Malicious PDF — malware analysis report

Static analysis result for SHA-256 b4b11578403a0f68…

MALICIOUS

PDF

45.1 KB Created: 2021-06-03 06:49:57 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: 70e7a7d222c35aaac42a551f7fb13238 SHA-1: 07fc7692a8bd54b771e4d7bef77d63fbe5e3c02e SHA-256: b4b11578403a0f68b7760316dce2147a4b41659666310d562ad54eb2eea5f7d1
82 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1203 Exploitation for Client Execution

The PDF contains multiple embedded URLs and a lure for free views or game currency, consistent with phishing or malware distribution. The ML classifier strongly flagged this PDF as malicious. The presence of MFA lure heuristics suggests an attempt to harvest session tokens or credentials.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9804

Heuristics 4

  • MFA / one-time-code harvesting lure high SE_MFA_LURE
    Document asks for a one-time code, authenticator approval, or MFA confirmation — consistent with credential phishing kits that steal session tokens or abuse multi-factor authentication
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://netcdn.online/app/835599320/free-tiktok-views-no-verification-game-hack
    • http://digilibfisip.unla.ac.id/repository/coin-master-coins_GM406889139.pdf
    • http://digilibfisip.unla.ac.id/repository/free-robux-hacker-us_GM431946152.pdf
    • http://digilibfisip.unla.ac.id/repository/how-to-free-robux_GM431946152.pdf
    • http://digilibfisip.unla.ac.id/repository/how-to-downgrade-minecraft-pe_GM479516143.pdf
    • http://digilibfisip.unla.ac.id/repository/coin-master-free-cards-hack_GM406889139.pdf
    • http://digilibfisip.unla.ac.id/repository/free-robux-no-verification-needed_GM431946152.pdf
    • http://digilibfisip.unla.ac.id/repository/coin-master-hack-2021_GM406889139.pdf
    • http://digilibfisip.unla.ac.id/repository/pig-master-free-spins-and-coins_GM406889139.pdf
    • http://digilibfisip.unla.ac.id/repository/www-cheatsk-com-coin-master-hack_GM406889139.pdf
    • http://digilibfisip.unla.ac.id/repository/coin-master-free-spin-and-coins-links-2021_GM406889139.pdf
    • http://digilibfisip.unla.ac.id/repository/free-robux-just-enter-username-and-password_GM431946152.pdf
    • http://digilibfisip.unla.ac.id/repository/how-to-install-minecraft-for-free-on-ios_GM479516143.pdf
    • http://digilibfisip.unla.ac.id/repository/robux-without-verification_GM431946152.pdf
    • http://digilibfisip.unla.ac.id/repository/free-robux-no-gift-card_GM431946152.pdf
    • http://digilibfisip.unla.ac.id/repository/coin-master-free-spins-blogspot_GM406889139.pdf
    • http://digilibfisip.unla.ac.id/repository/coin-master-free-spins-link-today-new_GM406889139.pdf
    • http://digilibfisip.unla.ac.id/repository/robux-com-free_GM431946152.pdf
    • http://digilibfisip.unla.ac.id/repository/como-hackear-coin-master-2021-espaol_GM406889139.pdf
    • http://digilibfisip.unla.ac.id/repository/robuxmatchcom-free-robux_GM431946152.pdf
    • http://digilibfisip.unla.ac.id/repository/coin-master-free-spins-and-coins-2021_GM406889139.pdf
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_004_off00004e19.bin
65dd2d9e4b22a15c6a8f498f0e0029d8c9f33d4a1f0e5ba225de44b543cda7e2
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x4E19 23616 bytes
font_01_sfnt_off000083d0.bin
a2f32a4bcd6aa6d72cbb5954256c816da8754c34f4c51331b5b082f21791ee8d
pdf-font-stream PDF embedded font (sfnt) at offset 0x83D0 3004 bytes
font_02_sfnt_off00008e37.bin
9795b21d017140d10c0b41d7b2b96a83a6c965cfa279b8aa3b98cbcfef695b0e
pdf-font-stream PDF embedded font (sfnt) at offset 0x8E37 17984 bytes