Malicious PDF — malware analysis report

Static analysis result for SHA-256 d724fe70f3b8bbc2…

MALICIOUS

PDF

57.2 KB Created: 2021-06-08 23:06:40 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: 4943cecc2c6caa86a4cf9fef88868b4b SHA-1: 451c332bc79d8041dbc3ef4b5d8c2ca158f096e0 SHA-256: d724fe70f3b8bbc2e3baeed691202c962dc59fabb4d0a98e8950d8b867c674ef
62 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF file contains multiple embedded URLs and a high-confidence ML classifier flagging it as malicious. The document body, though heavily obfuscated, suggests a lure related to game hacks ('how-to-speed-hack-with-bitslicer-on-roblox'). The presence of external URIs and an IP literal points to the document's intent to redirect users to external resources, likely for downloading further payloads or engaging in phishing activities.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9717

Heuristics 4

  • Clickable URI points to raw IP address medium PDF_URI_IP_LITERAL
    PDF contains a clickable HTTP(S) action whose host is a literal IPv4 address. Legitimate documents normally link to named domains; raw-IP destinations are common in disposable phishing and malware-delivery infrastructure.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://netcdn.tw/app/431946152/how-to-speed-hack-with-bitslicer-on-roblox-game-hack
    • http://110.232.83.89/slimsppks/repository/how-to-get-free-robux-easy_GM431946152.pdf
    • http://110.232.83.89/slimsppks/repository/coin-master-free-spins-and-coins-daily_GM406889139.pdf
    • http://110.232.83.89/slimsppks/repository/roblox-hack-ga_GM431946152.pdf
    • http://110.232.83.89/slimsppks/repository/how-to-get-free-spins-coin-master_GM406889139.pdf
    • http://110.232.83.89/slimsppks/repository/coin-master-free-spins-links-app_GM406889139.pdf
    • http://110.232.83.89/slimsppks/repository/minecraft-server-hacks_GM479516143.pdf
    • http://110.232.83.89/slimsppks/repository/roblox-gravity-cheat-engine_GM431946152.pdf
    • http://110.232.83.89/slimsppks/repository/free-robux-generator-2021_GM431946152.pdf
    • http://110.232.83.89/slimsppks/repository/appsmobinfo-coinmasterhack-coin-master-hack_GM406889139.pdf
    • http://110.232.83.89/slimsppks/repository/cool-kids-hacks-roblox_GM431946152.pdf
    • http://110.232.83.89/slimsppks/repository/coin-master-hack-xyz-download_GM406889139.pdf
    • http://110.232.83.89/slimsppks/repository/minecraft-alt-accounts-free_GM479516143.pdf
    • http://110.232.83.89/slimsppks/repository/free-printable-roblox-images_GM431946152.pdf
    • http://110.232.83.89/slimsppks/repository/is-minecraft-free-on-pc_GM479516143.pdf
    • http://110.232.83.89/slimsppks/repository/games-that-give-you-free-robux_GM431946152.pdf
    • http://110.232.83.89/slimsppks/repository/free-robux-site_GM431946152.pdf
    • http://110.232.83.89/slimsppks/repository/coin-master-daily-free-spin-app_GM406889139.pdf
    • http://110.232.83.89/slimsppks/repository/free-pet-food-on-coin-master_GM406889139.pdf
    • http://110.232.83.89/slimsppks/repository/coin-master-free-spins-link-today-new_GM406889139.pdf
    • http://110.232.83.89/slimsppks/repository/get-robux-today_GM431946152.pdf
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000056c7.bin
1804b3f3e1d16e448736ec744479085302f4866e3fe6d2c0d95d382406eb6429
pdf-font-stream PDF embedded font (sfnt) at offset 0x56C7 25668 bytes
font_01_sfnt_off000092ac.bin
db399d969d9309c9c38cb6e3c43aa83c06d227a5470715de93176d1df1e6747d
pdf-font-stream PDF embedded font (sfnt) at offset 0x92AC 12800 bytes
font_02_sfnt_off0000ba89.bin
858a4ae876476a7565f208188efae19c36d5739a59f92c2ac6423ad67ded7972
pdf-font-stream PDF embedded font (sfnt) at offset 0xBA89 19284 bytes