Malicious PDF — malware analysis report

Static analysis result for SHA-256 8cc7c4f71b03c23a…

MALICIOUS

PDF

44.3 KB Created: 2021-06-11 01:52:37 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: ed76640f7f6196212d115aede5899980 SHA-1: aca7f9acf255c141077961741835ab632b3e156b SHA-256: 8cc7c4f71b03c23ab5605139cbedcbe4c8260412740756ff40e585221374a834
102 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The document contains a lure related to free game items and includes a critical heuristic for requesting recovery secrets, indicating a phishing attempt. The embedded URL points to a suspicious domain, likely serving as a landing page for credential harvesting or malware distribution. No scripts were extracted from this sample, but the presence of external URIs and the ML classifier's high confidence suggest malicious intent.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9865

Heuristics 4

  • Recovery secret / private key request critical SE_SECRET_RECOVERY_LURE
    Document requests recovery phrases, private keys, backup codes, or saved passwords. Requests for these secrets in a document are high-risk.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://netcdn.tw/app/431946152/roblox-girl-outfits-free-game-hack
    • http://pustaka.fkm.unand.ac.id/repository/coin-master-free-spins-for-today_GM406889139.pdf
    • http://pustaka.fkm.unand.ac.id/repository/free-robux-no-human-verification-or-survey-or-download-2021_GM431946152.pdf
    • http://pustaka.fkm.unand.ac.id/repository/rc8-roblox-hack_GM431946152.pdf
    • http://pustaka.fkm.unand.ac.id/repository/rbx-free-robux_GM431946152.pdf
    • http://pustaka.fkm.unand.ac.id/repository/rbx-points-get-free-robux_GM431946152.pdf
    • http://pustaka.fkm.unand.ac.id/repository/free-robux-survey_GM431946152.pdf
    • http://pustaka.fkm.unand.ac.id/repository/free-robux-no-password-needed-or-verification_GM431946152.pdf
    • http://pustaka.fkm.unand.ac.id/repository/free-robux-please_GM431946152.pdf
    • http://pustaka.fkm.unand.ac.id/repository/roblox-dragon-ball-final-hack_GM431946152.pdf
    • http://pustaka.fkm.unand.ac.id/repository/games-that-give-you-free-robux_GM431946152.pdf
    • http://pustaka.fkm.unand.ac.id/repository/ways-to-get-free-robux-2021_GM431946152.pdf
    • http://pustaka.fkm.unand.ac.id/repository/free-robux-quiz_GM431946152.pdf
    • http://pustaka.fkm.unand.ac.id/repository/free-roblox-executor-no-key_GM431946152.pdf
    • http://pustaka.fkm.unand.ac.id/repository/minecraft-launcher-free_GM479516143.pdf
    • http://pustaka.fkm.unand.ac.id/repository/free-robux-generator-no-verification_GM431946152.pdf
    • http://pustaka.fkm.unand.ac.id/repository/play-minecraft-for-free_GM479516143.pdf
    • http://pustaka.fkm.unand.ac.id/repository/coin-master-daily-free-spins_GM406889139.pdf
    • http://pustaka.fkm.unand.ac.id/repository/roblox-helicopter-free-2021_GM431946152.pdf
    • http://pustaka.fkm.unand.ac.id/repository/free-coins-coin-master-2021_GM406889139.pdf
    • http://pustaka.fkm.unand.ac.id/repository/free-robux-hack-tool_GM431946152.pdf
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_004_off00004ed9.bin
fa45bcfbca0d06ccf0eb8dadefba5e913b2db0f7c905622098c1899f7b87ce98
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x4ED9 26372 bytes
font_01_sfnt_off00008a90.bin
244524c4b8304af758b57e8849bea4f73aa76a56654ce3bb9ee46995839bb28c
pdf-font-stream PDF embedded font (sfnt) at offset 0x8A90 18312 bytes