Malicious PDF — malware analysis report

Static analysis result for SHA-256 16526a9d80748546…

MALICIOUS

PDF

46.5 KB Created: 2021-05-16 16:19:30 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: 3217640529cdea4f8e6d2dbd642093b3 SHA-1: 03a585fc46eb69e82cc5c179f0295bce133b7123 SHA-256: 16526a9d8074854649e5e885bc09d2462272007c8aee2723d3bb11a7d75e42d2
102 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

This PDF document contains numerous embedded URLs and a specific heuristic firing for a 'secret recovery' lure, indicating a phishing or scam attempt. The document body, though partially corrupted, references game hacks and includes URLs pointing to similar content, suggesting the intent is to trick users into downloading malware or providing sensitive information. The ML classifier also flagged this PDF as malicious.

Machine Learning

  • Nyx PDF Classifier malicious score 0.8948

Heuristics 4

  • Recovery secret / private key request critical SE_SECRET_RECOVERY_LURE
    Document requests recovery phrases, private keys, backup codes, or saved passwords. Requests for these secrets in a document are high-risk.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://netcdn.xyz/app/406889139/coin-master-hack-quora-game-hack
    • http://optiquedelavaunage.com/images/free-2021-robux_GM431946152.pdf
    • http://optiquedelavaunage.com/images/minecraft-free-demo_GM479516143.pdf
    • http://optiquedelavaunage.com/images/roblox-online-free-no-download_GM431946152.pdf
    • http://optiquedelavaunage.com/images/how-to-get-free-robux-2021_GM431946152.pdf
    • http://optiquedelavaunage.com/images/all-minecraft-handbooks_GM479516143.pdf
    • http://optiquedelavaunage.com/images/rbx-com_GM431946152.pdf
    • http://optiquedelavaunage.com/images/free-hacks-for-coin-master_GM406889139.pdf
    • http://optiquedelavaunage.com/images/coin-master-free-spins-link_GM406889139.pdf
    • http://optiquedelavaunage.com/images/free-coin-master-spins-2021_GM406889139.pdf
    • http://optiquedelavaunage.com/images/how-to-get-free-robux-easy_GM431946152.pdf
    • http://optiquedelavaunage.com/images/coin-master-hack-download-2021_GM406889139.pdf
    • http://optiquedelavaunage.com/images/universal-minecraft-converter-free_GM479516143.pdf
    • http://optiquedelavaunage.com/images/plug-toolbox-for-minecraft-free-ios_GM479516143.pdf
    • http://optiquedelavaunage.com/images/free-spins-on-coin-master-iphone_GM406889139.pdf
    • http://optiquedelavaunage.com/images/coin-master-hack-pro-gamers_GM406889139.pdf
    • http://optiquedelavaunage.com/images/minecraft-gun-games-free_GM479516143.pdf
    • http://optiquedelavaunage.com/images/best-free-spins-link-coin-master_GM406889139.pdf
    • http://optiquedelavaunage.com/images/coin-master-hack-iosgods_GM406889139.pdf
    • http://optiquedelavaunage.com/images/free-spins-for-coin-master-game_GM406889139.pdf
    • http://optiquedelavaunage.com/images/minecraft-hacks-list_GM479516143.pdf
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_003_off00004aa7.bin
6e26dd6714f8bb4da385ecd252868386f92ac6fed92461d1854843d5903160cb
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x4AA7 27268 bytes
font_01_sfnt_off000089b9.bin
601c50867a41b9362538ff18e5f9479a0f9badf698aaf1eb7e88469c11719db7
pdf-font-stream PDF embedded font (sfnt) at offset 0x89B9 2920 bytes
font_02_sfnt_off000093d2.bin
cc1a19628674345e3b696abd9756b0bb2f88cc670761cbb92aefe1a407817aed
pdf-font-stream PDF embedded font (sfnt) at offset 0x93D2 18016 bytes