Malicious PDF — malware analysis report

Static analysis result for SHA-256 6012de1fd60d3239…

MALICIOUS

PDF

44.9 KB Created: 2021-05-10 16:33:32 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7) First seen: 2021-09-29
MD5: 7b8e1a575a929ef4f26a4e6f1ff298b0 SHA-1: 6dfe920672a074bd5cb5a11f04e77c91cc143317 SHA-256: 6012de1fd60d32390b6a27e515b6e2e97557cfa0b2e18935b0de7ba9008a928a
82 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF document contains lures for 'free Robux' and game hacks, directing users to malicious URLs. The presence of embedded URLs and a high ML classifier score indicate malicious intent. While no scripts were explicitly extracted, the document's structure and embedded links suggest it's designed to redirect users to potentially harmful content or initiate downloads.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9980

Heuristics 4

  • PDF links to a 'free generator / game hack' redirector high PDF_GAME_HACK_REDIRECT_LURE
    PDF's clickable action targets a redirector of the form /app/<id>/<slug>-game-hack — the landing-page shape of a large SEO 'free spins / generator / game hack' lure family that funnels victims through rotating disposable hosts to a malware/scam payload. The multi-link variants also trip ML/link-farm rules; this catches the single-link variants that otherwise score clean.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://netcdn.xyz/app/431946152/free-robux-no-verification-or-survey-game-hack PDF link annotation
    • http://repository.poliven.ac.id/repository/claim-robux_GM431946152.pdfIn PDF document text
    • http://repository.poliven.ac.id//repository/show-me-how-to-get-free-robux_GM431946152.pdfIn PDF document text
    • http://repository.poliven.ac.id//repository/free-hair-roblox-boy_GM431946152.pdfIn PDF document text
    • http://repository.poliven.ac.id/repository/free-coins_GM406889139.pdfIn PDF document text
    • http://repository.poliven.ac.id/repository/coin-master-hack-2021_GM406889139.pdfIn PDF document text
    • http://repository.poliven.ac.id//repository/moonactive-coin-master-free-spins_GM406889139.pdfIn PDF document text
    • http://repository.poliven.ac.id//repository/minecraft-pe-hacks-ios_GM479516143.pdfIn PDF document text
    • http://repository.poliven.ac.id//repository/how-to-hack-coin-master-spin_GM406889139.pdfIn PDF document text
    • http://repository.poliven.ac.id/repository/free-spins-for-coin-master-2021_GM406889139.pdfIn PDF document text
    • http://repository.poliven.ac.id/repository/free-robux-codes-2021-not-used_GM431946152.pdfIn PDF document text
    • http://repository.poliven.ac.id//repository/how-to-hack-minecraft_GM479516143.pdfIn PDF document text
    • http://repository.poliven.ac.id//repository/coin-master-hack-apk-2021-ios_GM406889139.pdfIn PDF document text
    • http://repository.poliven.ac.id/repository/spin-coin_GM406889139.pdfIn PDF document text
    • http://repository.poliven.ac.id//repository/coin-master-free-coins-no-human-verification_GM406889139.pdfIn PDF document text
    • http://repository.poliven.ac.id//repository/roblox-adopt-me-hack_GM431946152.pdfIn PDF document text
    • http://repository.poliven.ac.id/repository/if-you-delete-minecraft-can-you-redownload-it-for-free_GM479516143.pdfIn PDF document text
    • http://repository.poliven.ac.id/repository/can-u-get-free-robux_GM431946152.pdfIn PDF document text
    • http://repository.poliven.ac.id/repository/free-roebucks_GM431946152.pdfIn PDF document text
    • http://repository.poliven.ac.id/repository/how-to-get-a-lot-of-robux_GM431946152.pdfIn PDF document text
    • http://repository.poliven.ac.id/repository/minecraft-free-minecraft_GM479516143.pdfIn PDF document text
    • http://en.wikipedia.org/wiki/MIT_LicenseIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00004b13.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x4B13 28664 bytes
SHA-256: d9e97c6ec6f387b6e4fc8a65f38e21e89068ca48080945b5e951c1171e51c60f
font_01_sfnt_off00008b94.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x8B94 18892 bytes
SHA-256: 85e8471d4bb7809b16494b43ecc998cec7f87bafeaec38a3001510264e72f0e6