Malicious PDF — malware analysis report

Static analysis result for SHA-256 ce69d460b83a9a59…

MALICIOUS

PDF

37.4 KB Created: 2021-06-30 05:56:44 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: 810bfaa5d275534eabbcefa8ac555eac SHA-1: b706883549de9bf639a5c695dc45c06753c7fe93 SHA-256: ce69d460b83a9a592af744509d56b2551a28b04b62a486f709d808841d835112
62 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The document contains a lure for a "Free Roblox Account Giveaway" and includes an external URI pointing to a suspicious domain. The ML classifier also flagged this PDF as malicious. While no scripts were explicitly extracted, the presence of embedded URLs and the nature of the lure suggest an attempt to redirect users to a malicious site for credential harvesting or malware download.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9980

Heuristics 4

  • Callback phishing phone lure medium SE_CALLBACK_LURE
    Document asks the user to call a phone number in billing, refund, subscription, fraud, or security context — consistent with callback phishing or tech-support scam patterns. Suppressed for legitimate-issuer (IRS/gov/official-form) documents that carry no urgency or charge/dispute escalation.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://netcdn.co/app/431946152/free-roblox-account-giveaway-with-robux-game-hack
    • https://e-learning.manbangkalan.sch.id/__statics/gudangsoal/files/coin-master-daily-free-spins-and-coins_GM406889139.pdf
    • https://e-learning.manbangkalan.sch.id/__statics/gudangsoal/files/haktuts-coin-master-free-daily-spins_GM406889139.pdf
    • https://e-learning.manbangkalan.sch.id/__statics/gudangsoal/files/downtown-rp-roblox-hacks_GM431946152.pdf
    • https://e-learning.manbangkalan.sch.id/__statics/gudangsoal/files/how-to-get-robux-for-free-2021_GM431946152.pdf
    • https://e-learning.manbangkalan.sch.id/__statics/gudangsoal/files/how-to-get-free-robux-easy-no-download_GM431946152.pdf
    • https://e-learning.manbangkalan.sch.id/__statics/gudangsoal/files/how-to-hack-roblox-accounts-on-phone_GM431946152.pdf
    • https://e-learning.manbangkalan.sch.id/__statics/gudangsoal/files/roblox-redeem-robux_GM431946152.pdf
    • https://e-learning.manbangkalan.sch.id/__statics/gudangsoal/files/how-to-hack-roblox-to-get-free-robux_GM431946152.pdf
    • https://e-learning.manbangkalan.sch.id/__statics/gudangsoal/files/how-to-get-more-spins-on-coin-master-for-free_GM406889139.pdf
    • https://e-learning.manbangkalan.sch.id/__statics/gudangsoal/files/moonactive-coin-master-free-spins_GM406889139.pdf
    • https://e-learning.manbangkalan.sch.id/__statics/gudangsoal/files/free-spin-coin-master-2021_GM406889139.pdf
    • https://e-learning.manbangkalan.sch.id/__statics/gudangsoal/files/minecraft-windows-10-edition-free_GM479516143.pdf
    • https://e-learning.manbangkalan.sch.id/__statics/gudangsoal/files/coin-master-hack-https-coinms-net_GM406889139.pdf
    • https://e-learning.manbangkalan.sch.id/__statics/gudangsoal/files/free-robux-on-iphone_GM431946152.pdf
    • https://e-learning.manbangkalan.sch.id/__statics/gudangsoal/files/roblox-admin-hack-best_GM431946152.pdf
    • https://e-learning.manbangkalan.sch.id/__statics/gudangsoal/files/how-to-hack-someones-account-on-roblox_GM431946152.pdf
    • https://e-learning.manbangkalan.sch.id/__statics/gudangsoal/files/how-to-get-free-robux-2021-no-human-verification_GM431946152.pdf
    • https://e-learning.manbangkalan.sch.id/__statics/gudangsoal/files/roblox-free-vip-server_GM431946152.pdf
    • https://e-learning.manbangkalan.sch.id/__statics/gudangsoal/files/roblox-hack-2021-get-free-robux_GM431946152.pdf
    • https://e-learning.manbangkalan.sch.id/__statics/gudangsoal/files/free-robux-codes-no-verification_GM431946152.pdf
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000038bc.bin
858a3c95b709356be1ba90b24a67ec3fd150b59b899c35c6df71981f69bd41ba
pdf-font-stream PDF embedded font (sfnt) at offset 0x38BC 22544 bytes
font_01_sfnt_off00006b19.bin
525b43ad4f098b15a88847879867853eb7b9ac2f99963ca1116264839fcc3de9
pdf-font-stream PDF embedded font (sfnt) at offset 0x6B19 19836 bytes