Malicious PDF — malware analysis report

Static analysis result for SHA-256 d8349d2ad82c6262…

MALICIOUS

PDF

35.0 KB Created: 2021-07-05 15:11:48 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: b4647f512e99189b16dbb54bf654b7e4 SHA-1: bb1b15c317fc34018e7657d64aea932b94edde60 SHA-256: d8349d2ad82c6262e5018848dcff159ee1997229e2fa6ed55c61976b27b78be1
82 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF document contains numerous embedded URLs and invisible links that lead to lures promising free Robux or game hacks. The ML classifier strongly indicated maliciousness, and the presence of CAPTCHA-themed lures suggests a phishing or credential harvesting attempt. No scripts were extracted, but the document's structure and embedded links are designed to trick users into visiting malicious websites.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9980

Heuristics 4

  • Invisible PDF links to CAPTCHA-themed web lure high PDF_CAPTCHA_LINK_LURE
    PDF contains invisible clickable link annotations that point to a CAPTCHA/capcha-themed web path. This is a common phishing and ClickFix-style routing pattern: the PDF itself is inert, while the linked page performs the credential prompt or fake verification.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://netcdn.tw/app/431946152/how-to-get-free-robux-no-verification-2021-game-hack
    • http://perpus.ar-rum.ac.id/repository/free-tix-generator-roblox_GM431946152.pdf
    • http://perpus.ar-rum.ac.id//repository/free-robux-no-human-verification-no-survey_GM431946152.pdf
    • http://perpus.ar-rum.ac.id/repository/cicada-wings-roblox-free_GM431946152.pdf
    • http://perpus.ar-rum.ac.id/repository/roblox-games-free-admin_GM431946152.pdf
    • http://perpus.ar-rum.ac.id/repository/how-to-get-free-clothes-in-the-catalog-on-roblox_GM431946152.pdf
    • http://perpus.ar-rum.ac.id//repository/roblox-hack-site_GM431946152.pdf
    • http://perpus.ar-rum.ac.id/repository/va-a-ser-hackeado-roblox-en-2021_GM431946152.pdf
    • http://perpus.ar-rum.ac.id/repository/free-gift-card-ins-roblox_GM431946152.pdf
    • http://perpus.ar-rum.ac.id/repository/free-robux-no-captcha_GM431946152.pdf
    • http://perpus.ar-rum.ac.id/repository/red-boy-hack-roblox-jailbreak_GM431946152.pdf
    • http://perpus.ar-rum.ac.id/repository/play-jailbreak-for-free-without-installing-roblox-for-free_GM431946152.pdf
    • http://perpus.ar-rum.ac.id/repository/https-wwwrobloxcom-games-202120217-sponsoredfreerobux2021-about_GM431946152.pdf
    • http://perpus.ar-rum.ac.id/repository/roblox-hack-unlimited-health_GM431946152.pdf
    • http://perpus.ar-rum.ac.id/repository/dessert-simulator-hack-roblox_GM431946152.pdf
    • http://perpus.ar-rum.ac.id//repository/roblox-robux-hack_GM431946152.pdf
    • http://perpus.ar-rum.ac.id//repository/how-to-hack-robux_GM431946152.pdf
    • http://perpus.ar-rum.ac.id/repository/hacks-for-tower-battles-roblox_GM431946152.pdf
    • http://perpus.ar-rum.ac.id//repository/free-robux-please_GM431946152.pdf
    • http://perpus.ar-rum.ac.id/repository/april-fools-day-hack-roblox_GM431946152.pdf
    • http://perpus.ar-rum.ac.id/repository/how-to-get-2021-robux-for-free_GM431946152.pdf
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00002faf.bin
6e796a06d645ab82473175191925fd4bb8b3e0ca401560347ae1dfdf074e0d5b
pdf-font-stream PDF embedded font (sfnt) at offset 0x2FAF 22460 bytes
font_01_sfnt_off000061e1.bin
daa201838bdbf48b85e104a71e58172e46eb57685cc2d98453f7e8ceecfd16ef
pdf-font-stream PDF embedded font (sfnt) at offset 0x61E1 19640 bytes