Malicious PDF — malware analysis report

Static analysis result for SHA-256 55db94f22f3cc678…

MALICIOUS

PDF

34.3 KB Created: 2021-07-05 02:30:07 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: 5774c592d06a0904ac4372492b0d8e9d SHA-1: 79eae71f33b17273d5d03916266b76dd806d3d63 SHA-256: 55db94f22f3cc678701c3c93ae674fed39aab0c8f3343670dfdf8639d60ef307
62 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1203 Exploitation for Client Execution

The PDF document contains numerous embedded URLs, many pointing to IP addresses, that are designed to lure users into downloading further malicious content related to game cheats and hacks. The ML classifier strongly indicated maliciousness, and the presence of external URIs and a visual download button heuristic further support this. The document likely serves as a dropper or initial lure for more dangerous payloads.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9980

Heuristics 4

  • Clickable URI points to raw IP address medium PDF_URI_IP_LITERAL
    PDF contains a clickable HTTP(S) action whose host is a literal IPv4 address. Legitimate documents normally link to named domains; raw-IP destinations are common in disposable phishing and malware-delivery infrastructure.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://netcdn.tw/app/431946152/cpbildco-robux-game-hack
    • http://1.179.208.67/ckfinder/userfiles/files/free-tiktok-followers-generator_GM835599320.pdf
    • http://1.179.208.67/ckfinder/userfiles/files/free-black-shirt-roblox_GM431946152.pdf
    • http://1.179.208.67/ckfinder/userfiles/files/how-to-get-free-robux-without-verification-2021_GM431946152.pdf
    • http://1.179.208.67/ckfinder/userfiles/files/master-coin-free-spin_GM406889139.pdf
    • http://1.179.208.67/ckfinder/userfiles/files/clothes-in-roblox-free_GM431946152.pdf
    • http://1.179.208.67/ckfinder/userfiles/files/i-need-more-free-spins-on-coin-master_GM406889139.pdf
    • http://1.179.208.67/ckfinder/userfiles/files/coin-master-hack-tool-without-human-verification_GM406889139.pdf
    • http://1.179.208.67/ckfinder/userfiles/files/how-to-have-a-coo-roblox-avatar-for-free_GM431946152.pdf
    • http://1.179.208.67/ckfinder/userfiles/files/how-to-get-free-robux-without-downloading-apps-2021_GM431946152.pdf
    • http://1.179.208.67/ckfinder/userfiles/files/code-hack-roblox_GM431946152.pdf
    • http://1.179.208.67/ckfinder/userfiles/files/minecraft-for-laptop-free_GM479516143.pdf
    • http://1.179.208.67/ckfinder/userfiles/files/free-minecraft-skins_GM479516143.pdf
    • http://1.179.208.67/ckfinder/userfiles/files/minecraft-free-download-unblocked_GM479516143.pdf
    • http://1.179.208.67/ckfinder/userfiles/files/bloxawards-free-robux_GM431946152.pdf
    • http://1.179.208.67/ckfinder/userfiles/files/hack-download_GM431946152.pdf
    • http://1.179.208.67/ckfinder/userfiles/files/free-robux-mobile_GM431946152.pdf
    • http://1.179.208.67/ckfinder/userfiles/files/how-to-get-free-robux-funky_GM431946152.pdf
    • http://1.179.208.67/ckfinder/userfiles/files/free-robux-hack-no-verification_GM431946152.pdf
    • http://1.179.208.67/ckfinder/userfiles/files/clickbait-free-robux_GM431946152.pdf
    • http://1.179.208.67/ckfinder/userfiles/files/free-apk-mods-coin-master_GM406889139.pdf
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00002f94.bin
fe1da060162234425bfff5613c00379b323e9ee09cfacfea79e3327d19c3bb3e
pdf-font-stream PDF embedded font (sfnt) at offset 0x2F94 22204 bytes
font_01_sfnt_off000060d1.bin
3774e2cd1dca270d4381be7f0b5b05bd650ad330201d58729471f58c3aaeab14
pdf-font-stream PDF embedded font (sfnt) at offset 0x60D1 19096 bytes