Malicious PDF — malware analysis report

Static analysis result for SHA-256 e70ab3f546aa4616…

MALICIOUS

PDF

47.9 KB Created: 2021-06-09 07:01:02 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: 31e52ce95f18043205960043b6645f14 SHA-1: 6d872a5792307a35a9a01415d1f6f18db5001cc3 SHA-256: e70ab3f546aa46164a0aca7c3ee877ce72399f0732ff2bb217b6a903d99bf3ae
82 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1203 Exploitation for Client Execution

The document uses social engineering lures related to game hacks and free items to trick the user into downloading a payload. The presence of external URIs and the ML classifier firing indicate malicious intent. While no scripts were directly extracted, the PDF structure and embedded links suggest it is designed to facilitate the download and execution of a second-stage malicious file.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9796

Heuristics 4

  • Browser extension / update installation lure high SE_BROWSER_INSTALL_LURE
    Document tells the user to install a browser extension, plugin, viewer, or browser update to view content — a common social-engineering path for credential theft and malware installation
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://netcdn.tw/app/431946152/roblox-hacks-download-pc-game-hack
    • https://sf.nationalbreedingcenter.bz/ckfinder/userfiles/files/free-robux-no-verification-2021-ios_GM431946152.pdf
    • https://sf.nationalbreedingcenter.bz/ckfinder/userfiles/files/how-to-get-free-roblox-gift-card-codes_GM431946152.pdf
    • https://sf.nationalbreedingcenter.bz/ckfinder/userfiles/files/hacked-roblox-game_GM431946152.pdf
    • https://sf.nationalbreedingcenter.bz/ckfinder/userfiles/files/real-coin-master-hack-2021_GM406889139.pdf
    • https://sf.nationalbreedingcenter.bz/ckfinder/userfiles/files/roblox-hacked-version_GM431946152.pdf
    • https://sf.nationalbreedingcenter.bz/ckfinder/userfiles/files/minecraft-java-edition-free-code_GM479516143.pdf
    • https://sf.nationalbreedingcenter.bz/ckfinder/userfiles/files/free-robux-no-verification-needed_GM431946152.pdf
    • https://sf.nationalbreedingcenter.bz/ckfinder/userfiles/files/minecraft-java-edition-code-free_GM479516143.pdf
    • https://sf.nationalbreedingcenter.bz/ckfinder/userfiles/files/free-robux-for-kids_GM431946152.pdf
    • https://sf.nationalbreedingcenter.bz/ckfinder/userfiles/files/free-robux-websites-2021_GM431946152.pdf
    • https://sf.nationalbreedingcenter.bz/ckfinder/userfiles/files/free-spins-coin-master-apple_GM406889139.pdf
    • https://sf.nationalbreedingcenter.bz/ckfinder/userfiles/files/cute-free-roblox-outfits_GM431946152.pdf
    • https://sf.nationalbreedingcenter.bz/ckfinder/userfiles/files/buy-robux-free_GM431946152.pdf
    • https://sf.nationalbreedingcenter.bz/ckfinder/userfiles/files/play-roblox-for-free-on-google_GM431946152.pdf
    • https://sf.nationalbreedingcenter.bz/ckfinder/userfiles/files/how-to-get-free-robux-codes-2021_GM431946152.pdf
    • https://sf.nationalbreedingcenter.bz/ckfinder/userfiles/files/free-minecraft-pe-server_GM479516143.pdf
    • https://sf.nationalbreedingcenter.bz/ckfinder/userfiles/files/how-to-get-free-roblox-premium_GM431946152.pdf
    • https://sf.nationalbreedingcenter.bz/ckfinder/userfiles/files/how-to-get-100-robux-for-free_GM431946152.pdf
    • https://sf.nationalbreedingcenter.bz/ckfinder/userfiles/files/coin-master-free-daily-spins-link_GM406889139.pdf
    • https://sf.nationalbreedingcenter.bz/ckfinder/userfiles/files/robux-hack-2021_GM431946152.pdf
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_004_off00005022.bin
7f0e84964fdda99fcdf2ee0fba6c21a5e0ca8bf49d9d4e9cb1df563b8df4113b
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x5022 25820 bytes
font_01_sfnt_off00008cb5.bin
e28d2c57f35643e2026f86c34ac3bb63cba74be3f6c066e81aba6d285e5a121b
pdf-font-stream PDF embedded font (sfnt) at offset 0x8CB5 2908 bytes
font_02_sfnt_off000096af.bin
ec86cadc578403506901ed0e46ac546d40f70cc5280d066945b7675295d5272a
pdf-font-stream PDF embedded font (sfnt) at offset 0x96AF 18844 bytes