Malicious PDF — malware analysis report

Static analysis result for SHA-256 9008ae43242fc4c1…

MALICIOUS

PDF

59.4 KB Created: 2021-06-08 17:41:52 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: a647c02c0e7f7b993eb58515c2debd35 SHA-1: 39cbfc6cfda1d3d01ea51c8401ce277356edbab0 SHA-256: 9008ae43242fc4c1a9ff40a7a351cb18fa38a38466e424ef4fcde58cb112433a
82 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The document contains lures related to game hacking and obtaining in-game currency, indicated by the document body and numerous embedded URLs. The presence of a MFA lure heuristic suggests an attempt to harvest credentials or session tokens. While no scripts were explicitly extracted, the ML classifier and embedded URLs strongly indicate malicious intent, likely leading to a phishing site or a download of further malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9717

Heuristics 4

  • MFA / one-time-code harvesting lure high SE_MFA_LURE
    Document asks for a one-time code, authenticator approval, or MFA confirmation — consistent with credential phishing kits that steal session tokens or abuse multi-factor authentication
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://netcdn.tw/app/431946152/how-to-hack-roblox-fort-albreta-game-hack
    • https://dolphintour.vn/images/uploadsfiles/how-to-get-1-million-robux-for-free-really-easy_GM431946152.pdf
    • https://dolphintour.vn/images/uploadsfiles/master-coin-free_GM406889139.pdf
    • https://dolphintour.vn/images/uploadsfiles/play-coin-master-online-free_GM406889139.pdf
    • https://dolphintour.vn/images/uploadsfiles/how-to-hack-minecraft_GM479516143.pdf
    • https://dolphintour.vn/images/uploadsfiles/coin-master-free-attack_GM406889139.pdf
    • https://dolphintour.vn/images/uploadsfiles/how-to-get-robux-easy_GM431946152.pdf
    • https://dolphintour.vn/images/uploadsfiles/coin-master-time-hack-ios_GM406889139.pdf
    • https://dolphintour.vn/images/uploadsfiles/how-to-get-free-tiktok-followers_GM835599320.pdf
    • https://dolphintour.vn/images/uploadsfiles/hack-robux_GM431946152.pdf
    • https://dolphintour.vn/images/uploadsfiles/coin-master-cheat-apk-free-download_GM406889139.pdf
    • https://dolphintour.vn/images/uploadsfiles/hack-coin-master-apk-31_GM406889139.pdf
    • https://dolphintour.vn/images/uploadsfiles/freegames911com-coinmastertipsandcheats2021freecoinsandspins_GM406889139.pdf
    • https://dolphintour.vn/images/uploadsfiles/how-to-get-free-robux-games_GM431946152.pdf
    • https://dolphintour.vn/images/uploadsfiles/how-to-get-free-robux-without-human-verification_GM431946152.pdf
    • https://dolphintour.vn/images/uploadsfiles/bux-life-free-robux_GM431946152.pdf
    • https://dolphintour.vn/images/uploadsfiles/minecraft-apk-free-download_GM479516143.pdf
    • https://dolphintour.vn/images/uploadsfiles/free-robux-microsoft_GM431946152.pdf
    • https://dolphintour.vn/images/uploadsfiles/coin-master-free-spins-daily-1-ga_GM406889139.pdf
    • https://dolphintour.vn/images/uploadsfiles/roblox-cheat-engine-forcefield_GM431946152.pdf
    • https://dolphintour.vn/images/uploadsfiles/free-roblox-shirt-templates-2021_GM431946152.pdf
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_004_off0000544a.bin
419f84b57a45391a82de656743176da536ff58272e8d272b551fe071191649a9
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x544A 38608 bytes
font_01_sfnt_off0000a8d6.bin
ddfd86c88a6b8304bc31eeb9f28c8110fac325cdacc87503bacf4ac741777490
pdf-font-stream PDF embedded font (sfnt) at offset 0xA8D6 8704 bytes
font_02_sfnt_off0000c540.bin
ed0c7866d47fc50c738d18f991978fc7d55e2bc441c9cf00c5fa2da8737f0b1f
pdf-font-stream PDF embedded font (sfnt) at offset 0xC540 18612 bytes