Malicious PDF — malware analysis report

Static analysis result for SHA-256 fd3ae768884e5567…

MALICIOUS

PDF

42.3 KB Created: 2021-05-12 20:15:39 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: 266880039ce52047ba134875570e3b0b SHA-1: 75e703dee2bd0ca77dc053abd2ec59478ec8c12e SHA-256: fd3ae768884e5567c325cfd3c6e0d065baa340be07d5d3ed100d9e9a7f16ddbd
82 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The document uses a lure related to Minecraft server hosting, but the embedded URLs and document body content point towards unrelated game hacks and potentially malicious downloads. The presence of a remote support lure heuristic suggests an attempt to trick the user into installing potentially unwanted software or granting remote access. No scripts were extracted, but the document's structure and embedded URLs indicate a phishing or malware distribution attempt.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9971

Heuristics 4

  • Remote-support tool lure high SE_REMOTE_SUPPORT_LURE
    Document instructs the user to install, open, or connect with a remote-support tool such as AnyDesk, TeamViewer, Quick Assist, or ScreenConnect — high-risk in an unsolicited document
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://netcdn.xyz/app/479516143/minecraft-java-server-hosting-free-game-hack
    • https://repository.poltekkesgorontalo.ac.id/repository/boku-no-roblox-hack_GM431946152.pdf
    • https://repository.poltekkesgorontalo.ac.id/repository/roblox-free-robux-generator_GM431946152.pdf
    • https://repository.poltekkesgorontalo.ac.id/repository/robux-in_GM431946152.pdf
    • https://repository.poltekkesgorontalo.ac.id/repository/free-coins-and-free-spins-coin-master-2021_GM406889139.pdf
    • https://repository.poltekkesgorontalo.ac.id/repository/coin-master-free-spins-only_GM406889139.pdf
    • https://repository.poltekkesgorontalo.ac.id/repository/free-robux-picture_GM431946152.pdf
    • https://repository.poltekkesgorontalo.ac.id/repository/coin-master-15-free-spin-link-of-last-5-days_GM406889139.pdf
    • https://repository.poltekkesgorontalo.ac.id/repository/how-to-get-free-robux-easy_GM431946152.pdf
    • https://repository.poltekkesgorontalo.ac.id/repository/roblox-help-free-robux_GM431946152.pdf
    • https://repository.poltekkesgorontalo.ac.id/repository/free-minecraft-hacks_GM479516143.pdf
    • https://repository.poltekkesgorontalo.ac.id/repository/websites-to-get-free-robux_GM431946152.pdf
    • https://repository.poltekkesgorontalo.ac.id/repository/free-robux-no-verification-or-survey_GM431946152.pdf
    • https://repository.poltekkesgorontalo.ac.id/repository/how-to-get-free-spins-on-coin-master-game_GM406889139.pdf
    • https://repository.poltekkesgorontalo.ac.id/repository/roblox-hack-tool_GM431946152.pdf
    • https://repository.poltekkesgorontalo.ac.id/repository/how-to-hack-coin-master-computer_GM406889139.pdf
    • https://repository.poltekkesgorontalo.ac.id/repository/getrobux-ninja_GM431946152.pdf
    • https://repository.poltekkesgorontalo.ac.id/repository/coin-master-hack-download-android_GM406889139.pdf
    • https://repository.poltekkesgorontalo.ac.id/repository/coin-master-redeem-code-free_GM406889139.pdf
    • https://repository.poltekkesgorontalo.ac.id/repository/coin-master-hack-apk-free-download_GM406889139.pdf
    • https://repository.poltekkesgorontalo.ac.id/repository/coin-master-free-daily-spins-2021_GM406889139.pdf
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_003_off00004b6d.bin
60b776941aecaa0e8256197fdd0a7138b671e0d63568537b093c678550bb09a8
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x4B6D 24812 bytes
font_01_sfnt_off0000830b.bin
5e44962821fb2565cfe95a9f549b7a0fbd0587c00345fc69eb3db563df392af4
pdf-font-stream PDF embedded font (sfnt) at offset 0x830B 18276 bytes