Malicious PDF — malware analysis report

Static analysis result for SHA-256 d72906e0e228b77e…

MALICIOUS

PDF

34.3 KB Created: 2021-07-05 08:49:49 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: 8e8ba6e813e7d0fae26cde053e6e5e36 SHA-1: ccab282482c8acc7ec300d182feebebb12d1e21d SHA-256: d72906e0e228b77e1400ca3a1ccc38889e93c1e4136acb4679affa93f5f41d81
62 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

This PDF document contains numerous embedded URLs and a document body advertising hacks and generators for popular games, aiming to trick users into downloading malicious files. The ML classifier strongly indicated maliciousness, and the presence of external URIs, including one pointing to a raw IP address, further supports this. No scripts were extracted from this sample, but the overall pattern suggests a lure for downloading potentially unwanted or malicious software.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9980

Heuristics 4

  • Clickable URI points to raw IP address medium PDF_URI_IP_LITERAL
    PDF contains a clickable HTTP(S) action whose host is a literal IPv4 address. Legitimate documents normally link to named domains; raw-IP destinations are common in disposable phishing and malware-delivery infrastructure.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://netcdn.tw/app/431946152/freerobuxhack-us-2021-game-hack
    • http://103.30.145.97/__statics/gudangsoal/files/coin-master-mod_GM406889139.pdf
    • http://103.30.145.97/__statics/gudangsoal/files/roblox-avatar-com_GM431946152.pdf
    • http://103.30.145.97/__statics/gudangsoal/files/real-robux-generator-2021_GM431946152.pdf
    • http://103.30.145.97/__statics/gudangsoal/files/discord-server-roblox-hacking-community_GM431946152.pdf
    • http://103.30.145.97/__statics/gudangsoal/files/coin-blogspot_GM406889139.pdf
    • http://103.30.145.97/__statics/gudangsoal/files/cheat-roblox-power-simulator_GM431946152.pdf
    • http://103.30.145.97/__statics/gudangsoal/files/coin-master-how-to-get-japan-sushi-card-free_GM406889139.pdf
    • http://103.30.145.97/__statics/gudangsoal/files/roblox-fairy-tail-revelations-hack_GM431946152.pdf
    • http://103.30.145.97/__statics/gudangsoal/files/how-do-you-hack-a-roblox-server-on-mac_GM431946152.pdf
    • http://103.30.145.97/__statics/gudangsoal/files/coin-master-hack-no-survey-2021_GM406889139.pdf
    • http://103.30.145.97/__statics/gudangsoal/files/how-do-you-hack-minecraft_GM479516143.pdf
    • http://103.30.145.97/__statics/gudangsoal/files/free-coin-master-spin-app_GM406889139.pdf
    • http://103.30.145.97/__statics/gudangsoal/files/youtube-how-to-get-free-robux_GM431946152.pdf
    • http://103.30.145.97/__statics/gudangsoal/files/free-spins-coin-master-blogspot_GM406889139.pdf
    • http://103.30.145.97/__statics/gudangsoal/files/coin-master-free-spins-and-coins_GM406889139.pdf
    • http://103.30.145.97/__statics/gudangsoal/files/minecraft-free-minecoins_GM479516143.pdf
    • http://103.30.145.97/__statics/gudangsoal/files/ways-to-make-free-robux_GM431946152.pdf
    • http://103.30.145.97/__statics/gudangsoal/files/free-followers-for-tiktok_GM835599320.pdf
    • http://103.30.145.97/__statics/gudangsoal/files/how-to-get-java-minecraft-free_GM479516143.pdf
    • http://103.30.145.97/__statics/gudangsoal/files/aesthetic-free-t-shirt-roblox_GM431946152.pdf
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00002ea9.bin
4d66d40cbcbe42e4d9cf480e6363ce06760ac5555585c6cb00a04ecebbe7ed7e
pdf-font-stream PDF embedded font (sfnt) at offset 0x2EA9 22260 bytes
font_01_sfnt_off00005ff6.bin
43b81a284332bbcce6e172d110dbc1a63e46633337d5d3ab3430c81f8a1ab5e6
pdf-font-stream PDF embedded font (sfnt) at offset 0x5FF6 19452 bytes