Malicious PDF — malware analysis report

Static analysis result for SHA-256 29b976b67084a6bf…

MALICIOUS

PDF

48.9 KB Created: 2021-05-13 02:45:09 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: b6f76e1bb07fe8effdf500d3941d43e0 SHA-1: bdf5cf545afc53d0268a10c601aaa8322c3a9774 SHA-256: 29b976b67084a6bff81529eda4e067e2c1bf8bf0a777e3acd5285d1ac658c009
102 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF document contains numerous links to external websites, many of which are hosted on domains associated with link farms and SEO spam. The document body and extracted URLs suggest a lure for game-related hacks and cheats, which is a common tactic for distributing malware. The presence of a PDF_SEO_LINK_FARM heuristic indicates a high volume of outbound links designed to manipulate search engine results, likely leading to malicious payloads.

Machine Learning

  • Nyx PDF Classifier malicious score 0.8642

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://netcdn.xyz/app/406889139/mcpe-master-hack-coins-game-hack
    • https://www.bathshoponline.co.uk/uploads/files/files/get-gold-coin-master-village-hack_GM406889139.pdf
    • https://www.bathshoponline.co.uk/uploads/files/files/if-you-delete-minecraft-can-you-redownload-it-for-free_GM479516143.pdf
    • https://www.bathshoponline.co.uk/uploads/files/files/free-chest-coin-master_GM406889139.pdf
    • https://www.bathshoponline.co.uk/uploads/files/files/coinmaster-rewards_GM406889139.pdf
    • https://www.bathshoponline.co.uk/uploads/files/files/how-do-i-get-minecraft-for-free_GM479516143.pdf
    • https://www.bathshoponline.co.uk/uploads/files/files/robux-websites-2021_GM431946152.pdf
    • https://www.bathshoponline.co.uk/uploads/files/files/robux-com-free-robux_GM431946152.pdf
    • https://www.bathshoponline.co.uk/uploads/files/files/free-roblox-usernames-and-passwords_GM431946152.pdf
    • https://www.bathshoponline.co.uk/uploads/files/files/free-robux-no-human-verification-or-survey-2021_GM431946152.pdf
    • https://www.bathshoponline.co.uk/uploads/files/files/roblox-report-hacker_GM431946152.pdf
    • https://www.bathshoponline.co.uk/uploads/files/files/get-free-robux-today_GM431946152.pdf
    • https://www.bathshoponline.co.uk/uploads/files/files/coin-master-free-spins-cheat_GM406889139.pdf
    • https://www.bathshoponline.co.uk/uploads/files/files/free-coin-spin-daily-link-for-coin-master-game_GM406889139.pdf
    • https://www.bathshoponline.co.uk/uploads/files/files/coin-master-free-spin-sites_GM406889139.pdf
    • https://www.bathshoponline.co.uk/uploads/files/files/free-spins-coin-master-2021-today_GM406889139.pdf
    • https://www.bathshoponline.co.uk/uploads/files/files/coin-master-hack-without-verification-code_GM406889139.pdf
    • https://www.bathshoponline.co.uk/uploads/files/files/do-you-get-minecraft-windows-10-for-free_GM479516143.pdf
    • https://www.bathshoponline.co.uk/uploads/files/files/free-roblox-accounts-with-robux-that-work-2021_GM431946152.pdf
    • https://www.bathshoponline.co.uk/uploads/files/files/roblox-arsenal-hack-script-pastebin_GM431946152.pdf
    • https://www.bathshoponline.co.uk/uploads/files/files/earn-free-spins-for-coin-master_GM406889139.pdf
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_003_off00004d96.bin
7f6020854a43e06f86ff862859b64aea732b95fd0423ddcfaf049bf34a3b2301
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x4D96 24408 bytes
font_01_sfnt_off000085da.bin
a17c2a746d49ac23b23e38a371e32fddecfcd91b10cf42ff6155bff6b8a07e91
pdf-font-stream PDF embedded font (sfnt) at offset 0x85DA 4028 bytes
font_02_sfnt_off0000937b.bin
6fd7c7f447d66842f81aa8cf197935b17f22157d0c7e9f95622df1b5b4ddf530
pdf-font-stream PDF embedded font (sfnt) at offset 0x937B 2788 bytes
font_03_sfnt_off00009d6b.bin
0c63e033d5ffe887ffec85b5cafaf72e8c864209b86636c790ff2846ce341ff6
pdf-font-stream PDF embedded font (sfnt) at offset 0x9D6B 17892 bytes