Malicious PDF — malware analysis report

Static analysis result for SHA-256 9e7ab4c00847d72b…

MALICIOUS

PDF

38.3 KB Created: 2021-06-28 01:03:12 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: 9ca97624871a1966ae334a60ff19f12d SHA-1: fcca5e509d88360a37de03a9179caad62e72a6da SHA-256: 9e7ab4c00847d72bd20a9a2f05398c20ede079c99ac558d2844a6ee23f30d1b3
82 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The document contains multiple URLs and text fragments related to game exploits and free in-game currency, strongly suggesting a lure for users to download malicious software. The ML classifier also flagged this PDF as malicious. The presence of embedded URLs and the document's content indicate an attempt to trick users into downloading a second-stage payload, likely an exploit injector.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9985

Heuristics 4

  • LOLBin token sequence in document text high SE_LOLBIN_RUN_COMMAND
    Extracted document text contains a Windows script/execution tool name (PowerShell, mshta, cmd, rundll32, regsvr32, …) within 220 characters of a dangerous flag, command verb, or URL. This is a visible 'run this' instruction in HTML/PDF/RTF lure bodies, or — in macro-laden Office files — the macro's own string-pool entries appearing adjacent in extracted text.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://netcdn.co/app/431946152/free-roblox-exploit-injector-game-hack
    • http://digilib.ulm.ac.id/pusat/repository/lazy-blocks-com-free-robux_GM431946152.pdf
    • http://digilib.ulm.ac.id/pusat/repository/get-robux-for-free-2021_GM431946152.pdf
    • http://digilib.ulm.ac.id/pusat/repository/how-to-get-minecraft-windows-10-edition-for-free_GM479516143.pdf
    • http://digilib.ulm.ac.id/pusat/repository/free-roblox-clothes-templates_GM431946152.pdf
    • http://digilib.ulm.ac.id/pusat/repository/free-robux-100-working_GM431946152.pdf
    • http://digilib.ulm.ac.id/pusat/repository/pig-master-free-coins-and-spins_GM406889139.pdf
    • http://digilib.ulm.ac.id/pusat/repository/free-roblox-gfx_GM431946152.pdf
    • http://digilib.ulm.ac.id/pusat/repository/robux-no-human-verification_GM431946152.pdf
    • http://digilib.ulm.ac.id/pusat/repository/coin-master-free-spins-and-coins-today-gift-reward_GM406889139.pdf
    • http://digilib.ulm.ac.id/pusat/repository/coin-master-hack-xyz-download-free_GM406889139.pdf
    • http://digilib.ulm.ac.id/pusat/repository/bloxpage-free-robux_GM431946152.pdf
    • http://digilib.ulm.ac.id/pusat/repository/cmd-comandos-hack-juegos-roblox_GM431946152.pdf
    • http://digilib.ulm.ac.id/pusat/repository/free-spins-coin-master-november-2021_GM406889139.pdf
    • http://digilib.ulm.ac.id/pusat/repository/hack-mad-paintball-roblox_GM431946152.pdf
    • http://digilib.ulm.ac.id/pusat/repository/pubg-uc-code-redeem_GM1330123889.pdf
    • http://digilib.ulm.ac.id/pusat/repository/minecraft-logo-maker-free_GM479516143.pdf
    • http://digilib.ulm.ac.id/pusat/repository/earn-free-robux-today_GM431946152.pdf
    • http://digilib.ulm.ac.id/pusat/repository/free-robux-and-tix-no-download-no-survey_GM431946152.pdf
    • http://digilib.ulm.ac.id/pusat/repository/roblox-hacks-and-cheats-for-robux_GM431946152.pdf
    • http://digilib.ulm.ac.id/pusat/repository/how-to-get-free-robux-earnrobux-today_GM431946152.pdf
    • https://www.roblox.com/.I
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00003d71.bin
6dbeaf05daed9e30317a1464b84ecc8830561b378eab4aa4a063c86e0b021719
pdf-font-stream PDF embedded font (sfnt) at offset 0x3D71 22844 bytes
font_01_sfnt_off0000707d.bin
b314b35b78bdf8952d833b6605ff8c8994fedb964a0618cb4abdfcb7616db7a5
pdf-font-stream PDF embedded font (sfnt) at offset 0x707D 19240 bytes