Malicious PDF — malware analysis report

Static analysis result for SHA-256 6b36e9a33ea650db…

MALICIOUS

PDF

34.2 KB Created: 2021-07-09 06:09:00 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: fca1463cef498f35d182ecf8552948f3 SHA-1: 3deece9b71d1cca5965bb44ddce78c967c32aab3 SHA-256: 6b36e9a33ea650db17fcf1be415a8a500e2ea1ba2f1f8f82a04c06e8922cee91
62 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF document contains numerous embedded URLs and a document body that explicitly promises codes for free Robux and hacks for games like Minecraft. The ML classifier strongly flagged this PDF as malicious, and the presence of multiple links to external resources, including one directly on an IP address, indicates an attempt to redirect users to download malicious content. The heuristic firings confirm the presence of external URIs and a call-to-action button lure, supporting the conclusion that this document is designed for user-driven download of potentially harmful files.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9980

Heuristics 4

  • Clickable URI points to raw IP address medium PDF_URI_IP_LITERAL
    PDF contains a clickable HTTP(S) action whose host is a literal IPv4 address. Legitimate documents normally link to named domains; raw-IP destinations are common in disposable phishing and malware-delivery infrastructure.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://netcdn.tw/app/431946152/codes-to-get-free-robux-game-hack
    • http://110.232.83.89/slimsppks/repository/how-to-get-hacks-on-minecraft_GM479516143.pdf
    • http://110.232.83.89/slimsppks/repository/roblox-free-hoodie-template_GM431946152.pdf
    • http://110.232.83.89/slimsppks/repository/are-minecraft-realms-free_GM479516143.pdf
    • http://110.232.83.89/slimsppks/repository/roblox-hax_GM431946152.pdf
    • http://110.232.83.89/slimsppks/repository/roblox-got-talent-piano-hack_GM431946152.pdf
    • http://110.232.83.89/slimsppks/repository/earn-free-robux-today_GM431946152.pdf
    • http://110.232.83.89/slimsppks/repository/coin-master-hack-spin_GM406889139.pdf
    • http://110.232.83.89/slimsppks/repository/coin-master-free-spins-hack_GM406889139.pdf
    • http://110.232.83.89/slimsppks/repository/buy-robux-free_GM431946152.pdf
    • http://110.232.83.89/slimsppks/repository/how-to-get-free-robux-2021-upatchable_GM431946152.pdf
    • http://110.232.83.89/slimsppks/repository/coin-master-mod-apk-hack_GM406889139.pdf
    • http://110.232.83.89/slimsppks/repository/how-to-become-builders-club-on-roblox-for-free_GM431946152.pdf
    • http://110.232.83.89/slimsppks/repository/how-to-buy-robux-for-free_GM431946152.pdf
    • http://110.232.83.89/slimsppks/repository/robux-giver_GM431946152.pdf
    • http://110.232.83.89/slimsppks/repository/wurst-115-2_GM479516143.pdf
    • http://110.232.83.89/slimsppks/repository/how-do-you-get-free-robux-2021_GM431946152.pdf
    • http://110.232.83.89/slimsppks/repository/robuxy-com-free-robux_GM431946152.pdf
    • http://110.232.83.89/slimsppks/repository/minecraft-hacked-client-download_GM479516143.pdf
    • http://110.232.83.89/slimsppks/repository/how-to-hack-roblox-to-get-robux_GM431946152.pdf
    • http://110.232.83.89/slimsppks/repository/hacked-roblox-game_GM431946152.pdf
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00002de9.bin
9a87df4881703b3cd3510d0c663f9b7b69da33788bc0abbf2bde5eb1c9f78220
pdf-font-stream PDF embedded font (sfnt) at offset 0x2DE9 22568 bytes
font_01_sfnt_off000060b1.bin
dae15d86f19837a25368e9980f7c547d0fc236531c79ecd70a0408dcd8fbc7fb
pdf-font-stream PDF embedded font (sfnt) at offset 0x60B1 18996 bytes