Malicious PDF — malware analysis report

Static analysis result for SHA-256 76381ba54bf63443…

MALICIOUS

PDF

45.9 KB Created: 2021-06-03 13:40:48 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7) First seen: 2021-09-16
MD5: 110e104bd429cf69c787a1f43e141a7b SHA-1: 5c45bb0f7bf1136f3da5da63fd1faea1141c9f89 SHA-256: 76381ba54bf634431d3b800e6ba31d62a7e213fd0940a0f5278dba6cc4559a53
62 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF document contains embedded URLs and text that strongly suggest a lure for downloading game-related hacks and mods. The presence of multiple URLs pointing to similar content, combined with the ML classifier's high confidence, indicates a malicious intent to trick users into downloading potentially harmful files. The document body's garbled nature and the embedded URLs suggest it's designed to redirect users to external sites for further malicious actions.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9864

Heuristics 4

  • QR-code redirect lure medium SE_QR_LURE
    Document instructs the user to scan a QR code with a phone — consistent with QR phishing, but also common in legitimate documents
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://netcdn.online/app/479516143/free-mods-for-minecraft-pe-game-hack PDF link annotation
    • http://perpustakaan.poltekkespangkalpinang.ac.id//repository/roblox-hack-download_GM431946152.pdfIn PDF document text
    • http://perpustakaan.poltekkespangkalpinang.ac.id/repository/coin-master-free-spins-2021_GM406889139.pdfIn PDF document text
    • http://perpustakaan.poltekkespangkalpinang.ac.id/repository/coin-master-free-spin-and-coin-links_GM406889139.pdfIn PDF document text
    • http://perpustakaan.poltekkespangkalpinang.ac.id//repository/withdraw-robux_GM431946152.pdfIn PDF document text
    • http://perpustakaan.poltekkespangkalpinang.ac.id/repository/wurst-18-9_GM479516143.pdfIn PDF document text
    • http://perpustakaan.poltekkespangkalpinang.ac.id//repository/coin-master-hack-no-human-verification-2021_GM406889139.pdfIn PDF document text
    • http://perpustakaan.poltekkespangkalpinang.ac.id/repository/free-games-like-roblox_GM431946152.pdfIn PDF document text
    • http://perpustakaan.poltekkespangkalpinang.ac.id/repository/minecraft-maps-pe-free-download_GM479516143.pdfIn PDF document text
    • http://perpustakaan.poltekkespangkalpinang.ac.id/repository/roblox-hack-apk_GM431946152.pdfIn PDF document text
    • http://perpustakaan.poltekkespangkalpinang.ac.id//repository/how-to-get-1-million-robux-for-free-2021_GM431946152.pdfIn PDF document text
    • http://perpustakaan.poltekkespangkalpinang.ac.id//repository/robux-free-co_GM431946152.pdfIn PDF document text
    • http://perpustakaan.poltekkespangkalpinang.ac.id//repository/coin-master-free-spins-link-download-apk_GM406889139.pdfIn PDF document text
    • http://perpustakaan.poltekkespangkalpinang.ac.id//repository/how-to-get-free-robux-website_GM431946152.pdfIn PDF document text
    • http://perpustakaan.poltekkespangkalpinang.ac.id/repository/scary-larry-roblox_GM431946152.pdfIn PDF document text
    • http://perpustakaan.poltekkespangkalpinang.ac.id//repository/minecraft-hacker-skin_GM479516143.pdfIn PDF document text
    • http://perpustakaan.poltekkespangkalpinang.ac.id/repository/free-spins-for-coin-master-on-1-19-19_GM406889139.pdfIn PDF document text
    • http://perpustakaan.poltekkespangkalpinang.ac.id//repository/how-to-hack-roblox-2021_GM431946152.pdfIn PDF document text
    • http://perpustakaan.poltekkespangkalpinang.ac.id/repository/coin-master-daily-free-spins-and-coins_GM406889139.pdfIn PDF document text
    • http://perpustakaan.poltekkespangkalpinang.ac.id//repository/free-spins-on-coin-master-2021_GM406889139.pdfIn PDF document text
    • http://perpustakaan.poltekkespangkalpinang.ac.id//repository/is-tiktok-free-on-voxi_GM835599320.pdfIn PDF document text
    • http://en.wikipedia.org/wiki/MIT_LicenseIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_004_off00005888.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x5888 25308 bytes
SHA-256: 4313e316f4de3c7e0b4ddb59996c59cd6d537b60769576a1f67f1f525838abe8
font_01_sfnt_off000091f0.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x91F0 18040 bytes
SHA-256: 55677d50e7f19372d6dfb723d72c398dee248f925afb4425ab44c3bb4ecd28f4