Malicious PDF — malware analysis report

Static analysis result for SHA-256 a2e33921c8fd5a5f…

MALICIOUS

PDF

44.5 KB Created: 2021-06-01 01:26:48 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: 086f03ede51cf289f6ae4ff4863ef2c4 SHA-1: 1f39194e4149635e6a6fc2a8667b51aa9eb292b4 SHA-256: a2e33921c8fd5a5f95711fb8a98857f7b1d3bafb17269fc8bf8370a1c40da691
82 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The document uses a social engineering lure related to game hacks to trick users into downloading a payload. It contains multiple embedded URLs pointing to potentially malicious content, and heuristic analysis indicates it's designed to prompt users to install browser extensions or updates. The ML classifier also flagged this PDF as malicious with high confidence.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9865

Heuristics 4

  • Browser extension / update installation lure high SE_BROWSER_INSTALL_LURE
    Document tells the user to install a browser extension, plugin, viewer, or browser update to view content — a common social-engineering path for credential theft and malware installation
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://netcdn.xyz/app/431946152/roblox-assassin-hacks-2021-game-hack
    • https://zbych-pol.pl/wp-content/uploads/fsqm-files/real-free-robux-codes_GM431946152.pdf
    • https://zbych-pol.pl/wp-content/uploads/fsqm-files/roblox-admin-hack-2021_GM431946152.pdf
    • https://zbych-pol.pl/wp-content/uploads/fsqm-files/free-roblox-accounts-rich_GM431946152.pdf
    • https://zbych-pol.pl/wp-content/uploads/fsqm-files/free-robux-card-codes_GM431946152.pdf
    • https://zbych-pol.pl/wp-content/uploads/fsqm-files/free-roblox-girl-accounts-with-robux_GM431946152.pdf
    • https://zbych-pol.pl/wp-content/uploads/fsqm-files/buy-tiktok-followers-free_GM835599320.pdf
    • https://zbych-pol.pl/wp-content/uploads/fsqm-files/get-minecraft-for-free_GM479516143.pdf
    • https://zbych-pol.pl/wp-content/uploads/fsqm-files/free-robux-games-on-roblox_GM431946152.pdf
    • https://zbych-pol.pl/wp-content/uploads/fsqm-files/how-to-get-minecraft-bedrock-edition-for-free_GM479516143.pdf
    • https://zbych-pol.pl/wp-content/uploads/fsqm-files/100-free-spins-coin-master_GM406889139.pdf
    • https://zbych-pol.pl/wp-content/uploads/fsqm-files/minecraft-free-download-ios_GM479516143.pdf
    • https://zbych-pol.pl/wp-content/uploads/fsqm-files/how-to-get-free-robux-no-human-verification_GM431946152.pdf
    • https://zbych-pol.pl/wp-content/uploads/fsqm-files/how-to-hack-an-roblox-account-2021-november_GM431946152.pdf
    • https://zbych-pol.pl/wp-content/uploads/fsqm-files/juno-hack-filedropper-roblox_GM431946152.pdf
    • https://zbych-pol.pl/wp-content/uploads/fsqm-files/free-minecraft-mods_GM479516143.pdf
    • https://zbych-pol.pl/wp-content/uploads/fsqm-files/roblox-sprinting-simulator-hack-2021_GM431946152.pdf
    • https://zbych-pol.pl/wp-content/uploads/fsqm-files/roblox-robux-hack-download-free-2021_GM431946152.pdf
    • https://zbych-pol.pl/wp-content/uploads/fsqm-files/roblox-promo-code-to-get-free-robux_GM431946152.pdf
    • https://zbych-pol.pl/wp-content/uploads/fsqm-files/a-code-for-free-robux-script_GM431946152.pdf
    • https://zbych-pol.pl/wp-content/uploads/fsqm-files/kuso-ico-roblox-free_GM431946152.pdf
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000052f2.bin
380438e4b728e2f94cd996cc0258bb5adf9ea6f6cbebecb251423a11798bb4c4
pdf-font-stream PDF embedded font (sfnt) at offset 0x52F2 24040 bytes
font_01_sfnt_off000089d4.bin
4bf27753f24ea651548757ae5c22a2db50a6192bb64424b738798e31a2acaef8
pdf-font-stream PDF embedded font (sfnt) at offset 0x89D4 18704 bytes