Malicious PDF — malware analysis report

Static analysis result for SHA-256 df6bc550f14beff0…

MALICIOUS

PDF

46.9 KB Created: 2021-06-04 00:49:14 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: 33743d0f1c80f49c8f25f4afee489de7 SHA-1: becbd735692f5e30e2b2e5c554ab99c4642413f5 SHA-256: df6bc550f14beff0f62819e8cf86a2fb0ed57df74fccfdb0a9a9aa2887473081
102 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1203 Exploitation for Client Execution

The PDF document contains multiple embedded URLs and a fake CAPTCHA lure, indicating an attempt to trick users into downloading further malicious content. The ML classifier strongly flagged this PDF as malicious. The presence of external URIs and the fake CAPTCHA heuristic suggest a social engineering attack aimed at users seeking game-related cheats or currency.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9769

Heuristics 5

  • Fake CAPTCHA / human verification prompt high SE_FAKE_CAPTCHA
    Document displays a fake CAPTCHA or human-verification prompt — used to trick users into running commands or pressing keyboard shortcuts
  • Clickable URI points to raw IP address medium PDF_URI_IP_LITERAL
    PDF contains a clickable HTTP(S) action whose host is a literal IPv4 address. Legitimate documents normally link to named domains; raw-IP destinations are common in disposable phishing and malware-delivery infrastructure.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://netcdn.online/app/431946152/robux-free-online-game-hack
    • http://183.91.70.7/repository/windows-10-minecraft-free-with-java_GM479516143.pdf
    • http://183.91.70.7/repository/free-minecraft-accounts-reddit_GM479516143.pdf
    • http://183.91.70.7/repository/roblox-promo-codes-for-free-robux_GM431946152.pdf
    • http://183.91.70.7/repository/free-roblox-exploits_GM431946152.pdf
    • http://183.91.70.7//repository/links-to-get-free-spins-on-coin-master_GM406889139.pdf
    • http://183.91.70.7//repository/the-coin-master-hack_GM406889139.pdf
    • http://183.91.70.7//repository/free-robux-only-username_GM431946152.pdf
    • http://183.91.70.7//repository/minecraft-realms-free_GM479516143.pdf
    • http://183.91.70.7//repository/coin-master-free-spins-link-facebook-page_GM406889139.pdf
    • http://183.91.70.7/repository/games-to-get-free-robux_GM431946152.pdf
    • http://183.91.70.7//repository/free-spins-for-coin-master-2021_GM406889139.pdf
    • http://183.91.70.7//repository/coin-master-free-coins-amp_GM406889139.pdf
    • http://183.91.70.7/repository/coin-master-free-spins-link-2021-no-verification_GM406889139.pdf
    • http://183.91.70.7/repository/coin-master-70-spin-link-2021_GM406889139.pdf
    • http://183.91.70.7/repository/www-bandicam-com-free-robux_GM431946152.pdf
    • http://183.91.70.7/repository/roblox-com-free-play_GM431946152.pdf
    • http://183.91.70.7/repository/minecraft-wurst-hacked-client_GM479516143.pdf
    • http://183.91.70.7/repository/coin-master-free-stars_GM406889139.pdf
    • http://183.91.70.7//repository/minecraft-hacks-18-9_GM479516143.pdf
    • http://183.91.70.7//repository/coin-master-hack-tool_GM406889139.pdf
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_004_off00004c97.bin
d5588379256826595dd5cb96ecfcac96fc1357b7505524e91d12d291c85d0f57
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x4C97 26536 bytes
font_01_sfnt_off000089b7.bin
ddeceb2862f27911f7e16c0b38463f1d8a5744b909bfd39267679665e968d94f
pdf-font-stream PDF embedded font (sfnt) at offset 0x89B7 3188 bytes
font_02_sfnt_off000094bd.bin
9c6e6aa5efa9903ee4d2fc70532f13b8880c04837d913a4df075592e4b137fb6
pdf-font-stream PDF embedded font (sfnt) at offset 0x94BD 18208 bytes