Malicious PDF — malware analysis report

Static analysis result for SHA-256 bace660a9c97945d…

MALICIOUS

PDF

47.5 KB Created: 2021-06-07 18:35:39 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: 1b9464ab0ffebd6e09118b6ba20a7058 SHA-1: bf175ff9b48df8cf0c58aea1ca51f9e8fe72934b SHA-256: bace660a9c97945d20b94906a17316df2383db40f125d2450ac13273414ba557
82 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The document contains lures for advance-fee scams, specifically related to game currency and hacks, directing users to external URLs. The ML classifier also flagged this PDF as malicious. The primary goal appears to be tricking users into visiting malicious websites, likely for phishing or to download further malware.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9832

Heuristics 4

  • Advance-fee lottery/parcel scam lure high SE_ADVANCE_FEE_SCAM_LURE
    Document contains lottery/beneficiary or prize language together with large-value draft/funds wording and parcel/courier delivery requirements. This is a classic advance-fee fraud document shape.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://netcdn.tw/app/431946152/how-to-hack-roblox-murder-mystery-2-game-hack
    • https://tv-transvision.com/ckfinder/userfiles/files/roblox-free-accessories_GM431946152.pdf
    • https://tv-transvision.com/ckfinder/userfiles/files/free-robux-on-phone_GM431946152.pdf
    • https://tv-transvision.com/ckfinder/userfiles/files/free-tiktok-followers-generator_GM835599320.pdf
    • https://tv-transvision.com/ckfinder/userfiles/files/how-to-play-minecraft-online-for-free_GM479516143.pdf
    • https://tv-transvision.com/ckfinder/userfiles/files/free-robux-generator-2021_GM431946152.pdf
    • https://tv-transvision.com/ckfinder/userfiles/files/free-spins-on-coin-master-2021_GM406889139.pdf
    • https://tv-transvision.com/ckfinder/userfiles/files/free-robux-generator-no-human-verification_GM431946152.pdf
    • https://tv-transvision.com/ckfinder/userfiles/files/free-robux-no-survey-or-human-verification_GM431946152.pdf
    • https://tv-transvision.com/ckfinder/userfiles/files/claim-free-spins-coin-master_GM406889139.pdf
    • https://tv-transvision.com/ckfinder/userfiles/files/master-coin-hack_GM406889139.pdf
    • https://tv-transvision.com/ckfinder/userfiles/files/minecraft-bedrock-free_GM479516143.pdf
    • https://tv-transvision.com/ckfinder/userfiles/files/free-tiktok-likes-without-verification_GM835599320.pdf
    • https://tv-transvision.com/ckfinder/userfiles/files/wahoo-gaming-co-free-robux_GM431946152.pdf
    • https://tv-transvision.com/ckfinder/userfiles/files/free-custom-minecraft-skins_GM479516143.pdf
    • https://tv-transvision.com/ckfinder/userfiles/files/free-minecraft-java-account_GM479516143.pdf
    • https://tv-transvision.com/ckfinder/userfiles/files/free-robux-no-human-verification-and-no-survey_GM431946152.pdf
    • https://tv-transvision.com/ckfinder/userfiles/files/best-coin-master-hack_GM406889139.pdf
    • https://tv-transvision.com/ckfinder/userfiles/files/roblox-re_GM431946152.pdf
    • https://tv-transvision.com/ckfinder/userfiles/files/xray-hack_GM479516143.pdf
    • https://tv-transvision.com/ckfinder/userfiles/files/today-coin-master-spin-free_GM406889139.pdf
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_004_off00005435.bin
3f7bc3c5bdd4459f79e1199dcf032f7471dbf6865dcf45c8ef271c3e92230155
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x5435 28436 bytes
font_01_sfnt_off00009442.bin
992ea8369a0f92ceda76d1bb1f48ab61b4bb674ab606b3a1cc3f5b844bf56b26
pdf-font-stream PDF embedded font (sfnt) at offset 0x9442 19264 bytes