Malicious PDF — malware analysis report

Static analysis result for SHA-256 2920083bbfe0c90c…

MALICIOUS

PDF

35.8 KB Created: 2021-05-14 18:30:18 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: ddb041302b53b1cc70a0bd5531e7f582 SHA-1: a12e74b4ff718b0c8604ac86d7a06b125028c977 SHA-256: 2920083bbfe0c90c699b2b7098927c99502b74e14de80b9774a05be129a95f80
72 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a lure for a "Coin Master Free Cards Hack" and explicitly requests recovery secrets or private keys, indicating a phishing or scam attempt. The embedded URL points to a suspicious domain that likely hosts the malicious content. Although no scripts were directly extracted, the PDF structure and heuristics suggest an attempt to exploit user interest in game cheats to steal sensitive information.

Machine Learning

  • Nyx PDF Classifier clean score 0.0265

Heuristics 4

  • Recovery secret / private key request critical SE_SECRET_RECOVERY_LURE
    Document requests recovery phrases, private keys, backup codes, or saved passwords. Requests for these secrets in a document are high-risk.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://netcdn.xyz/app/406889139/coin-master-free-cards-hack-game-hack
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_003_off00003476.bin
5952b66e25736e2f53cae80287db2a191a7cf02d1ee36fa22138b5868c9c49c2
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x3476 24128 bytes
font_01_sfnt_off00006b42.bin
ad4f2d10031887feff52537d65cf9a04719575ebe7be64232d8e0b4f73fdfdc1
pdf-font-stream PDF embedded font (sfnt) at offset 0x6B42 18056 bytes