Malicious PDF — malware analysis report

Static analysis result for SHA-256 b81c7ef197a0aaf0…

MALICIOUS

PDF

34.5 KB Created: 2021-07-05 01:42:51 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: d832675b1ca8a3e271f44a8f6dad4413 SHA-1: a23131e43e1516b9cb11e80dda0c98b2416b32f1 SHA-256: b81c7ef197a0aaf0347677a2671471af5c036c4cde760fc6d5613dfef627b263
82 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 User Execution: Malicious File

The document displays a fake CAPTCHA lure to entice users into clicking a link, likely to download malicious content related to game hacks. The embedded URL and numerous other URLs found within the document body point to sites offering cheats and hacks for games like Minecraft and Roblox. The ML classifier also strongly indicated maliciousness.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9980

Heuristics 4

  • Fake CAPTCHA / human verification prompt high SE_FAKE_CAPTCHA
    Document displays a fake CAPTCHA or human-verification prompt — used to trick users into running commands or pressing keyboard shortcuts
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://netcdn.tw/app/479516143/best-free-minecraft-server-hosting-reddit-game-hack
    • https://katalog.smkn1glagah.sch.id/repository/roblox-gui-hack_GM431946152.pdf
    • https://katalog.smkn1glagah.sch.id/repository/coin-master-free-spins-fb_GM406889139.pdf
    • https://katalog.smkn1glagah.sch.id//repository/coin-master-spin-hack-no-verification_GM406889139.pdf
    • https://katalog.smkn1glagah.sch.id/repository/roblox-sit-fly-hack_GM431946152.pdf
    • https://katalog.smkn1glagah.sch.id//repository/coin-master-free-spins-link-2021-twitter_GM406889139.pdf
    • https://katalog.smkn1glagah.sch.id/repository/roblox-hack-jailbreak-2021_GM431946152.pdf
    • https://katalog.smkn1glagah.sch.id//repository/free-minecraft-coins_GM479516143.pdf
    • https://katalog.smkn1glagah.sch.id/repository/coin-master-spins-hack-2021_GM406889139.pdf
    • https://katalog.smkn1glagah.sch.id/repository/coin-master-hack-app-2021_GM406889139.pdf
    • https://katalog.smkn1glagah.sch.id//repository/moonactive-coin-master-free-spins_GM406889139.pdf
    • https://katalog.smkn1glagah.sch.id/repository/roblox-free-like-bots_GM431946152.pdf
    • https://katalog.smkn1glagah.sch.id/repository/free-roblox-hair-codes_GM431946152.pdf
    • https://katalog.smkn1glagah.sch.id/repository/free-roblox-outfits_GM431946152.pdf
    • https://katalog.smkn1glagah.sch.id//repository/how-to-get-free-pet-snacks-in-coin-master_GM406889139.pdf
    • https://katalog.smkn1glagah.sch.id/repository/coin-master-blogspot_GM406889139.pdf
    • https://katalog.smkn1glagah.sch.id/repository/roblox-afk-saber-simulator-hack_GM431946152.pdf
    • https://katalog.smkn1glagah.sch.id/repository/free-robux-hack-no-download-2021_GM431946152.pdf
    • https://katalog.smkn1glagah.sch.id/repository/how-to-use-process-hacker-for-roblox-for-robux_GM431946152.pdf
    • https://katalog.smkn1glagah.sch.id/repository/roblox-hack-menu-download-2021_GM431946152.pdf
    • https://katalog.smkn1glagah.sch.id/repository/filter-peint-existe-hack-roblox_GM431946152.pdf
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000030a9.bin
0a7b5026f0a93127b1c14751f3936470ab8f7f8294c8eaf0402911d864d3e07a
pdf-font-stream PDF embedded font (sfnt) at offset 0x30A9 22900 bytes
font_01_sfnt_off00006380.bin
d871dcb748a79589dfb9206c8c26b1b31a59c6b5fd6e64801d8efc9cfdffb698
pdf-font-stream PDF embedded font (sfnt) at offset 0x6380 18504 bytes