Malicious PDF — malware analysis report

Static analysis result for SHA-256 54580c355f1dcaf3…

MALICIOUS

PDF

42.5 KB Created: 2021-05-16 14:43:57 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: 932c1c5bb26f81a4a0cf3b3bfc4d6fad SHA-1: 5dfc4c62b38c74f7d73b17c19c3c9fc861ada8c9 SHA-256: 54580c355f1dcaf3bdc9c20395dc1b8d338afc5b12cdae104d8afb244af39619
82 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The sample is identified as a malicious PDF by an ML classifier and exhibits characteristics of an advance-fee scam, specifically luring users with promises of free game currency like Robux. It contains multiple embedded URLs pointing to potentially malicious download sites, suggesting it's designed to trick users into downloading further malware. No scripts were extracted, but the presence of external URIs and the scam lure strongly indicate a phishing or malware distribution attempt.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9971

Heuristics 4

  • Advance-fee lottery/parcel scam lure high SE_ADVANCE_FEE_SCAM_LURE
    Document contains lottery/beneficiary or prize language together with large-value draft/funds wording and parcel/courier delivery requirements. This is a classic advance-fee fraud document shape.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://netcdn.xyz/app/431946152/rblx-city-free-robux-game-hack
    • https://dolphintour.vn/images/uploadsfiles/roblox-com-www_GM431946152.pdf
    • https://dolphintour.vn/images/uploadsfiles/minecraft-pe-texture-packs-free-download_GM479516143.pdf
    • https://dolphintour.vn/images/uploadsfiles/roblox-hack-generator_GM431946152.pdf
    • https://dolphintour.vn/images/uploadsfiles/coin-master-free-spins--coins-2021_GM406889139.pdf
    • https://dolphintour.vn/images/uploadsfiles/easy-free-spins-coin-master_GM406889139.pdf
    • https://dolphintour.vn/images/uploadsfiles/free-robux-no-human-verification-or-survey-2021_GM431946152.pdf
    • https://dolphintour.vn/images/uploadsfiles/robux-free-c_GM431946152.pdf
    • https://dolphintour.vn/images/uploadsfiles/promo-codes-to-get-free-robux_GM431946152.pdf
    • https://dolphintour.vn/images/uploadsfiles/free-robux-youtube_GM431946152.pdf
    • https://dolphintour.vn/images/uploadsfiles/how-to-get-more-spins-on-coin-master-hack_GM406889139.pdf
    • https://dolphintour.vn/images/uploadsfiles/www-coin-master-hack_GM406889139.pdf
    • https://dolphintour.vn/images/uploadsfiles/google-moon-active_GM406889139.pdf
    • https://dolphintour.vn/images/uploadsfiles/roblox36com-free-robux_GM431946152.pdf
    • https://dolphintour.vn/images/uploadsfiles/how-can-you-get-free-robux_GM431946152.pdf
    • https://dolphintour.vn/images/uploadsfiles/free-daily-spin-coin-master-game_GM406889139.pdf
    • https://dolphintour.vn/images/uploadsfiles/free-robux-websites-that-actually-work-2021_GM431946152.pdf
    • https://dolphintour.vn/images/uploadsfiles/coin-master-free-coins-and-spins-daily_GM406889139.pdf
    • https://dolphintour.vn/images/uploadsfiles/where-to-get-free-robux_GM431946152.pdf
    • https://dolphintour.vn/images/uploadsfiles/minecraft-pocket-apk_GM479516143.pdf
    • https://dolphintour.vn/images/uploadsfiles/coin-master-free-spins-link-today-new-2021_GM406889139.pdf
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000049aa.bin
cad1c1d0003a8a13b29d3f5ef38d99b1ff1e9a2a0177c49fa352ab65b00aa52b
pdf-font-stream PDF embedded font (sfnt) at offset 0x49AA 25208 bytes
font_01_sfnt_off00008328.bin
8c36c54b235ee774b4288e3a660071bec0b4f54d4ae0ca28de0be66b92090129
pdf-font-stream PDF embedded font (sfnt) at offset 0x8328 18492 bytes