Malicious PDF — malware analysis report

Static analysis result for SHA-256 0667e80edb79a1fa…

MALICIOUS

PDF

43.8 KB Created: 2021-05-15 14:07:40 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: 92cf88bf114300bfdc7a13fd30c6a20e SHA-1: 658898109b685f6a89a2e9480c7358a6b3cb4fa7 SHA-256: 0667e80edb79a1fab684d8948b73ccba00d3aef90c94643ce00b8fde7e60bd36
102 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains numerous external links, many of which appear to be part of an SEO link farm designed to drive traffic to specific content. One embedded URL, 'https://netcdn.xyz/app/406889139/coin-spin-game-hack', suggests a potential download or redirection to malicious content. The ML classifier also flagged this PDF with high confidence, indicating malicious intent.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9969

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://netcdn.xyz/app/406889139/coin-spin-game-hack
    • http://www.bzconstructionservices.com/images/roblox-army-robux_GM431946152.pdf
    • http://www.bzconstructionservices.com/images/coin-master-free-spin-and-coins-fbid-links_GM406889139.pdf
    • http://www.bzconstructionservices.com/images/coin-master-links-free-spins_GM406889139.pdf
    • http://www.bzconstructionservices.com/images/www-roblox-robux_GM431946152.pdf
    • http://www.bzconstructionservices.com/images/is-minecraft-vr-free_GM479516143.pdf
    • http://www.bzconstructionservices.com/images/how-to-get-minecraft-windows-10-for-free_GM479516143.pdf
    • http://www.bzconstructionservices.com/images/free-coin-master-spins-without-human-verification_GM406889139.pdf
    • http://www.bzconstructionservices.com/images/coin-master-hacks-for-free-spins_GM406889139.pdf
    • http://www.bzconstructionservices.com/images/how-to-get-free-robux-without-surveys_GM431946152.pdf
    • http://www.bzconstructionservices.com/images/coin-master-free-spins-and-coins-today-gift-reward_GM406889139.pdf
    • http://www.bzconstructionservices.com/images/play-games-for-robux_GM431946152.pdf
    • http://www.bzconstructionservices.com/images/coin-master-daily-spin-free_GM406889139.pdf
    • http://www.bzconstructionservices.com/images/coin-master-spin-cheat_GM406889139.pdf
    • http://www.bzconstructionservices.com/images/roblox-robux_GM431946152.pdf
    • http://www.bzconstructionservices.com/images/how-to-get-free-robux-on-ipad_GM431946152.pdf
    • http://www.bzconstructionservices.com/images/how-to-get-free-robux-2021_GM431946152.pdf
    • http://www.bzconstructionservices.com/images/free-spin-in-coin-master_GM406889139.pdf
    • http://www.bzconstructionservices.com/images/free-robux-no-gift-card_GM431946152.pdf
    • http://www.bzconstructionservices.com/images/coin-master-free-spins-link-blogspot-april-2021_GM406889139.pdf
    • http://www.bzconstructionservices.com/images/coin-master-facebook-hack_GM406889139.pdf
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_003_off00004874.bin
e83d18a2c5b2014502de035a252f3c8457623c10679e096f4a79b010cb076d75
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x4874 30720 bytes
font_01_sfnt_off00008ba4.bin
26961c9f14d61c789be320ef33f793128d7856b3f2b2e22dee8a483f9b6c2997
pdf-font-stream PDF embedded font (sfnt) at offset 0x8BA4 17392 bytes