Malicious PDF — malware analysis report

Static analysis result for SHA-256 fc72a56b94acd6ac…

MALICIOUS

PDF

46.7 KB Created: 2021-05-14 22:07:49 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: f2f2d83dd863a39b18d2012cd3768717 SHA-1: 0732076923146677ac79b441017038ba6d5ab3e4 SHA-256: fc72a56b94acd6ac73ada6d6cf26da7c8eeb6525e8a8e2397d65b7eb7055f5dd
82 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The document presents a fake CAPTCHA or human verification prompt to trick the user into clicking a link. The embedded URL, https://netcdn.xyz/app/431946152/free-robux-pin-codes-game-hack, likely leads to a secondary download or exploit. The ML classifier also flagged this PDF as malicious.

Machine Learning

  • Nyx PDF Classifier malicious score 0.8948

Heuristics 4

  • Fake CAPTCHA / human verification prompt high SE_FAKE_CAPTCHA
    Document displays a fake CAPTCHA or human-verification prompt — used to trick users into running commands or pressing keyboard shortcuts
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://netcdn.xyz/app/431946152/free-robux-pin-codes-game-hack
    • https://zarco.co.in/uploaded_files/userfiles/files/free-robux-no-human-verification-or-survey_GM431946152.pdf
    • https://zarco.co.in/uploaded_files/userfiles/files/hack-avatar_GM431946152.pdf
    • https://zarco.co.in/uploaded_files/userfiles/files/how-to-get-robux-without-human-verification_GM431946152.pdf
    • https://zarco.co.in/uploaded_files/userfiles/files/coin-master-heaven-free-spins-today_GM406889139.pdf
    • https://zarco.co.in/uploaded_files/userfiles/files/how-to-hack-coin-master-root_GM406889139.pdf
    • https://zarco.co.in/uploaded_files/userfiles/files/free-robux-generator_GM431946152.pdf
    • https://zarco.co.in/uploaded_files/userfiles/files/free-roblox-shirts-templates_GM431946152.pdf
    • https://zarco.co.in/uploaded_files/userfiles/files/free-robux-without-downloading-apps_GM431946152.pdf
    • https://zarco.co.in/uploaded_files/userfiles/files/minecraft-pe_GM479516143.pdf
    • https://zarco.co.in/uploaded_files/userfiles/files/coin-master-spin-cheat_GM406889139.pdf
    • https://zarco.co.in/uploaded_files/userfiles/files/pro-free-spins-coin-master_GM406889139.pdf
    • https://zarco.co.in/uploaded_files/userfiles/files/free-robux-come_GM431946152.pdf
    • https://zarco.co.in/uploaded_files/userfiles/files/https-rbx-place-rewards_GM431946152.pdf
    • https://zarco.co.in/uploaded_files/userfiles/files/free-robux-redeem-codes-2021_GM431946152.pdf
    • https://zarco.co.in/uploaded_files/userfiles/files/free-spin-coin-master-app-download_GM406889139.pdf
    • https://zarco.co.in/uploaded_files/userfiles/files/free-robux-2021-no-human-verification_GM431946152.pdf
    • https://zarco.co.in/uploaded_files/userfiles/files/free-robux-generator-no-human-verification_GM431946152.pdf
    • https://zarco.co.in/uploaded_files/userfiles/files/free-spins-and-coins-from-coin-master-game_GM406889139.pdf
    • https://zarco.co.in/uploaded_files/userfiles/files/coin-master-free-coins-facebook_GM406889139.pdf
    • https://zarco.co.in/uploaded_files/userfiles/files/i-need-more-free-spins-on-coin-master_GM406889139.pdf
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_003_off00004d28.bin
af5eb30d3cb79d30797bb2c1f9d3bec4a64a2d17408b30ee51db156742997531
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x4D28 26272 bytes
font_01_sfnt_off00008a02.bin
3fb127b764b9d10f5525bc4de5ec8316de704409ccb0cf21cff3ad8a30d11676
pdf-font-stream PDF embedded font (sfnt) at offset 0x8A02 2840 bytes
font_02_sfnt_off000093b4.bin
23872266a6577b01853888d52c04c526ac323517b7f86f8cb64f3b9e81653507
pdf-font-stream PDF embedded font (sfnt) at offset 0x93B4 18464 bytes