Malicious PDF — malware analysis report

Static analysis result for SHA-256 da777dbdc323041c…

MALICIOUS

PDF

45.2 KB Created: 2021-06-09 04:50:31 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: c3fe724e777ce07c99d3c51099c02b93 SHA-1: 96b2869357e07db21204aa5fa7d6e06926f448d5 SHA-256: da777dbdc323041c954321b390f9b6ac2c36e6e02d59a91dec7caed47366b920
82 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF document contains numerous links to external websites that promise game cheats and hacks, indicating a social engineering lure. The ML classifier and heuristic firings strongly suggest malicious intent, likely to trick users into downloading malware or visiting compromised sites. The document body itself contains obfuscated text and URLs related to these lures.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9865

Heuristics 4

  • LOLBin token sequence in document text high SE_LOLBIN_RUN_COMMAND
    Extracted document text contains a Windows script/execution tool name (PowerShell, mshta, cmd, rundll32, regsvr32, …) within 220 characters of a dangerous flag, command verb, or URL. This is a visible 'run this' instruction in HTML/PDF/RTF lure bodies, or — in macro-laden Office files — the macro's own string-pool entries appearing adjacent in extracted text.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://netcdn.tw/app/431946152/how-to-hack-all-roblox-games-pc-game-hack
    • http://perpus.poltekeskupang.ac.id/repository/rbl-gg-free-robux_GM431946152.pdf
    • http://perpus.poltekeskupang.ac.id//repository/coin-master-hack-reddit_GM406889139.pdf
    • http://perpus.poltekeskupang.ac.id//repository/coin-master-free-cards-link_GM406889139.pdf
    • http://perpus.poltekeskupang.ac.id/repository/how-to-get-free-minecoins-in-minecraft_GM479516143.pdf
    • http://perpus.poltekeskupang.ac.id//repository/free-spins-coin-master-ios-links_GM406889139.pdf
    • http://perpus.poltekeskupang.ac.id//repository/coin-master-free-card-link-today_GM406889139.pdf
    • http://perpus.poltekeskupang.ac.id/repository/minecraft-pocket-edition-free_GM479516143.pdf
    • http://perpus.poltekeskupang.ac.id//repository/free-spins-for-coin-master-ios_GM406889139.pdf
    • http://perpus.poltekeskupang.ac.id//repository/coin-master-no-download-app-but-play-for-free_GM406889139.pdf
    • http://perpus.poltekeskupang.ac.id//repository/freerobuxhack-us_GM431946152.pdf
    • http://perpus.poltekeskupang.ac.id//repository/play-coin-master_GM406889139.pdf
    • http://perpus.poltekeskupang.ac.id/repository/20-free-spins-coin-master_GM406889139.pdf
    • http://perpus.poltekeskupang.ac.id/repository/tiktok-free-followers-without-human-verification_GM835599320.pdf
    • http://perpus.poltekeskupang.ac.id/repository/free-robux-hack-generator_GM431946152.pdf
    • http://perpus.poltekeskupang.ac.id/repository/coin-master-free-spins-twitter_GM406889139.pdf
    • http://perpus.poltekeskupang.ac.id//repository/coin-master-free-spins-link-quora_GM406889139.pdf
    • http://perpus.poltekeskupang.ac.id//repository/how-to-get-free-clothes-on-roblox-2021_GM431946152.pdf
    • http://perpus.poltekeskupang.ac.id/repository/free-cmds-in-roblox_GM431946152.pdf
    • http://perpus.poltekeskupang.ac.id/repository/coin-master-spin-pattern_GM406889139.pdf
    • http://perpus.poltekeskupang.ac.id/repository/how-to-get-free-hair-in-roblox_GM431946152.pdf
    • http://perpus.poltekeskupang
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_004_off000051ba.bin
e9ea798435363b4e7f3b580ddde77b24ecdb6e2107b9a0678507efe105e6280c
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x51BA 25632 bytes
font_01_sfnt_off00008c8e.bin
42f714811f79ee93bf5a0b66c5ca038b7fe1692c942611c9fc7ef820ce58b1a0
pdf-font-stream PDF embedded font (sfnt) at offset 0x8C8E 18760 bytes