Malicious PDF — malware analysis report

Static analysis result for SHA-256 b92d98cec6085ad1…

MALICIOUS

PDF

42.6 KB Created: 2021-05-19 23:02:59 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: 63603244afd906910936975f6d0f3524 SHA-1: 528ccd6dc2838f681c05062285356b8c26d107f0 SHA-256: b92d98cec6085ad1e205f136e13ce29797580e7bc55f7b5c5925a236e10c45b4
62 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains multiple embedded URLs and a visual download button, all pointing to sites offering game hacks or free currency. The ML classifier strongly indicates maliciousness, and the presence of external URIs suggests the document is designed to redirect users to download further malicious content. The document body, though heavily obfuscated, contains references to 'Free Robux Gen' and URLs related to game exploits.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9971

Heuristics 4

  • Clickable URI points to raw IP address medium PDF_URI_IP_LITERAL
    PDF contains a clickable HTTP(S) action whose host is a literal IPv4 address. Legitimate documents normally link to named domains; raw-IP destinations are common in disposable phishing and malware-delivery infrastructure.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://netcdn.xyz/app/431946152/free-robux-gen-game-hack
    • http://111.68.26.74/widyapustaka/repository/coin-master-game-hack-link_GM406889139.pdf
    • http://111.68.26.74/widyapustaka/repository/coin-master-unlimited-spin-link_GM406889139.pdf
    • http://111.68.26.74/widyapustaka/repository/get-free-spins-coin-master-2021_GM406889139.pdf
    • http://111.68.26.74/widyapustaka/repository/free-daily-spins-coin-master-2021_GM406889139.pdf
    • http://111.68.26.74/widyapustaka/repository/robux-xyz_GM431946152.pdf
    • http://111.68.26.74/widyapustaka/repository/how-do-i-get-free-coins-on-coin-master_GM406889139.pdf
    • http://111.68.26.74/widyapustaka/repository/roblox-help-free-robux_GM431946152.pdf
    • http://111.68.26.74/widyapustaka/repository/easy-way-to-get-free-robux_GM431946152.pdf
    • http://111.68.26.74/widyapustaka/repository/coin-master-hack-tool-for-pc_GM406889139.pdf
    • http://111.68.26.74/widyapustaka/repository/rbx-earn_GM431946152.pdf
    • http://111.68.26.74/widyapustaka/repository/minecraft-hacked-client-bedrock_GM479516143.pdf
    • http://111.68.26.74/widyapustaka/repository/coin-master-daily-free-spins-link-today-facebook_GM406889139.pdf
    • http://111.68.26.74/widyapustaka/repository/coin-master-unlimited-spins-hack_GM406889139.pdf
    • http://111.68.26.74/widyapustaka/repository/oprewards-points-generator_GM431946152.pdf
    • http://111.68.26.74/widyapustaka/repository/coin-master-free-spin-link-today-2021_GM406889139.pdf
    • http://111.68.26.74/widyapustaka/repository/free-coin-master-coins_GM406889139.pdf
    • http://111.68.26.74/widyapustaka/repository/getrobux-come_GM431946152.pdf
    • http://111.68.26.74/widyapustaka/repository/how-to-get-free-robux-without-verifying-2021_GM431946152.pdf
    • http://111.68.26.74/widyapustaka/repository/free-mods-for-minecraft-pe_GM479516143.pdf
    • http://111.68.26.74/widyapustaka/repository/coin-master-free-spins-through-coin-pop_GM406889139.pdf
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_003_off000049d9.bin
cfac89574449405a9923e2e36d6f063829cd7d73a67d92b2c4b5b650040b21f8
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x49D9 25440 bytes
font_01_sfnt_off00008500.bin
b822dfaf3b200acc051a64c4c7a9b8bc6e1a7e93aa10f3c17b5d396512734dd6
pdf-font-stream PDF embedded font (sfnt) at offset 0x8500 18012 bytes