Malicious PDF — malware analysis report

Static analysis result for SHA-256 d421a322da86bb70…

MALICIOUS

PDF

35.0 KB Created: 2021-07-05 15:10:24 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: ebe273a37e20e889df1a2f01fa2c0ff8 SHA-1: 6a19fd427531d59ec6cdd43a8b97fa9f1d5b879e SHA-256: d421a322da86bb708e5f4281f39fed0aec5fd6f7f1ffb66a626c8d5cee84ee94
122 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1203 Exploitation for Client Execution

The document presents a fake CAPTCHA and a lure for free Robux, directing users to a malicious URL. The ML classifier strongly flagged this PDF as malicious, and the presence of external URIs indicates an attempt to download further content. The document body, though heavily obfuscated, contains references to 'free Robux' and URLs associated with such scams.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9980

Heuristics 5

  • Fake CAPTCHA / human verification prompt high SE_FAKE_CAPTCHA
    Document displays a fake CAPTCHA or human-verification prompt — used to trick users into running commands or pressing keyboard shortcuts
  • Password-protected archive handoff high SE_PASSWORD_ARCHIVE_LURE
    Document gives password instructions for an archive or attachment — often used to keep payloads encrypted until after gateway scanning
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://netcdn.tw/app/431946152/free-robux-no-password-game-hack
    • http://library.itekes-bali.ac.id/repository/roblox-cheat-gg_GM431946152.pdf
    • http://library.itekes-bali.ac.id/repository/free-robux-hack_GM431946152.pdf
    • http://library.itekes-bali.ac.id/repository/free-hair-on-roblox-girl_GM431946152.pdf
    • http://library.itekes-bali.ac.id/repository/roblox-offers-earn-free-robux_GM431946152.pdf
    • http://library.itekes-bali.ac.id/repository/hack-de-roblox_GM431946152.pdf
    • http://library.itekes-bali.ac.id/repository/robloxcom-free-kkk_GM431946152.pdf
    • http://library.itekes-bali.ac.id/repository/how-to-get-free-robux-on-pc_GM431946152.pdf
    • http://library.itekes-bali.ac.id/repository/roblox-free-codes-that-make-things-free_GM431946152.pdf
    • http://library.itekes-bali.ac.id/repository/latest-free-spin-coin-master-daily_GM406889139.pdf
    • http://library.itekes-bali.ac.id/repository/4chan-roblox-hack_GM431946152.pdf
    • http://library.itekes-bali.ac.id/repository/how-to-hack-someones-account-on-roblox-2021_GM431946152.pdf
    • http://library.itekes-bali.ac.id/repository/how-to-get-free-robux-2021_GM431946152.pdf
    • http://library.itekes-bali.ac.id/repository/wwwroblox-hack-get-free-robux_GM431946152.pdf
    • http://library.itekes-bali.ac.id/repository/free-aimbot-for-roblox_GM431946152.pdf
    • http://library.itekes-bali.ac.id/repository/coin-master-hack-app-ios_GM406889139.pdf
    • http://library.itekes-bali.ac.id/repository/how-to-hack-roblox-robux-no-survey_GM431946152.pdf
    • http://library.itekes-bali.ac.id/repository/free-robux-games-that-actually-work-june-2021_GM431946152.pdf
    • http://library.itekes-bali.ac.id/repository/robux-free-com_GM431946152.pdf
    • http://library.itekes-bali.ac.id/repository/minecraft-java-free-download_GM479516143.pdf
    • http://library.itekes-bali.ac.id/repository/how-to-buy-robux-free-on-roblox_GM431946152.pdf
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000031c1.bin
8c7bd8ae183259a94ca807fdba866a8871531399c41e97319fac6bb040aee81a
pdf-font-stream PDF embedded font (sfnt) at offset 0x31C1 22232 bytes
font_01_sfnt_off00006365.bin
6b3d0efb3debf488fe81ea92b60c01ccbae5249fd0a29fdced25ee5be01c6081
pdf-font-stream PDF embedded font (sfnt) at offset 0x6365 19208 bytes