Malicious PDF — malware analysis report

Static analysis result for SHA-256 dab7b261ca1fd98a…

MALICIOUS

PDF

33.5 KB Created: 2021-07-05 03:20:55 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: 73d4c824036caf52355763ce79529f63 SHA-1: b549a43873eba29a7867d37bdb65166ffe623036 SHA-256: dab7b261ca1fd98aab334afb531696b410af6dd58873d8ddffc57f10f7e2e4b5
82 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF document contains numerous embedded URLs and a prominent external URI pointing to sites offering hacks for popular games like Coin Master and Roblox. The ML classifier strongly indicated maliciousness, and the presence of these lures suggests the document is designed to trick users into downloading malware or visiting malicious sites. No scripts were extracted, but the document's structure and embedded links are indicative of a phishing or social engineering attack.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9980

Heuristics 4

  • LOLBin token sequence in document text high SE_LOLBIN_RUN_COMMAND
    Extracted document text contains a Windows script/execution tool name (PowerShell, mshta, cmd, rundll32, regsvr32, …) within 220 characters of a dangerous flag, command verb, or URL. This is a visible 'run this' instruction in HTML/PDF/RTF lure bodies, or — in macro-laden Office files — the macro's own string-pool entries appearing adjacent in extracted text.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://netcdn.tw/app/406889139/free-spins-for-coin-master-hack-game-hack
    • https://fib.ub.ac.id/sac/repository/roblox-free-robux_GM431946152.pdf
    • https://fib.ub.ac.id/sac//repository/how-to-get-free-stuff-on-roblox_GM431946152.pdf
    • https://fib.ub.ac.id/sac/repository/free-backpack-roblox_GM431946152.pdf
    • https://fib.ub.ac.id/sac/repository/how-to-get-free-robux-onroblox-and-pastebin_GM431946152.pdf
    • https://fib.ub.ac.id/sac//repository/coin-master-hack-apk-2021-ios_GM406889139.pdf
    • https://fib.ub.ac.id/sac/repository/free-fmswat-camp-roblox_GM431946152.pdf
    • https://fib.ub.ac.id/sac//repository/android-coin-master-3433-apk-hack_GM406889139.pdf
    • https://fib.ub.ac.id/sac/repository/invisibility-hack-roblox-jaulbreak_GM431946152.pdf
    • https://fib.ub.ac.id/sac/repository/roblox-escape-room-cheats_GM431946152.pdf
    • https://fib.ub.ac.id/sac//repository/free-robux-quiz_GM431946152.pdf
    • https://fib.ub.ac.id/sac/repository/inappropriate-roblox_GM431946152.pdf
    • https://fib.ub.ac.id/sac/repository/hwo-to-hack-someones-account-roblox_GM431946152.pdf
    • https://fib.ub.ac.id/sac/repository/hack-to-get-free-spins-on-coin-master_GM406889139.pdf
    • https://fib.ub.ac.id/sac//repository/coin-master-35-16-hack-apk_GM406889139.pdf
    • https://fib.ub.ac.id/sac/repository/moonactive-coin-master-hack_GM406889139.pdf
    • https://fib.ub.ac.id/sac/repository/free-robux-1-000-000_GM431946152.pdf
    • https://fib.ub.ac.id/sac/repository/get-hacked-roblox-account-back_GM431946152.pdf
    • https://fib.ub.ac.id/sac//repository/coin-master-free-2021-spin-link_GM406889139.pdf
    • https://fib.ub.ac.id/sac/repository/free-roblox-cmds_GM431946152.pdf
    • https://fib.ub.ac.id/sac/repository/roblox-cheats-for-robux-2021_GM431946152.pdf
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00002eb3.bin
c99dde4adc61e67180a420521b02b342ba39b806038e8a6cd69bf08c84d75403
pdf-font-stream PDF embedded font (sfnt) at offset 0x2EB3 22284 bytes
font_01_sfnt_off00006037.bin
1b9c2ef9418efdd4f31bdac1407ea9f2d903a284f26a3d935c42a711d8cabc04
pdf-font-stream PDF embedded font (sfnt) at offset 0x6037 18344 bytes