Malicious PDF — malware analysis report

Static analysis result for SHA-256 881b5d8abde0dde4…

MALICIOUS

PDF

48.1 KB Created: 2021-06-02 02:46:47 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: 6e9094e8d9be4ea22d2ee7161dbfe76a SHA-1: 7ec068347ba7b2ae8d76100d37d7af64f44f8e4c SHA-256: 881b5d8abde0dde4e2861f7bfd624a529f46adba5a3db7a5617a40828ac9e5d0
82 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The document contains multiple embedded URLs and a prominent external URI, all related to game hacks and free currency, indicating a lure for users to download potentially malicious files. The heuristic for a password-protected archive suggests a method to bypass security scans by encrypting the payload. While no scripts were directly extracted, the ML classifier and embedded URLs strongly suggest a malicious intent to deliver a second-stage payload.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9796

Heuristics 4

  • Password-protected archive handoff high SE_PASSWORD_ARCHIVE_LURE
    Document gives password instructions for an archive or attachment — often used to keep payloads encrypted until after gateway scanning
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://netcdn.xyz/app/431946152/robux-free-illimited-game-hack
    • http://thinkpro.ca/wp-content/uploads/fsqm-files/roblox-how-to-activate-hack-gui-script_GM431946152.pdf
    • http://thinkpro.ca/wp-content/uploads/fsqm-files/free-tiktok-likes_GM835599320.pdf
    • http://thinkpro.ca/wp-content/uploads/fsqm-files/free-minecraft-accounts-2021_GM479516143.pdf
    • http://thinkpro.ca/wp-content/uploads/fsqm-files/funbloxxyz-free-robux_GM431946152.pdf
    • http://thinkpro.ca/wp-content/uploads/fsqm-files/minecraft-free-install_GM479516143.pdf
    • http://thinkpro.ca/wp-content/uploads/fsqm-files/roblox-hacked-client-buy_GM431946152.pdf
    • http://thinkpro.ca/wp-content/uploads/fsqm-files/minecraft-free-computer-game_GM479516143.pdf
    • http://thinkpro.ca/wp-content/uploads/fsqm-files/how-to-get-free-robux-and-free-tix-on-roblox_GM431946152.pdf
    • http://thinkpro.ca/wp-content/uploads/fsqm-files/roblox-hack-account-2021_GM431946152.pdf
    • http://thinkpro.ca/wp-content/uploads/fsqm-files/can-cheat-engine-hack-roblox_GM431946152.pdf
    • http://thinkpro.ca/wp-content/uploads/fsqm-files/minecraft-free-trial_GM479516143.pdf
    • http://thinkpro.ca/wp-content/uploads/fsqm-files/free-robux-survey_GM431946152.pdf
    • http://thinkpro.ca/wp-content/uploads/fsqm-files/roblox-screen-recorder-free_GM431946152.pdf
    • http://thinkpro.ca/wp-content/uploads/fsqm-files/free-codes-for-toys-on-roblox_GM431946152.pdf
    • http://thinkpro.ca/wp-content/uploads/fsqm-files/tiktok-likes-free_GM835599320.pdf
    • http://thinkpro.ca/wp-content/uploads/fsqm-files/robux-hacks-2021_GM431946152.pdf
    • http://thinkpro.ca/wp-content/uploads/fsqm-files/hack-para-jailbreak-2021-roblox-de-sontix_GM431946152.pdf
    • http://thinkpro.ca/wp-content/uploads/fsqm-files/robux-free-2021_GM431946152.pdf
    • http://thinkpro.ca/wp-content/uploads/fsqm-files/free-tiktok-followers-no-human-verification-or-survey_GM835599320.pdf
    • http://thinkpro.ca/wp-content/uploads/fsqm-files/minecraft-server-hacks_GM479516143.pdf
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_004_off00004f66.bin
598f7003ddefa878df54080162919f21668d8507f3ca40b16815047efff9f2f2
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x4F66 25464 bytes
font_01_sfnt_off0000899d.bin
f866077ce59d6ea276f75e4af76daa2aab5f3a1a679df144776123d85664d65c
pdf-font-stream PDF embedded font (sfnt) at offset 0x899D 6100 bytes
font_02_sfnt_off00009828.bin
f8d7b03773f7ed67bd0b3f884d0411c3658be9f6b8773f2a24b85be0989d0760
pdf-font-stream PDF embedded font (sfnt) at offset 0x9828 18748 bytes