Malicious PDF — malware analysis report

Static analysis result for SHA-256 b20b4857c75a5202…

MALICIOUS

PDF

35.3 KB Created: 2021-07-05 05:45:53 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: 596077bdc1d50ac5113bb10992076af5 SHA-1: dc2f21d1a3db69c31abe65d35bc5a8589ab1fd9c SHA-256: b20b4857c75a52024a3a995439c3dc7ab2823ed994662507173bbb2569cf3942
62 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF document contains multiple embedded URLs and a prominent link within its body text, all directing users to download applications related to game hacks and cheats. The ML classifier strongly flagged this PDF as malicious, and the presence of download lures reinforces the intent to trick users into downloading potentially harmful software. No scripts were extracted, but the overall pattern suggests a phishing or social engineering attack aimed at distributing malware.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9980

Heuristics 4

  • Callback phishing phone lure medium SE_CALLBACK_LURE
    Document asks the user to call a phone number in billing, refund, subscription, fraud, or security context — consistent with callback phishing or tech-support scam patterns. Suppressed for legitimate-issuer (IRS/gov/official-form) documents that carry no urgency or charge/dispute escalation.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://netcdn.tw/app/406889139/coin-master-hack-apk-april-12-2021-game-hack
    • http://lib.icbc-indonesia.org/repository/como-hackear-roblox-robu-gratis_GM431946152.pdf
    • http://lib.icbc-indonesia.org/repository/free-clothing-on-roblox_GM431946152.pdf
    • http://lib.icbc-indonesia.org/repository/a-hack-to-get-the-bage-admin-on-roblox_GM431946152.pdf
    • http://lib.icbc-indonesia.org/repository/how-to-hack-roblox-accounts-with-cheat-engine-2021_GM431946152.pdf
    • http://lib.icbc-indonesia.org/repository/tiktok-free-view-iphone-keychain_GM835599320.pdf
    • http://lib.icbc-indonesia.org/repository/free-robux-no-survey-2021_GM431946152.pdf
    • http://lib.icbc-indonesia.org//repository/coin-master-mod-version-free-download-ios_GM406889139.pdf
    • http://lib.icbc-indonesia.org/repository/roblox-marketplace-sell-free-shirts_GM431946152.pdf
    • http://lib.icbc-indonesia.org/repository/get-roblox-app-for-free_GM431946152.pdf
    • http://lib.icbc-indonesia.org/repository/hunting-simulator-hack-roblox_GM431946152.pdf
    • http://lib.icbc-indonesia.org/repository/all-no-clip-hacks-for-roblox_GM431946152.pdf
    • http://lib.icbc-indonesia.org/repository/free-roblox-cards-july-2021_GM431946152.pdf
    • http://lib.icbc-indonesia.org/repository/free-spin-hack-coin-master-2021_GM406889139.pdf
    • http://lib.icbc-indonesia.org/repository/win-free-robux_GM431946152.pdf
    • http://lib.icbc-indonesia.org/repository/hack-coin-master-without-root_GM406889139.pdf
    • http://lib.icbc-indonesia.org/repository/tuto-cheat-we-are-devs-roblox_GM431946152.pdf
    • http://lib.icbc-indonesia.org/repository/roblox-card-includes-free-virtual-item_GM431946152.pdf
    • http://lib.icbc-indonesia.org/repository/anyway-to-get-robux-for-free_GM431946152.pdf
    • http://lib.icbc-indonesia.org/repository/coin-master-free-daily-spins_GM406889139.pdf
    • http://lib.icbc-indonesia.org/repository/coinmasterhack-club_GM406889139.pdf
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_002_off00003351.bin
3302a624dcb95ab9a7134752c9f09e8fb2761d1dfd32044cdb6aa2c3529e29e0
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x3351 22860 bytes
font_01_sfnt_off00006629.bin
ce7730a0d587cee2fb52d8d5c08edd61688c30ef220bfad8760e49edbd2f2858
pdf-font-stream PDF embedded font (sfnt) at offset 0x6629 18656 bytes