Malicious PDF — malware analysis report

Static analysis result for SHA-256 d3b673bca1bb1259…

MALICIOUS

PDF

45.5 KB Created: 2021-06-11 08:58:06 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: 12b3d731372adf738998faae3e6b801a SHA-1: 8a151100343504e71bffd9126e9368025a09e63a SHA-256: d3b673bca1bb125968bca993a11c5f533316a5a130d5a86ef27f62def293fffa
82 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1203 Exploitation for Client Execution T1534 Internal Spearphishing

The PDF document contains embedded URLs and heuristics indicating it's a lure for a "free Robux generator" and attempts MFA harvesting. The document body, though heavily obfuscated, contains references to game hacks and URLs pointing to similar content. The ML classifier strongly flagged this PDF as malicious, suggesting it's designed to trick users into clicking malicious links, likely to steal credentials or abuse MFA.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9864

Heuristics 4

  • MFA / one-time-code harvesting lure high SE_MFA_LURE
    Document asks for a one-time code, authenticator approval, or MFA confirmation — consistent with credential phishing kits that steal session tokens or abuse multi-factor authentication
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://netcdn.tw/app/431946152/wahoo-gaming-co-free-robux-generator-game-hack
    • http://opac.akafarma-aceh.ac.id/repository/coin-master-hack-online-no-human-verification_GM406889139.pdf
    • http://opac.akafarma-aceh.ac.id/repository/counter-blox-roblox-offensive-knife-hack_GM431946152.pdf
    • http://opac.akafarma-aceh.ac.id/repository/get-free-gold-cards-in-coin-master_GM406889139.pdf
    • http://opac.akafarma-aceh.ac.id/repository/roblox-hacking-website_GM431946152.pdf
    • http://opac.akafarma-aceh.ac.id/repository/minecraft-bedrock-edition-hacks_GM479516143.pdf
    • http://opac.akafarma-aceh.ac.id/repository/rbx-place-free-robux_GM431946152.pdf
    • http://opac.akafarma-aceh.ac.id/repository/free-400-spins-coin-master_GM406889139.pdf
    • http://opac.akafarma-aceh.ac.id/repository/coin-master-hacks-for-free-spins_GM406889139.pdf
    • http://opac.akafarma-aceh.ac.id/repository/free-robux-no-human-verification-and-no-offers_GM431946152.pdf
    • http://opac.akafarma-aceh.ac.id/repository/websites-that-give-free-robux_GM431946152.pdf
    • http://opac.akafarma-aceh.ac.id/repository/how-to-hack-someones-roblox-account-2021_GM431946152.pdf
    • http://opac.akafarma-aceh.ac.id/repository/rbx-gg-free-robux_GM431946152.pdf
    • http://opac.akafarma-aceh.ac.id/repository/broken-bones-roblox-hack_GM431946152.pdf
    • http://opac.akafarma-aceh.ac.id/repository/free-robux-quiz_GM431946152.pdf
    • http://opac.akafarma-aceh.ac.id/repository/coin-master-free-coins-2021_GM406889139.pdf
    • http://opac.akafarma-aceh.ac.id/repository/free-roblox-generator-for-roblox_GM431946152.pdf
    • http://opac.akafarma-aceh.ac.id/repository/how-to-hack-someones-account-on-roblox_GM431946152.pdf
    • http://opac.akafarma-aceh.ac.id/repository/free-robux-websites-that-actually-work-2021_GM431946152.pdf
    • http://opac.akafarma-aceh.ac.id/repository/5-games-that-give-u-free-robux_GM431946152.pdf
    • http://opac.akafarma-aceh.ac.id/repository/free-spins-coin-master-links-no-human-verification_GM406889139.pdf
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_004_off000051ef.bin
9a2c5695d4c5f4581fafbdf574ab7b4b49bb2c1bcb264cba21a619be67991fcf
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x51EF 26148 bytes
font_01_sfnt_off00008c2b.bin
82db3b3e4ee56f5cfa60b7f235cac9923d42d210a937619d734bf5954c8dbd31
pdf-font-stream PDF embedded font (sfnt) at offset 0x8C2B 19380 bytes