Malicious PDF — malware analysis report

Static analysis result for SHA-256 8428fc7b719d05c3…

MALICIOUS

PDF

42.5 KB Created: 2021-05-19 23:12:49 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7) First seen: 2021-09-27
MD5: e29192c6bf7bd46f7f03993e61ce263b SHA-1: 0ac3f8a5e9364b98c682be474e1e7de5218ef75d SHA-256: 8428fc7b719d05c303369e9839b827d2a7c700ad92a6ca1c5f972a09796818af
82 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The document displays a fake CAPTCHA or human verification prompt, a common lure to trick users into clicking malicious links. The embedded URLs, such as 'https://netcdn.xyz/app/1330123889/can-pubg-uc-be-hacked-game-hack', likely lead to further malicious content or downloads. While no scripts were explicitly extracted, the PDF structure and heuristics suggest an attempt to exploit user interaction for malicious purposes.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9971

Heuristics 4

  • Fake CAPTCHA / human verification prompt high SE_FAKE_CAPTCHA
    Document displays a fake CAPTCHA or human-verification prompt — used to trick users into running commands or pressing keyboard shortcuts
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://netcdn.xyz/app/1330123889/can-pubg-uc-be-hacked-game-hack PDF link annotation
    • https://labdagatismk1pundong.com/repository/free-robux-codes-2021_GM431946152.pdfIn PDF document text
    • https://labdagatismk1pundong.com/repository/rbxcity-free-robux_GM431946152.pdfIn PDF document text
    • https://www.labdagatismk1pundong.com/repository/is-coin-master-hack-safe_GM406889139.pdfIn PDF document text
    • https://labdagatismk1pundong.com/repository/how-to-get-minecraft-for-free-on-xbox_GM479516143.pdfIn PDF document text
    • https://www.labdagatismk1pundong.com/repository/how-to-hack-roblox-to-get-robux_GM431946152.pdfIn PDF document text
    • https://www.labdagatismk1pundong.com/repository/free-robux-no-verify-2021_GM431946152.pdfIn PDF document text
    • https://www.labdagatismk1pundong.com/repository/free-spins-coin-master-site-wwwquoracom_GM406889139.pdfIn PDF document text
    • https://labdagatismk1pundong.com/repository/can-you-actually-get-free-robux_GM431946152.pdfIn PDF document text
    • https://labdagatismk1pundong.com/repository/coin-master-spins_GM406889139.pdfIn PDF document text
    • https://www.labdagatismk1pundong.com/repository/coin-master-spin-ml-link_GM406889139.pdfIn PDF document text
    • https://www.labdagatismk1pundong.com/repository/cm-spin-link_GM406889139.pdfIn PDF document text
    • https://labdagatismk1pundong.com/repository/how-to-get-free-stuff-on-roblox_GM431946152.pdfIn PDF document text
    • https://www.labdagatismk1pundong.com/repository/earn-free-robux-for-roblox_GM431946152.pdfIn PDF document text
    • https://labdagatismk1pundong.com/repository/coin-master-time-speed-hack_GM406889139.pdfIn PDF document text
    • https://labdagatismk1pundong.com/repository/free-group-roblox_GM431946152.pdfIn PDF document text
    • https://www.labdagatismk1pundong.com/repository/free-draw-roblox_GM431946152.pdfIn PDF document text
    • https://www.labdagatismk1pundong.com/repository/classic-minecraft-net-hacks_GM479516143.pdfIn PDF document text
    • https://www.labdagatismk1pundong.com/repository/coin-master-free-daily-spins_GM406889139.pdfIn PDF document text
    • https://www.labdagatismk1pundong.com/repository/free-robux-websites-2021_GM431946152.pdfIn PDF document text
    • https://labdagatismk1pundong.com/repository/free-roblox-accounts-with-robux-2021_GM431946152.pdfIn PDF document text
    • http://en.wikipedia.org/wiki/MIT_LicenseIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_003_off0000466d.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x466D 28420 bytes
SHA-256: 8e699df312f9502b94b371e402b2b72e485352256212dc8f0511f0b3e7f744c3
font_01_sfnt_off0000834f.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x834F 18468 bytes
SHA-256: e4e65200b262af3b84ac1afa1e481a5fcfdc9c086a0e4213b0855c66829c52ae