Malicious PDF — malware analysis report

Static analysis result for SHA-256 906b0e2ad5e17699…

MALICIOUS

PDF

35.0 KB Created: 2021-07-03 10:14:59 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: a995acec1e2d618afea08eeefcf4de97 SHA-1: 76335b58a1f44c64b162405940054d26fec2fba8 SHA-256: 906b0e2ad5e17699d48ff32af80409969d98733ff8fbd8fb50147407f7cc7e34
82 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The document displays a fake CAPTCHA to lure users into clicking a link, which is a common social engineering tactic. The embedded URLs suggest the document is designed to trick users into downloading potentially malicious files related to game cheats or hacks. No scripts were extracted from this sample, limiting further analysis of its execution behavior.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9980

Heuristics 4

  • Fake CAPTCHA / human verification prompt high SE_FAKE_CAPTCHA
    Document displays a fake CAPTCHA or human-verification prompt — used to trick users into running commands or pressing keyboard shortcuts
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://netcdn.co/app/431946152/boku-no-roblox-hack-game-hack
    • http://www.elearning.mysadam.info/__statics/gudangsoal/files/freerubux_GM431946152.pdf
    • http://elearning.mysadam.info/__statics/gudangsoal/files/free-robux-sites-2021_GM431946152.pdf
    • http://www.elearning.mysadam.info/__statics/gudangsoal/files/coin-master-free-coins-and-spins_GM406889139.pdf
    • http://elearning.mysadam.info/__statics/gudangsoal/files/coin-master-free-spin-reward-links_GM406889139.pdf
    • http://elearning.mysadam.info/__statics/gudangsoal/files/cheat-codes-for-adopt-me-roblox_GM431946152.pdf
    • http://elearning.mysadam.info/__statics/gudangsoal/files/minecraft-hacked-client-bedrock_GM479516143.pdf
    • http://www.elearning.mysadam.info/__statics/gudangsoal/files/roblox-apk-hack_GM431946152.pdf
    • http://www.elearning.mysadam.info/__statics/gudangsoal/files/coin-master-free-coins-and-spins-daily-summary_GM406889139.pdf
    • http://elearning.mysadam.info/__statics/gudangsoal/files/coinmaster-spin-ml-link_GM406889139.pdf
    • http://www.elearning.mysadam.info/__statics/gudangsoal/files/hack-coin-master-nyc_GM406889139.pdf
    • http://www.elearning.mysadam.info/__statics/gudangsoal/files/hack-account-of-roblox_GM431946152.pdf
    • http://elearning.mysadam.info/__statics/gudangsoal/files/free-robux-no-gift-card_GM431946152.pdf
    • http://elearning.mysadam.info/__statics/gudangsoal/files/free-robux-obby_GM431946152.pdf
    • http://www.elearning.mysadam.info/__statics/gudangsoal/files/free-robux-questions_GM431946152.pdf
    • http://www.elearning.mysadam.info/__statics/gudangsoal/files/free-robux-no-human-verification_GM431946152.pdf
    • http://elearning.mysadam.info/__statics/gudangsoal/files/free-roblox-bundles-2021_GM431946152.pdf
    • http://elearning.mysadam.info/__statics/gudangsoal/files/coin-master-hack-pro-gamers_GM406889139.pdf
    • http://www.elearning.mysadam.info/__statics/gudangsoal/files/free-spin-coin-master-2021_GM406889139.pdf
    • http://elearning.mysadam.info/__statics/gudangsoal/files/easy-way-to-get-robux_GM431946152.pdf
    • http://www.elearning.mysadam.info/__statics/gudangsoal/files/coin-master-free-spins-link-no-verification-2021_GM406889139.pdf
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00003178.bin
7aa918bf3820bc00f744883e65ffe1fdd905e2b9e66ec74c51064497f8fa0881
pdf-font-stream PDF embedded font (sfnt) at offset 0x3178 22684 bytes
font_01_sfnt_off00006442.bin
19135353552efac95f1c00fc10c19e7b17473ce31d967bef669c8f4fb6ca84ac
pdf-font-stream PDF embedded font (sfnt) at offset 0x6442 18796 bytes