Malicious PDF — malware analysis report

Static analysis result for SHA-256 41b26c0af29e3e66…

MALICIOUS

PDF

44.9 KB Created: 2021-05-16 21:03:47 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: 8fbc0b451673aabd4b456926858eeb0d SHA-1: d3aa17c52c01f3ea57a03ec362b058868ccedb94 SHA-256: 41b26c0af29e3e661ede1d8f166c1b1b445b45278b94199764263376546b33e2
102 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The document contains multiple embedded URLs and a prominent call-to-action lure related to obtaining free in-game currency for games like Roblox and Coin Master. The heuristic 'SE_SECRET_RECOVERY_LURE' indicates the document may also attempt to phish for user credentials or recovery secrets. The ML classifier strongly flagged this PDF as malicious, suggesting it is designed to lead users to download further malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9980

Heuristics 4

  • Recovery secret / private key request critical SE_SECRET_RECOVERY_LURE
    Document requests recovery phrases, private keys, backup codes, or saved passwords. Requests for these secrets in a document are high-risk.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://netcdn.xyz/app/431946152/how-to-get-free-robux-on-roblox-2021-game-hack
    • http://www.museodopobo.gal/web/uploads/files/roblox-exploit-download_GM431946152.pdf
    • http://www.museodopobo.gal/web/uploads/files/coin-master-heaven-free-spins-link-2021-today_GM406889139.pdf
    • http://www.museodopobo.gal/web/uploads/files/free-card-link-coin-master_GM406889139.pdf
    • http://www.museodopobo.gal/web/uploads/files/free-robux-without-human-verification_GM431946152.pdf
    • http://www.museodopobo.gal/web/uploads/files/links-to-get-free-spins-on-coin-master_GM406889139.pdf
    • http://www.museodopobo.gal/web/uploads/files/roblox-free-roblox_GM431946152.pdf
    • http://www.museodopobo.gal/web/uploads/files/minecraft-windows-10-hacked-client_GM479516143.pdf
    • http://www.museodopobo.gal/web/uploads/files/roblox-premium-free_GM431946152.pdf
    • http://www.museodopobo.gal/web/uploads/files/roblox-robux-generator-tool_GM431946152.pdf
    • http://www.museodopobo.gal/web/uploads/files/free-robux-2021_GM431946152.pdf
    • http://www.museodopobo.gal/web/uploads/files/free-robux-obby_GM431946152.pdf
    • http://www.museodopobo.gal/web/uploads/files/daily-spins-coin-master_GM406889139.pdf
    • http://www.museodopobo.gal/web/uploads/files/free-robux-no-human-verification-or-survey-2021_GM431946152.pdf
    • http://www.museodopobo.gal/web/uploads/files/free-robux-link_GM431946152.pdf
    • http://www.museodopobo.gal/web/uploads/files/coin-master-latest-version-hack_GM406889139.pdf
    • http://www.museodopobo.gal/web/uploads/files/como-descargar-coin-master-hackeado_GM406889139.pdf
    • http://www.museodopobo.gal/web/uploads/files/how-to-hack-and-get-free-robux_GM431946152.pdf
    • http://www.museodopobo.gal/web/uploads/files/robux-hack-2021_GM431946152.pdf
    • http://www.museodopobo.gal/web/uploads/files/coin-master-hack-pro-gamers_GM406889139.pdf
    • http://www.museodopobo.gal/web/uploads/files/roblox-promo-code-to-get-free-robux_GM431946152.pdf
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_003_off00004bed.bin
cc603e644a9d3fe1a49ca7b58ea024c7dcf9aac8fc805b5d625d60406fa44992
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x4BED 28416 bytes
font_01_sfnt_off00008ba7.bin
57ee29ca2df633c9559bea9da81b447a7ef2e0dffb4d388bdd233aaad46b31ec
pdf-font-stream PDF embedded font (sfnt) at offset 0x8BA7 18756 bytes