Malicious PDF — malware analysis report

Static analysis result for SHA-256 ea148130f8663109…

MALICIOUS

PDF

43.8 KB Created: 2021-05-31 07:41:49 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: 34a29e959aa206f4faae7d84ef2567f6 SHA-1: f903a936c64d39d5d25c53e469eced140462ab59 SHA-256: ea148130f8663109b75807c5b9aec3ec9f29a6db16fda8190ff8906ff9e41a42
62 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF document contains embedded URLs and text that mimic download links for game mods and hacks, aiming to trick users into downloading malicious content. The ML classifier strongly flagged this PDF as malicious, and the presence of multiple suspicious URLs reinforces this assessment. No scripts were extracted, but the document's structure and content suggest it's a lure for further malicious downloads.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9683

Heuristics 4

  • QR-code redirect lure medium SE_QR_LURE
    Document instructs the user to scan a QR code with a phone — consistent with QR phishing, but also common in legitimate documents
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://netcdn.xyz/app/479516143/minecraft-mods-download-free-game-hack
    • https://caotangmen.org/wp-content/uploads/sites/17/fsqm-files/roblox-hack-2021_GM431946152.pdf
    • https://caotangmen.org/wp-content/uploads/sites/17/fsqm-files/free-robux-codes-no-verification_GM431946152.pdf
    • https://caotangmen.org/wp-content/uploads/sites/17/fsqm-files/minecraft-java-edition-free_GM479516143.pdf
    • https://caotangmen.org/wp-content/uploads/sites/17/fsqm-files/free-robux-no-survey_GM431946152.pdf
    • https://caotangmen.org/wp-content/uploads/sites/17/fsqm-files/free-minecraft-skins_GM479516143.pdf
    • https://caotangmen.org/wp-content/uploads/sites/17/fsqm-files/free-robux-games_GM431946152.pdf
    • https://caotangmen.org/wp-content/uploads/sites/17/fsqm-files/how-to-hack-someones-account-on-roblox_GM431946152.pdf
    • https://caotangmen.org/wp-content/uploads/sites/17/fsqm-files/minecraft-skins-free-girl_GM479516143.pdf
    • https://caotangmen.org/wp-content/uploads/sites/17/fsqm-files/free-robux-hack-generator_GM431946152.pdf
    • https://caotangmen.org/wp-content/uploads/sites/17/fsqm-files/minecraft-story-mode-free_GM479516143.pdf
    • https://caotangmen.org/wp-content/uploads/sites/17/fsqm-files/how-to-get-free-tiktok-fans_GM835599320.pdf
    • https://caotangmen.org/wp-content/uploads/sites/17/fsqm-files/how-to-get-free-robux-2021-no-human-verification_GM431946152.pdf
    • https://caotangmen.org/wp-content/uploads/sites/17/fsqm-files/games-that-give-you-free-robux_GM431946152.pdf
    • https://caotangmen.org/wp-content/uploads/sites/17/fsqm-files/how-to-hack-into-someones-roblox-account_GM431946152.pdf
    • https://caotangmen.org/wp-content/uploads/sites/17/fsqm-files/free-minecraft-accounts-reddit_GM479516143.pdf
    • https://caotangmen.org/wp-content/uploads/sites/17/fsqm-files/rblx-gg-free-robux_GM431946152.pdf
    • https://caotangmen.org/wp-content/uploads/sites/17/fsqm-files/free-roblox-accounts-with-robux-2021_GM431946152.pdf
    • https://caotangmen.org/wp-content/uploads/sites/17/fsqm-files/roblox-studio-free-robux_GM431946152.pdf
    • https://caotangmen.org/wp-content/uploads/sites/17/fsqm-files/roblox-free-robux-generator_GM431946152.pdf
    • https://caotangmen.org/wp-content/uploads/sites/17/fsqm-files/tiktok-follower-bot-free_GM835599320.pdf
    • https://caotangmen.org/wp-content/uploads/sites/17/fsqm-files/how-to-get-minecraft-for-free-on-pc_GM479516143.pdf
    • https://caotangmen.org/wp-content/uploads/sites/17/fsqm-files/coin-master-free-spins-and-coins-daily_GM406889139.pdf
    • https://caotangmen.org/wp-content/uploads/sites/17/fsqm-files/roblox-fun-com-free-robux_GM431946152.pdf
    • https://sigmaclient.info#2
    • https://flux.today#3
    • https://www.yout
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000050c7.bin
3bd1059eed630e82809ca487d8ff2e299228a86a1d6726e0d8a47257140ccc98
pdf-font-stream PDF embedded font (sfnt) at offset 0x50C7 25024 bytes
font_01_sfnt_off000088e0.bin
cdbcc94192cea0c1a32d76b4e8648406db092070658ebd9590606dd52a123660
pdf-font-stream PDF embedded font (sfnt) at offset 0x88E0 18292 bytes