Malicious PDF — malware analysis report

Static analysis result for SHA-256 a8ebca97b00aa38a…

MALICIOUS

PDF

43.0 KB Created: 2021-06-03 11:17:42 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: 56f1423a59ee8275af6ecf99c80d1fc4 SHA-1: 30936b2a9cb5ca673f9c7f95011e044a35255999 SHA-256: a8ebca97b00aa38a7d601d5357ad6a5f6e2f80e3e2c22f047fcb8d9f341b6fcb
62 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The ML classifier and embedded URLs strongly indicate malicious intent. The document body, though partially garbled, contains references to 'free Roblox followers' and 'free Robux', alongside URLs pointing to similar lures. The presence of embedded URLs suggests the document is designed to redirect users to external sites, likely to download malware or engage in further phishing activities.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9874

Heuristics 4

  • Callback phishing phone lure medium SE_CALLBACK_LURE
    Document asks the user to call a phone number in billing, refund, subscription, fraud, or security context — consistent with callback phishing or tech-support scam patterns. Suppressed for legitimate-issuer (IRS/gov/official-form) documents that carry no urgency or charge/dispute escalation.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://netcdn.online/app/431946152/free-roblox-followers-game-hack
    • http://library.itekes-bali.ac.id/repository/free-robux-earn_GM431946152.pdf
    • http://library.itekes-bali.ac.id/repository/coin-master-apk-free-download_GM406889139.pdf
    • http://library.itekes-bali.ac.id/repository/how-to-hack-roblox-accounts-2021-easy_GM431946152.pdf
    • http://library.itekes-bali.ac.id/repository/how-to-get-free-robux-easy-on-phone_GM431946152.pdf
    • http://library.itekes-bali.ac.id/repository/free-robux-scam_GM431946152.pdf
    • http://library.itekes-bali.ac.id/repository/get-more-free-spins-on-coin-master_GM406889139.pdf
    • http://library.itekes-bali.ac.id/repository/minecraft-book-collection_GM479516143.pdf
    • http://library.itekes-bali.ac.id/repository/how-to-get-free-spins-for-coin-master_GM406889139.pdf
    • http://library.itekes-bali.ac.id/repository/mcpe-com_GM479516143.pdf
    • http://library.itekes-bali.ac.id/repository/free-robux-app-2021_GM431946152.pdf
    • http://library.itekes-bali.ac.id/repository/today-coin-master-free-coins-link_GM406889139.pdf
    • http://library.itekes-bali.ac.id/repository/coin-master-free-gold-cards-link_GM406889139.pdf
    • http://library.itekes-bali.ac.id/repository/cute-free-roblox-clothes_GM431946152.pdf
    • http://library.itekes-bali.ac.id/repository/free-group-roblox_GM431946152.pdf
    • http://library.itekes-bali.ac.id/repository/master-coin-hack-mod_GM406889139.pdf
    • http://library.itekes-bali.ac.id/repository/coin-master-free-spins-link-download-ios_GM406889139.pdf
    • http://library.itekes-bali.ac.id/repository/how-to-get-free-pokeballs-in-pokemon-go_GM1094591345.pdf
    • http://library.itekes-bali.ac.id/repository/oprewards-robux_GM431946152.pdf
    • http://library.itekes-bali.ac.id/repository/how-to-get-hacks-on-roblox_GM431946152.pdf
    • http://library.itekes-bali.ac.id/repository/minecraft-18-9-hacked-client_GM479516143.pdf
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00005075.bin
5a55b690fb9b6a8f001fcf98c44a28c9606cc71ad19206d34837f560b27142a1
pdf-font-stream PDF embedded font (sfnt) at offset 0x5075 23692 bytes
font_01_sfnt_off000085f0.bin
ccd38d5c4d6902a87b59ff7236a25d6da26946ef77410ea8fc3c9751fa4e7a37
pdf-font-stream PDF embedded font (sfnt) at offset 0x85F0 18112 bytes