Malicious PDF — malware analysis report

Static analysis result for SHA-256 f9b22c7fd1700e64…

MALICIOUS

PDF

46.2 KB Created: 2021-06-09 13:26:22 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: aaf876d75655b1b93c1bca01e7d6e5d2 SHA-1: a3d9e4a6e41b4b24ba6a8090269f54555c063153 SHA-256: f9b22c7fd1700e6436427220c8a3b8bb8b0d9c2098b36a3338ed9a44abbae6d5
82 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The document contains a lure for free in-game items, which is a common tactic for credential harvesting or malware distribution. The presence of embedded URLs and a high ML classifier score indicate malicious intent. The document's content and heuristics suggest it's designed to trick users into clicking malicious links, potentially leading to credential theft or further payload execution.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9864

Heuristics 4

  • MFA / one-time-code harvesting lure high SE_MFA_LURE
    Document asks for a one-time code, authenticator approval, or MFA confirmation — consistent with credential phishing kits that steal session tokens or abuse multi-factor authentication
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://netcdn.tw/app/431946152/free-roblox-outfits-for-avatar-game-hack
    • https://zbych-pol.pl/wp-content/uploads/fsqm-files/new-this-game-actuslly-gives-free-robux_GM431946152.pdf
    • https://zbych-pol.pl/wp-content/uploads/fsqm-files/how-to-get-free-limiteds-on-roblox-2021_GM431946152.pdf
    • https://zbych-pol.pl/wp-content/uploads/fsqm-files/how-to-hack-robux_GM431946152.pdf
    • https://zbych-pol.pl/wp-content/uploads/fsqm-files/descargar-free-robux-hack_GM431946152.pdf
    • https://zbych-pol.pl/wp-content/uploads/fsqm-files/become-a-hacker-in-roblox_GM431946152.pdf
    • https://zbych-pol.pl/wp-content/uploads/fsqm-files/who-type-of-roblox-hack-is-the-best_GM431946152.pdf
    • https://zbych-pol.pl/wp-content/uploads/fsqm-files/free-robux-easy-human-verification_GM431946152.pdf
    • https://zbych-pol.pl/wp-content/uploads/fsqm-files/minecraft-online-free-no-download_GM479516143.pdf
    • https://zbych-pol.pl/wp-content/uploads/fsqm-files/free-gsg9-roblox-group_GM431946152.pdf
    • https://zbych-pol.pl/wp-content/uploads/fsqm-files/military-sim-hack-roblox-vikinglaw_GM431946152.pdf
    • https://zbych-pol.pl/wp-content/uploads/fsqm-files/10-000-robux-for-free_GM431946152.pdf
    • https://zbych-pol.pl/wp-content/uploads/fsqm-files/roblox-hack-robux-and-tix-cheat-tool-no-survey_GM431946152.pdf
    • https://zbych-pol.pl/wp-content/uploads/fsqm-files/roblox-case-clicker-hack-download_GM431946152.pdf
    • https://zbych-pol.pl/wp-content/uploads/fsqm-files/roblox-vip-server-free-link-vehicle-simulator_GM431946152.pdf
    • https://zbych-pol.pl/wp-content/uploads/fsqm-files/how-to-hack-peoples-accounts-on-roblox-2021_GM431946152.pdf
    • https://zbych-pol.pl/wp-content/uploads/fsqm-files/how-to-hack-lumber-tycoon-2-roblox_GM431946152.pdf
    • https://zbych-pol.pl/wp-content/uploads/fsqm-files/how-to-get-free-quirks-in-boku-no-roblox_GM431946152.pdf
    • https://zbych-pol.pl/wp-content/uploads/fsqm-files/robux-hack-client-download_GM431946152.pdf
    • https://zbych-pol.pl/wp-content/uploads/fsqm-files/hacker-roblox-robux-tuto_GM431946152.pdf
    • https://zbych-pol.pl/wp-content/uploads/fsqm-files/roblox-piece-hack_GM431946152.pdf
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00005564.bin
af54d720241b76afa2a313db2fc96230c1e4abd0e618d20fb48efb46948faea7
pdf-font-stream PDF embedded font (sfnt) at offset 0x5564 25580 bytes
font_01_sfnt_off000090e2.bin
023a777dd65f7ab906a37173522ef34675565bf014f315fc2e9955c74f91b253
pdf-font-stream PDF embedded font (sfnt) at offset 0x90E2 18656 bytes