Malicious PDF — malware analysis report

Static analysis result for SHA-256 d0f0aa2031c00980…

MALICIOUS

PDF

42.8 KB Created: 2021-05-15 01:30:36 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: 8afcec48397c630e7cf1c8d835c1dfb5 SHA-1: 4e78dcfefaa6b480586607b5189681522f527fa1 SHA-256: d0f0aa2031c0098003fc3193a05cb55889465bc94d0903e7d9ebe335993b9af9
82 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious File

The PDF document contains heuristics indicating it is malicious and attempts to lure the user into executing commands. Specifically, it instructs the user to copy and paste content into a command-line interface, likely to download and execute a second-stage payload from the embedded URL. The ML classifier strongly flagged this PDF as malicious.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9971

Heuristics 4

  • Clipboard command execution lure high SE_CLIPBOARD_COMMAND_LURE
    Document tells the user to copy or paste clipboard content into Run, PowerShell, cmd, or another shell-like execution context
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://netcdn.xyz/app/479516143/free-texture-packs-for-minecraft-pe-game-hack
    • https://www.littlerockholidayresort.co.za/images/no-human-verification-hack-for-coin-master_GM406889139.pdf
    • https://www.littlerockholidayresort.co.za/images/robux-codes_GM431946152.pdf
    • https://www.littlerockholidayresort.co.za/images/roblox-free-robux-generator_GM431946152.pdf
    • https://www.littlerockholidayresort.co.za/images/get-minecraft-for-free_GM479516143.pdf
    • https://www.littlerockholidayresort.co.za/images/coins-master_GM406889139.pdf
    • https://www.littlerockholidayresort.co.za/images/get-2021-free-spins-on-coin-master_GM406889139.pdf
    • https://www.littlerockholidayresort.co.za/images/coin-master-spins-free-2021_GM406889139.pdf
    • https://www.littlerockholidayresort.co.za/images/how-to-hack-coin-master-game-without-root_GM406889139.pdf
    • https://www.littlerockholidayresort.co.za/images/free-spins-on-coin-master-generator_GM406889139.pdf
    • https://www.littlerockholidayresort.co.za/images/how-can-i-get-free-robux_GM431946152.pdf
    • https://www.littlerockholidayresort.co.za/images/roblox-lawsuit_GM431946152.pdf
    • https://www.littlerockholidayresort.co.za/images/free-roblox-clothes-2021_GM431946152.pdf
    • https://www.littlerockholidayresort.co.za/images/how-do-i-get-free-coins-on-coin-master_GM406889139.pdf
    • https://www.littlerockholidayresort.co.za/images/where-to-get-free-robux_GM431946152.pdf
    • https://www.littlerockholidayresort.co.za/images/free-robux-no-verification_GM431946152.pdf
    • https://www.littlerockholidayresort.co.za/images/free-spin-coin-master-iphone_GM406889139.pdf
    • https://www.littlerockholidayresort.co.za/images/free-spins-for-coin-master-app_GM406889139.pdf
    • https://www.littlerockholidayresort.co.za/images/how-to-get-free-robux-2021_GM431946152.pdf
    • https://www.littlerockholidayresort.co.za/images/how-to-get-free-gamepasses-on-roblox_GM431946152.pdf
    • https://www.littlerockholidayresort.co.za/images/free-robux-apk_GM431946152.pdf
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_003_off00004d71.bin
476cf2ee3a9ce3e7d0249464531aacf2f6defccb4e0f3aac11518c030264e380
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x4D71 24504 bytes
font_01_sfnt_off000084cb.bin
4bd922cb808520f712e6f68915d55ea385c9bd17e049420b207e71ca6d562f93
pdf-font-stream PDF embedded font (sfnt) at offset 0x84CB 18384 bytes