Malicious PDF — malware analysis report

Static analysis result for SHA-256 f1cbc9642d4955ad…

MALICIOUS

PDF

42.5 KB Created: 2021-05-18 04:15:36 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: d798e4382692b2bb39794c19cc4116ad SHA-1: 6bdc1eee1ca1bbd3bae684229048e144beca58fd SHA-256: f1cbc9642d4955ad9a6ca02a7dbd88d2ce43ad4e4a1d93dfc09c3a63a0e677c1
62 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF document contains lures for free game items and virtual currency, directing users to external URLs. The presence of an embedded URI and multiple external links suggests an attempt to redirect users to malicious sites for downloading further payloads or engaging in phishing. The ML classifier strongly flagged this PDF as malicious, supporting the assessment of a malicious download lure.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9971

Heuristics 4

  • Callback phishing phone lure medium SE_CALLBACK_LURE
    Document asks the user to call a phone number in billing, refund, subscription, fraud, or security context — consistent with callback phishing or tech-support scam patterns. Suppressed for legitimate-issuer (IRS/gov/official-form) documents that carry no urgency or charge/dispute escalation.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://netcdn.xyz/app/431946152/free-promo-codes-for-robux-game-hack
    • https://bancroftandsons.com/images/free-roblox-accounts-dantdm_GM431946152.pdf
    • https://bancroftandsons.com/images/how-to-get-minecraft-for-free-on-iphone_GM479516143.pdf
    • https://bancroftandsons.com/images/how-to-get-free-robux-without-download-apps-or-survey_GM431946152.pdf
    • https://bancroftandsons.com/images/minecraft-games-free-download_GM479516143.pdf
    • https://bancroftandsons.com/images/como-sacar-buen-puntaje-en-juego-coin-master-free-spins_GM406889139.pdf
    • https://bancroftandsons.com/images/free-spins-and-coins-coin-master-2021_GM406889139.pdf
    • https://bancroftandsons.com/images/coin-master-hack-generator-tool_GM406889139.pdf
    • https://bancroftandsons.com/images/buy-robux-free_GM431946152.pdf
    • https://bancroftandsons.com/images/coin-master-hack-2021_GM406889139.pdf
    • https://bancroftandsons.com/images/coin-master-free-spins-link-download-hack_GM406889139.pdf
    • https://bancroftandsons.com/images/how-to-get-free-gamepasses-on-roblox_GM431946152.pdf
    • https://bancroftandsons.com/images/coin-master-daily-free-spins-link-today-blog_GM406889139.pdf
    • https://bancroftandsons.com/images/minecraft-free-reddit_GM479516143.pdf
    • https://bancroftandsons.com/images/rbl-gg-free-robux_GM431946152.pdf
    • https://bancroftandsons.com/images/coin-master-gold-cards-hack_GM406889139.pdf
    • https://bancroftandsons.com/images/coin-master-free-spin-codes_GM406889139.pdf
    • https://bancroftandsons.com/images/coin-master-hack-without-human-verification-2021_GM406889139.pdf
    • https://bancroftandsons.com/images/javascript-free-robux_GM431946152.pdf
    • https://bancroftandsons.com/images/hack-robux_GM431946152.pdf
    • https://bancroftandsons.com/images/roblox-hack-codes_GM431946152.pdf
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000048f8.bin
80f2834eb22f5f2b87434346b99001560eafb7cd07cfe7a7da4e85bc060ab758
pdf-font-stream PDF embedded font (sfnt) at offset 0x48F8 25540 bytes
font_01_sfnt_off000082eb.bin
f71c03fba91376071fb946d88a6d16afcc2c6d61aa4ef632c3571b6200829f5d
pdf-font-stream PDF embedded font (sfnt) at offset 0x82EB 18604 bytes