Malicious PDF — malware analysis report

Static analysis result for SHA-256 6aa46d080cd217eb…

MALICIOUS

PDF

34.3 KB Created: 2021-06-25 22:41:18 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7) First seen: 2021-09-15
MD5: 65a7b568d652cee253fda1ec34031f76 SHA-1: 8594618a94d396a2bccca9454fc40cd3378bc8cd SHA-256: 6aa46d080cd217eb814bfc5c9b7c6b50cb27a62ddfa32bd040ca7651926b3967
80 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF document contains invisible links disguised as a "Free Robux Generator" lure, directing users to a malicious URL. The ML classifier strongly indicated maliciousness, and the presence of multiple related URLs reinforces the phishing and potential malware distribution intent. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9980

Heuristics 3

  • Invisible PDF links to CAPTCHA-themed web lure high PDF_CAPTCHA_LINK_LURE
    PDF contains invisible clickable link annotations that point to a CAPTCHA/capcha-themed web path. This is a common phishing and ClickFix-style routing pattern: the PDF itself is inert, while the linked page performs the credential prompt or fake verification.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://netcdn.co/app/431946152/free-robux-generator-recaptcha-game-hack In PDF document text
    • http://www.nelsonssales.com/media/storage/editor/files/free-robux-today_GM431946152.pdfIn PDF document text
    • http://www.nelsonssales.com/media/storage/editor/files/free-robux-for-kids-no-verification_GM431946152.pdfIn PDF document text
    • http://www.nelsonssales.com/media/storage/editor/files/how-to-get-free-robux-2021-easy_GM431946152.pdfIn PDF document text
    • http://www.nelsonssales.com/media/storage/editor/files/claim-free-robux_GM431946152.pdfIn PDF document text
    • http://www.nelsonssales.com/media/storage/editor/files/a-code-froom-free-robux_GM431946152.pdfIn PDF document text
    • http://www.nelsonssales.com/media/storage/editor/files/minecraft-hacks-list_GM479516143.pdfIn PDF document text
    • http://www.nelsonssales.com/media/storage/editor/files/minecraft-com-free_GM479516143.pdfIn PDF document text
    • http://www.nelsonssales.com/media/storage/editor/files/claim-free-robux-button_GM431946152.pdfIn PDF document text
    • http://www.nelsonssales.com/media/storage/editor/files/free-robux-for-free_GM431946152.pdfIn PDF document text
    • http://www.nelsonssales.com/media/storage/editor/files/free-group-roblox_GM431946152.pdfIn PDF document text
    • http://www.nelsonssales.com/media/storage/editor/files/send-me-500-2021-spins_GM406889139.pdfIn PDF document text
    • http://www.nelsonssales.com/media/storage/editor/files/pokemon-go-free-play_GM1094591345.pdfIn PDF document text
    • http://www.nelsonssales.com/media/storage/editor/files/minecraft-pe-016-0-apk-download-free_GM479516143.pdfIn PDF document text
    • http://www.nelsonssales.com/media/storage/editor/files/coin-master-free-spins-link-blogspot-today_GM406889139.pdfIn PDF document text
    • http://www.nelsonssales.com/media/storage/editor/files/how-to-hack-coin-master-game-2021_GM406889139.pdfIn PDF document text
    • http://www.nelsonssales.com/media/storage/editor/files/coin-master-free-spins-2021-no-human-verification_GM406889139.pdfIn PDF document text
    • http://www.nelsonssales.com/media/storage/editor/files/robux-generator-free-no-password-no-verification_GM431946152.pdfIn PDF document text
    • http://www.nelsonssales.com/media/storage/editor/files/how-to-get-free-robux-codes_GM431946152.pdfIn PDF document text
    • http://www.nelsonssales.com/media/storage/editor/files/coin-master-34-4-hack_GM406889139.pdfIn PDF document text
    • http://www.nelsonssales.com/media/storage/editor/files/free-coin-master-coins_GM406889139.pdfIn PDF document text
    • http://en.wikipedia.org/wiki/MIT_LicenseIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00003074.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x3074 21928 bytes
SHA-256: 6e0445a443d0b9969bde006e8972d05973347ee0ac0f27a5ee699fb2f928e349
font_01_sfnt_off000060bc.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x60BC 19160 bytes
SHA-256: da3529dd2dd50e9ade59f4ad95052b04ab64961e7b01bb1143d4c600fad68998