Malicious PDF — malware analysis report

Static analysis result for SHA-256 278dcaadc937a74c…

MALICIOUS

PDF

49.3 KB Created: 2021-05-17 11:10:51 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: 6052286862f2bb34f0984d46d2f4a9a3 SHA-1: 73128f866c14d71654277b2ac5fa33cfe3553117 SHA-256: 278dcaadc937a74c330b86670ff9875b0582ebf55139a86341d3520b5192a3f4
82 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The document presents itself as a guide for hacking games, specifically mentioning 'Coin Master', and includes a fake CAPTCHA or human verification prompt to trick users. It contains numerous embedded URLs, many of which point to other PDF files hosted on suspicious domains, likely serving as download lures for malicious content. The ML classifier also flagged this PDF as malicious.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9228

Heuristics 4

  • Fake CAPTCHA / human verification prompt high SE_FAKE_CAPTCHA
    Document displays a fake CAPTCHA or human-verification prompt — used to trick users into running commands or pressing keyboard shortcuts
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://netcdn.xyz/app/406889139/como-hackear-coin-master-2021-game-hack
    • http://christiansymbolkits.com/images/minecraft-apk-free-download_GM479516143.pdf
    • http://christiansymbolkits.com/images/how-do-you-get-free-roblox_GM431946152.pdf
    • http://christiansymbolkits.com/images/how-to-hack-robux_GM431946152.pdf
    • http://christiansymbolkits.com/images/coin-master-free-spins-link-today-new-2021_GM406889139.pdf
    • http://christiansymbolkits.com/images/hackear-coin-master_GM406889139.pdf
    • http://christiansymbolkits.com/images/free-minecraft-java-code_GM479516143.pdf
    • http://christiansymbolkits.com/images/coin-master-free-spins-for-today_GM406889139.pdf
    • http://christiansymbolkits.com/images/coin-master-links-to-get-free-spins_GM406889139.pdf
    • http://christiansymbolkits.com/images/download-hack-coin-master_GM406889139.pdf
    • http://christiansymbolkits.com/images/coin-master-daily-free-spins-link-2021-today_GM406889139.pdf
    • http://christiansymbolkits.com/images/minecraft-free-apk-download-016-0_GM479516143.pdf
    • http://christiansymbolkits.com/images/how-to-play-minecraft-with-friends-for-free_GM479516143.pdf
    • http://christiansymbolkits.com/images/minecraft-xbox-one-free_GM479516143.pdf
    • http://christiansymbolkits.com/images/robux-win_GM431946152.pdf
    • http://christiansymbolkits.com/images/coin-master-download_GM406889139.pdf
    • http://christiansymbolkits.com/images/coin-master-hack-spins-and-coins-unlimited-free-download_GM406889139.pdf
    • http://christiansymbolkits.com/images/roblox-hack-download-pc_GM431946152.pdf
    • http://christiansymbolkits.com/images/how-to-get-free-robux-generator_GM431946152.pdf
    • http://christiansymbolkits.com/images/coin-master-hacks-2021_GM406889139.pdf
    • http://christiansymbolkits.com/images/best-way-to-get-free-robux_GM431946152.pdf
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_003_off00004c10.bin
6ea51f19e8f99faf3ecb510d0fdcb3026ac580750b152677d13a0b2fe4fdec69
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x4C10 26864 bytes
font_01_sfnt_off00008999.bin
e06aca5f85e50ae6cefda302c5299c18ab6d27c174f74f0bb0ee8efa7ccb4468
pdf-font-stream PDF embedded font (sfnt) at offset 0x8999 8676 bytes
font_02_sfnt_off00009e24.bin
7d079b1918a151c222a156c250c5aa0e1b0afb08b6f17fdb7ccf3df79397c72b
pdf-font-stream PDF embedded font (sfnt) at offset 0x9E24 18380 bytes