Malicious PDF — malware analysis report

Static analysis result for SHA-256 88d57464814a2f01…

MALICIOUS

PDF

44.9 KB Created: 2021-06-09 15:31:15 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: 477b1613ae86f13170822d15aa4fc7a4 SHA-1: 6fc347b5b596d5613faf9ec8e683330f81948f74 SHA-256: 88d57464814a2f01a6828aac00aea0711786a374c3c80ff6026f2191dc9f929f
62 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains an embedded URL that leads to a download, disguised as a free Robux generator. The document body, though heavily obfuscated, contains references to 'Roblox' and 'free Robux', aligning with common phishing and scam lures. The presence of an external URI and the ML classifier's high confidence score indicate malicious intent, likely to trick users into downloading a second-stage payload.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9865

Heuristics 4

  • Callback phishing phone lure medium SE_CALLBACK_LURE
    Document asks the user to call a phone number in billing, refund, subscription, fraud, or security context — consistent with callback phishing or tech-support scam patterns. Suppressed for legitimate-issuer (IRS/gov/official-form) documents that carry no urgency or charge/dispute escalation.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://netcdn.tw/app/431946152/roblox-today-free-robux-game-hack
    • http://www.vermaagri.com/uploaded_files/userfiles/files/roblox-free-login_GM431946152.pdf
    • http://vermaagri.com/uploaded_files/userfiles/files/free-robux-websites-that-actually-work_GM431946152.pdf
    • http://vermaagri.com/uploaded_files/userfiles/files/minecraft-menu_GM479516143.pdf
    • http://vermaagri.com/uploaded_files/userfiles/files/free-face-roblox_GM431946152.pdf
    • http://vermaagri.com/uploaded_files/userfiles/files/how-to-use-scripts-in-roblox-hack_GM431946152.pdf
    • http://vermaagri.com/uploaded_files/userfiles/files/robloxheroxyz-free-robux_GM431946152.pdf
    • http://vermaagri.com/uploaded_files/userfiles/files/coin-master-free-spins-link-no-verification-2021_GM406889139.pdf
    • http://vermaagri.com/uploaded_files/userfiles/files/how-do-you-get-free-robux-without-doing-anything_GM431946152.pdf
    • http://vermaagri.com/uploaded_files/userfiles/files/25-free-spins-coin-master_GM406889139.pdf
    • http://vermaagri.com/uploaded_files/userfiles/files/dominus-roblox-free_GM431946152.pdf
    • http://www.vermaagri.com/uploaded_files/userfiles/files/free-robux-on-phone_GM431946152.pdf
    • http://www.vermaagri.com/uploaded_files/userfiles/files/coin-master-unlimited-free-spins-link-2021_GM406889139.pdf
    • http://www.vermaagri.com/uploaded_files/userfiles/files/minecraft-games-free-download_GM479516143.pdf
    • http://vermaagri.com/uploaded_files/userfiles/files/coin-master-hacksco_GM406889139.pdf
    • http://vermaagri.com/uploaded_files/userfiles/files/give-me-robux-now_GM431946152.pdf
    • http://www.vermaagri.com/uploaded_files/userfiles/files/how-to-get-free-robux-for-real_GM431946152.pdf
    • http://vermaagri.com/uploaded_files/userfiles/files/free-robux-without-verification-or-survey_GM431946152.pdf
    • http://vermaagri.com/uploaded_files/userfiles/files/get-free-robux-com_GM431946152.pdf
    • http://vermaagri.com/uploaded_files/userfiles/files/how-do-you-get-free-pet-food-in-coin-master_GM406889139.pdf
    • http://www.vermaagri.com/uploaded_files/userfiles/files/robux-generator-no-survey_GM431946152.pdf
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000053a1.bin
1dd3fa707d34a74dd7747b2db0049dd55a9210db87ae95914d392a7c5d2f828f
pdf-font-stream PDF embedded font (sfnt) at offset 0x53A1 24480 bytes
font_01_sfnt_off00008ba8.bin
78cc9f9af2d1701a0d6381170a9a52c1f36bb62e815b24d954ac78338fa2c489
pdf-font-stream PDF embedded font (sfnt) at offset 0x8BA8 18668 bytes