Malicious PDF — malware analysis report

Static analysis result for SHA-256 6b7c7be1a7037042…

MALICIOUS

PDF

43.4 KB Created: 2021-05-19 23:02:26 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: 4932b8737e66e47463be3fb8fad2bd07 SHA-1: 0756f4fa4564fff2a1b777ebbd7bc2afab999acd SHA-256: 6b7c7be1a703704222e129db4d65f8ba8b3b530750170038cb6e13189829a54b
82 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

This PDF document employs social engineering by promising free Robux and free spins for Coin Master, common lures for malicious content. It also includes a heuristic indicating a browser extension installation lure, suggesting the user is prompted to install something to view the content. The ML classifier strongly flagged this PDF as malicious, and it contains numerous embedded URLs pointing to potentially malicious download sites.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9979

Heuristics 4

  • Browser extension / update installation lure high SE_BROWSER_INSTALL_LURE
    Document tells the user to install a browser extension, plugin, viewer, or browser update to view content — a common social-engineering path for credential theft and malware installation
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://netcdn.xyz/app/431946152/free-robux-codes-2021-real-game-hack
    • https://www.interfaceventos.com.br/imagens/files/coin-master-hack-android_GM406889139.pdf
    • https://www.interfaceventos.com.br/imagens/files/coin-master-free-spins-hacktman_GM406889139.pdf
    • https://www.interfaceventos.com.br/imagens/files/free-roblox-accounts-2021-with-robux_GM431946152.pdf
    • https://www.interfaceventos.com.br/imagens/files/hack-coin-master-net_GM406889139.pdf
    • https://www.interfaceventos.com.br/imagens/files/coin-master-app-hack_GM406889139.pdf
    • https://www.interfaceventos.com.br/imagens/files/coin-master-spin-link-today_GM406889139.pdf
    • https://www.interfaceventos.com.br/imagens/files/give-me-free-robux_GM431946152.pdf
    • https://www.interfaceventos.com.br/imagens/files/pubg-uc-2021_GM1330123889.pdf
    • https://www.interfaceventos.com.br/imagens/files/pokemon-go-free-unblocked_GM1094591345.pdf
    • https://www.interfaceventos.com.br/imagens/files/free-roblox-hair-girl_GM431946152.pdf
    • https://www.interfaceventos.com.br/imagens/files/what-are-points-for-in-roblox_GM431946152.pdf
    • https://www.interfaceventos.com.br/imagens/files/freespinandcoin_GM406889139.pdf
    • https://www.interfaceventos.com.br/imagens/files/how-to-get-free-hair-on-roblox_GM431946152.pdf
    • https://www.interfaceventos.com.br/imagens/files/is-it-possible-to-get-free-robux_GM431946152.pdf
    • https://www.interfaceventos.com.br/imagens/files/how-do-u-hack-roblox_GM431946152.pdf
    • https://www.interfaceventos.com.br/imagens/files/roblox-hacks-for-mac_GM431946152.pdf
    • https://www.interfaceventos.com.br/imagens/files/coin-master-get-free-spins_GM406889139.pdf
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_003_off0000465f.bin
7069b69bdc9fada3e56090b25c7e31b7d1be553fd01ba633dec8b4ebdc8bde24
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x465F 27924 bytes
font_01_sfnt_off00008584.bin
79fc292783aafa0d2798f175881928b0c75cb864ff282a378c41953696f75480
pdf-font-stream PDF embedded font (sfnt) at offset 0x8584 18892 bytes