GM431946152.pdf
    • https://lib-stie.yai.ac.id/repository/coin-master-free-spins-link-2021-today_GM406889139.pdf
    • https://lib-stie.yai.ac.id/repository/add-robux_GM431946152.pdf
    • https://lib-stie.yai.ac.id/repository/free-robux-accounts-2021_GM431946152.pdf
    • https://lib-stie.yai.ac.id/repository/free-robux-generator-roblox-no-survey_GM431946152.pdf
    • https://lib-stie.yai.ac.id/repository/how-to-reach-hacks-in-sf-roblox_GM431946152.pdf
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00002f99.bin
dc8b72dbffc2b6f5042bea912ae0f4b9d037e1fdeab7eff83b4735ea8a444778
pdf-font-stream PDF embedded font (sfnt) at offset 0x2F99 22440 bytes
font_01_sfnt_off0000616c.bin
33d33ed7570fcd507c7d529bd10320f103da9d949c650efa26819e4dbd723d60
pdf-font-stream PDF embedded font (sfnt) at offset 0x616C 19844 bytes