Malicious PDF — malware analysis report

Static analysis result for SHA-256 624854bf017f9c26…

MALICIOUS

PDF

48.6 KB Created: 2021-05-16 19:32:04 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: 58a83982a7ed08a906d622789cd24806 SHA-1: 4c1531a71ffcb408cfb7d27b422dfd17e82f0bf2 SHA-256: 624854bf017f9c260e753c7768a3f57af3cbbc792b949be1aa693a67624aa12d
82 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF document contains embedded URLs and a lure for a 'hack robux game hack', indicating a phishing attempt to trick users into downloading potentially malicious software. The presence of MFA lure heuristics suggests an attempt to harvest credentials or session tokens. No scripts were extracted, but the embedded URLs are the primary indicators of malicious intent.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9013

Heuristics 4

  • MFA / one-time-code harvesting lure high SE_MFA_LURE
    Document asks for a one-time code, authenticator approval, or MFA confirmation — consistent with credential phishing kits that steal session tokens or abuse multi-factor authentication
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://netcdn.xyz/app/431946152/hack-robux-game-hack
    • https://www.bodyammo.in/uploaded_files/userfiles/files/coin-master-hack-xyz-apk-download_GM406889139.pdf
    • https://www.bodyammo.in/uploaded_files/userfiles/files/free-robux-ad_GM431946152.pdf
    • https://www.bodyammo.in/uploaded_files/userfiles/files/free-robux-generator-com-roblox-hack_GM431946152.pdf
    • https://www.bodyammo.in/uploaded_files/userfiles/files/coin-master-apk_GM406889139.pdf
    • https://www.bodyammo.in/uploaded_files/userfiles/files/roblox-robux-hack_GM431946152.pdf
    • https://www.bodyammo.in/uploaded_files/userfiles/files/how-to-get-free-food-for-foxy-in-coin-master_GM406889139.pdf
    • https://www.bodyammo.in/uploaded_files/userfiles/files/how-to-hack-a-roblox-account-2021_GM431946152.pdf
    • https://www.bodyammo.in/uploaded_files/userfiles/files/coin-monster_GM406889139.pdf
    • https://www.bodyammo.in/uploaded_files/userfiles/files/free-spins-on-coin-master-generator_GM406889139.pdf
    • https://www.bodyammo.in/uploaded_files/userfiles/files/blox-world-free-robux_GM431946152.pdf
    • https://www.bodyammo.in/uploaded_files/userfiles/files/free-robux-survey_GM431946152.pdf
    • https://www.bodyammo.in/uploaded_files/userfiles/files/watch-ads-for-robux_GM431946152.pdf
    • https://www.bodyammo.in/uploaded_files/userfiles/files/uprobuxcom-free-robux_GM431946152.pdf
    • https://www.bodyammo.in/uploaded_files/userfiles/files/roblox-free-hair-codes_GM431946152.pdf
    • https://www.bodyammo.in/uploaded_files/userfiles/files/coin-master-fun-hack-online_GM406889139.pdf
    • https://www.bodyammo.in/uploaded_files/userfiles/files/minecraft-pc-download-free-full-version_GM479516143.pdf
    • https://www.bodyammo.in/uploaded_files/userfiles/files/como-hackear-coin-master-espaol_GM406889139.pdf
    • https://www.bodyammo.in/uploaded_files/userfiles/files/how-do-you-hack-roblox_GM431946152.pdf
    • https://www.bodyammo.in/uploaded_files/userfiles/files/robux-hack-generator_GM431946152.pdf
    • https://www.bodyammo.in/uploaded_files/userfiles/files/free-robux-no-human-verification-generator_GM431946152.pdf
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00004f30.bin
dccc4e22771596cbbd53921fdfe67e6e0a5a23a6212784e0eb54067407a5474c
pdf-font-stream PDF embedded font (sfnt) at offset 0x4F30 27812 bytes
font_01_sfnt_off00008ed1.bin
63a179d8a9645bea05c6d53b1776faf4e4a7281930de6cf484e639846bec2e20
pdf-font-stream PDF embedded font (sfnt) at offset 0x8ED1 3656 bytes
font_02_sfnt_off00009b8a.bin
9805bb7d0eadd4beaac6fd3b5d5d8b6e8e5d33c97ce909732e364f826719e5d2
pdf-font-stream PDF embedded font (sfnt) at offset 0x9B8A 18248 bytes