Malicious PDF — malware analysis report

Static analysis result for SHA-256 cdc939383915b506…

MALICIOUS

PDF

36.0 KB Created: 2021-07-04 02:05:02 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: a5aeb2cc3dad0e189aa6669d67f242b3 SHA-1: 08b6ee156f0c6c3ef9e0e479d1310707a2bee455 SHA-256: cdc939383915b506d9cdfa710b54ff9c8614cb5f4f81deaf3d67c3c07ffa47ba
82 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The document contains numerous embedded URLs and lures users with promises of free in-game items, a common tactic for phishing and malware distribution. The ML classifier strongly flagged this PDF as malicious, and the presence of external URIs suggests an attempt to download further malicious content. The heuristic indicating a password-protected archive lure suggests a multi-stage attack.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9980

Heuristics 4

  • Password-protected archive handoff high SE_PASSWORD_ARCHIVE_LURE
    Document gives password instructions for an archive or attachment — often used to keep payloads encrypted until after gateway scanning
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://netcdn.tw/app/431946152/how-to-get-free-robux-without-human-verification-2021-game-hack
    • http://library.itekes-bali.ac.id/repository/coinmasterhack-club_GM406889139.pdf
    • http://library.itekes-bali.ac.id/repository/roblox-free-wings-2021_GM431946152.pdf
    • http://library.itekes-bali.ac.id/repository/get-free-roblox-clothes-2021_GM431946152.pdf
    • http://library.itekes-bali.ac.id/repository/roblox-hack-account-2021_GM431946152.pdf
    • http://library.itekes-bali.ac.id/repository/pokemon-go-free-promo-code_GM1094591345.pdf
    • http://library.itekes-bali.ac.id/repository/free-roblox-usernames-and-passwords_GM431946152.pdf
    • http://library.itekes-bali.ac.id/repository/how-to-hack-a-minecraft-account_GM479516143.pdf
    • http://library.itekes-bali.ac.id/repository/minecraft-hack-client-18-9_GM479516143.pdf
    • http://library.itekes-bali.ac.id/repository/how-to-hack-roblox-jailbreak_GM431946152.pdf
    • http://library.itekes-bali.ac.id/repository/boost9-com-roblox-hack_GM431946152.pdf
    • http://library.itekes-bali.ac.id/repository/free-robux-site-2021_GM431946152.pdf
    • http://library.itekes-bali.ac.id/repository/crate-new-accownt-for-free-robux-code_GM431946152.pdf
    • http://library.itekes-bali.ac.id/repository/how-to-hack-roblox-accounts-back_GM431946152.pdf
    • http://library.itekes-bali.ac.id/repository/free-robux-hack-2021-april-may_GM431946152.pdf
    • http://library.itekes-bali.ac.id/repository/free-script-executor-roblox-2021_GM431946152.pdf
    • http://library.itekes-bali.ac.id/repository/today-coin-master-free-coins-link_GM406889139.pdf
    • http://library.itekes-bali.ac.id/repository/adidas-roblox-t-shirt-free_GM431946152.pdf
    • http://library.itekes-bali.ac.id/repository/how-to-get-zombie-animation-for-free-roblox_GM431946152.pdf
    • http://library.itekes-bali.ac.id/repository/roblox-hack-apk-mod_GM431946152.pdf
    • http://library.itekes-bali.ac.id/repository/coin-master-free-spins-and-coins-2021_GM406889139.pdf
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000030f7.bin
1877695aae18c8a6cce970e2f3974aed92ab83cdc4b1c8d41174b08856c5b3ad
pdf-font-stream PDF embedded font (sfnt) at offset 0x30F7 22768 bytes
font_01_sfnt_off00006401.bin
26aa4917e1153719256d6dd4d07c71b39b84df2f774e0169f128f53eab8dbbb8
pdf-font-stream PDF embedded font (sfnt) at offset 0x6401 20264 bytes