Malicious PDF — malware analysis report

Static analysis result for SHA-256 47bc6e32b217e823…

MALICIOUS

PDF

44.9 KB Created: 2021-05-10 16:04:53 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: 2699f86434060007e4df1add789931b8 SHA-1: 465b09360caf530dded2fa831c01e35f54fe509d SHA-256: 47bc6e32b217e823544dcc1e84ad42909aa7bda6693064f83491f57298401f41
82 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1203 Exploitation for Client Execution

The PDF document contains embedded URLs and lures users with a fake download button and a remote support pretext, suggesting an attempt to trick the user into downloading malicious content or installing unwanted software. The ML classifier also flagged this PDF as malicious with high confidence. No scripts were extracted from this sample, but the presence of external URIs and the remote support lure indicate a high likelihood of a malicious payload delivery.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9632

Heuristics 4

  • Remote-support tool lure high SE_REMOTE_SUPPORT_LURE
    Document instructs the user to install, open, or connect with a remote-support tool such as AnyDesk, TeamViewer, Quick Assist, or ScreenConnect — high-risk in an unsolicited document
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://netcdn.xyz/app/479516143/minecraft-world-free-download-game-hack
    • https://library.sttbandung.ac.id/repository/how-to-get-free-robux-website_GM431946152.pdf
    • https://library.sttbandung.ac.id/repository/coin-master-jackpot-hack_GM406889139.pdf
    • https://library.sttbandung.ac.id/repository/free-roblox-accounts-with-robux-that-work-not-banned-2021_GM431946152.pdf
    • https://library.sttbandung.ac.id/repository/como-hackear-coin-master-gratis_GM406889139.pdf
    • https://library.sttbandung.ac.id/repository/roblox-com-r_GM431946152.pdf
    • https://library.sttbandung.ac.id/repository/free-robux-website_GM431946152.pdf
    • https://library.sttbandung.ac.id/repository/roblox-hacked-version_GM431946152.pdf
    • https://library.sttbandung.ac.id/repository/coin-master-mod-version-free-download-2021_GM406889139.pdf
    • https://library.sttbandung.ac.id/repository/www-coin-master-hack-tk_GM406889139.pdf
    • https://library.sttbandung.ac.id/repository/coin-master-hack-2021_GM406889139.pdf
    • https://library.sttbandung.ac.id/repository/free-spins-coins-coin-master_GM406889139.pdf
    • https://library.sttbandung.ac.id/repository/robux-free-promo-codes_GM431946152.pdf
    • https://library.sttbandung.ac.id/repository/coin-master-daily-free-spins-and-coins-2021_GM406889139.pdf
    • https://library.sttbandung.ac.id/repository/how-to-get-minecraft-for-free-on-ps4-2021_GM479516143.pdf
    • https://library.sttbandung.ac.id/repository/free-coins-coin-master_GM406889139.pdf
    • https://library.sttbandung.ac.id/repository/coin-master-heaven-free-spins-today_GM406889139.pdf
    • https://library.sttbandung.ac.id/repository/free-spin-link-in-coin-master_GM406889139.pdf
    • https://library.sttbandung.ac.id/repository/free-coin-master-generator_GM406889139.pdf
    • https://library.sttbandung.ac.id/repository/coin-master-apk-hack-3527_GM406889139.pdf
    • https://library.sttbandung.ac.id/repository/coin-master-spin-hack_GM406889139.pdf
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_003_off00004a8e.bin
42770d93cb37e24a06dafd09233b246942d7db7d550fda826ce697d913f9898f
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x4A8E 24840 bytes
font_01_sfnt_off00008261.bin
10d025f04f706eb71cdda4f99784df1b9ccb52e48080e43095e0398eaef6f132
pdf-font-stream PDF embedded font (sfnt) at offset 0x8261 2880 bytes
font_02_sfnt_off00008c4b.bin
53d97953320c4a27ca75ab54c15cccabcbe94f1a7eef6df1be3b25df4f56750c
pdf-font-stream PDF embedded font (sfnt) at offset 0x8C4B 18488 bytes