Malicious PDF — malware analysis report

Static analysis result for SHA-256 5dc6ec90ea037162…

MALICIOUS

PDF

33.4 KB Created: 2021-07-05 19:31:51 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: 367dc62c7a55e837bf62e86d9e351b1b SHA-1: a3ecda6a47cfeb70511443e499a9d82a4fbbb316 SHA-256: 5dc6ec90ea037162c50369bc95c2217eecb32f5ec3f99b399fcff867261807d2
62 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF document contains numerous embedded URLs, many pointing to IP addresses, that advertise free game items and downloads for popular games like Minecraft and Roblox. The ML classifier strongly indicated maliciousness, and the presence of external URIs and a download button lure suggests the document is designed to trick users into clicking links that likely lead to malware or unwanted applications. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9980

Heuristics 4

  • Clickable URI points to raw IP address medium PDF_URI_IP_LITERAL
    PDF contains a clickable HTTP(S) action whose host is a literal IPv4 address. Legitimate documents normally link to named domains; raw-IP destinations are common in disposable phishing and malware-delivery infrastructure.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://netcdn.tw/app/479516143/minecraft-free-download-android-apk-game-hack
    • http://111.68.26.74/widyapustaka/repository/roblox-hack-me_GM431946152.pdf
    • http://111.68.26.74/widyapustaka/repository/games-on-roblox-that-give-you-free-robux_GM431946152.pdf
    • http://111.68.26.74/widyapustaka/repository/rbxcity-free-robux_GM431946152.pdf
    • http://111.68.26.74/widyapustaka/repository/coin-master-free-spins-link-2021_GM406889139.pdf
    • http://111.68.26.74/widyapustaka/repository/free-roblox-accounts-with-robux-that-work-2021_GM431946152.pdf
    • http://111.68.26.74/widyapustaka/repository/apk-roblox-mobile-hack_GM431946152.pdf
    • http://111.68.26.74/widyapustaka/repository/my-roblox-avatar_GM431946152.pdf
    • http://111.68.26.74/widyapustaka/repository/free-robux-trader_GM431946152.pdf
    • http://111.68.26.74/widyapustaka/repository/free-robux-offers_GM431946152.pdf
    • http://111.68.26.74/widyapustaka/repository/free-clothes-giveaway-roblox_GM431946152.pdf
    • http://111.68.26.74/widyapustaka/repository/roblox-asriel-hack_GM431946152.pdf
    • http://111.68.26.74/widyapustaka/repository/how-do-we-hack-in-roblox_GM431946152.pdf
    • http://111.68.26.74/widyapustaka/repository/roblox-fashion-famous-hack_GM431946152.pdf
    • http://111.68.26.74/widyapustaka/repository/cheats-for-coin-master_GM406889139.pdf
    • http://111.68.26.74/widyapustaka/repository/epic-mini-games-cheats-on-roblox_GM431946152.pdf
    • http://111.68.26.74/widyapustaka/repository/roblox-game-pass-hack-2021_GM431946152.pdf
    • http://111.68.26.74/widyapustaka/repository/coin-master-hack-activegamer_GM406889139.pdf
    • http://111.68.26.74/widyapustaka/repository/commen-avoir-robux-free_GM431946152.pdf
    • http://111.68.26.74/widyapustaka/repository/free-roblox-hack_GM431946152.pdf
    • http://111.68.26.74/widyapustaka/repository/how-do-you-hack-people-on-roblox_GM431946152.pdf
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00002de2.bin
3d3b1a54ff61aba3828b61ff88519f6a063f8561f27b162f2d6bd91e4547d08d
pdf-font-stream PDF embedded font (sfnt) at offset 0x2DE2 21856 bytes
font_01_sfnt_off00005de4.bin
efc37f420cdc81e1c687537520cee3b415957f43dea2926da52e5da4cb078786
pdf-font-stream PDF embedded font (sfnt) at offset 0x5DE4 18924 bytes