Malicious PDF — malware analysis report

Static analysis result for SHA-256 018fc74fae07672f…

MALICIOUS

PDF

43.3 KB Created: 2021-06-04 01:25:00 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: 0fccc65f0754e85b965d13db74c261bd SHA-1: 9bc7b6da47d588b9910eeb85e63e0a3d01c9b5f6 SHA-256: 018fc74fae07672fad55d3947421d2704c5f6f9f5bf37f578793e70df7867cc9
102 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The document contains multiple embedded URLs pointing to sites offering game hacks and cheats, and a critical heuristic identified a lure for recovery secrets or private keys. The ML classifier also flagged the PDF as malicious with high confidence. These elements suggest the document is designed to trick users into downloading potentially harmful files or divulging sensitive information.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9865

Heuristics 4

  • Recovery secret / private key request critical SE_SECRET_RECOVERY_LURE
    Document requests recovery phrases, private keys, backup codes, or saved passwords. Requests for these secrets in a document are high-risk.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://netcdn.online/app/406889139/hacks-master-coin-game-hack
    • https://library.sman1berau.sch.id/repository/coin-master-hack-without-root_GM406889139.pdf
    • https://library.sman1berau.sch.id/repository/facebook-coin-master-free-spins_GM406889139.pdf
    • https://library.sman1berau.sch.id/repository/how-to-earn-robux_GM431946152.pdf
    • https://library.sman1berau.sch.id/repository/free-robux-script_GM431946152.pdf
    • https://library.sman1berau.sch.id/repository/minecraft-hacked-client-download_GM479516143.pdf
    • https://library.sman1berau.sch.id/repository/free-robux-no-apps_GM431946152.pdf
    • https://library.sman1berau.sch.id/repository/coin-master-15-free-spin-link-today_GM406889139.pdf
    • https://library.sman1berau.sch.id/repository/free-coin-master-spins-2021_GM406889139.pdf
    • https://library.sman1berau.sch.id/repository/minecraft-apk-android-free_GM479516143.pdf
    • https://library.sman1berau.sch.id/repository/hack-a-game_GM431946152.pdf
    • https://library.sman1berau.sch.id/repository/microsoft-rewards-roblox_GM431946152.pdf
    • https://library.sman1berau.sch.id/repository/real-coin-master-hack-2021_GM406889139.pdf
    • https://library.sman1berau.sch.id/repository/300-free-spins-coin-master_GM406889139.pdf
    • https://library.sman1berau.sch.id/repository/how-to-win-robux_GM431946152.pdf
    • https://library.sman1berau.sch.id/repository/minecraft-building-hacks_GM479516143.pdf
    • https://library.sman1berau.sch.id/repository/free-spins-and-coins-coin-master-2021-link_GM406889139.pdf
    • https://library.sman1berau.sch.id/repository/coin-master-heaven-free-spins_GM406889139.pdf
    • https://library.sman1berau.sch.id/repository/coin-master-free-spin-realme-products_GM406889139.pdf
    • https://library.sman1berau.sch.id/repository/free-robux-microsoft_GM431946152.pdf
    • https://library.sman1berau.sch.id/repository/free-coins-and-spins-coin-master-2021_GM406889139.pdf
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_004_off00005167.bin
a51c2df9bb7c7c7d5a97c2867901fa954cfd909f4c41793f174131c95a7c275f
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x5167 24200 bytes
font_01_sfnt_off00008842.bin
aea1ef4c1cd469d79511e585102869a057304cba4fed84ae86aa90ce3b018750
pdf-font-stream PDF embedded font (sfnt) at offset 0x8842 17716 bytes