Malicious PDF — malware analysis report

Static analysis result for SHA-256 2bfcee277977fd36…

MALICIOUS

PDF

43.2 KB Created: 2021-05-15 17:35:58 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7) First seen: 2021-09-16
MD5: d0ca23c7586dc5b40e6731db58179d3d SHA-1: 94a4613d088e88cde0eafa604860d868122ba901 SHA-256: 2bfcee277977fd368064531d7c0b1d75d7a825b1c956c91dae7a142ebcfd033a
82 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell T1059.003 Windows Command Shell

The document presents itself as a free game hack, likely to trick users into downloading a malicious payload from the embedded URL. The heuristic 'SE_CLIPBOARD_COMMAND_LURE' indicates the document instructs users to copy and paste content into a shell, suggesting an attempt to execute commands or scripts. The ML classifier strongly flagged this PDF as malicious.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9969

Heuristics 4

  • Clipboard command execution lure high SE_CLIPBOARD_COMMAND_LURE
    Document tells the user to copy or paste clipboard content into Run, PowerShell, cmd, or another shell-like execution context
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://netcdn.xyz/app/479516143/minecraft-bedrock-download-pc-free-game-hack PDF link annotation
    • http://bit-sky.com/images/como-hackear-coin-master-ios_GM406889139.pdfIn PDF document text
    • http://bit-sky.com/images/free-roblox-toy-codes-not-used_GM431946152.pdfIn PDF document text
    • http://bit-sky.com/images/update-coin-master-free-spins_GM406889139.pdfIn PDF document text
    • http://bit-sky.com/images/coin-master-free-spins-and-coins-today-gift-reward_GM406889139.pdfIn PDF document text
    • http://bit-sky.com/images/free-roblox-accounts-with-robux-that-work-not-banned_GM431946152.pdfIn PDF document text
    • http://bit-sky.com/images/mcpe-master-hack-coins_GM406889139.pdfIn PDF document text
    • http://bit-sky.com/images/minecraft-java-for-free_GM479516143.pdfIn PDF document text
    • http://bit-sky.com/images/free-robux-by-watching-ads_GM431946152.pdfIn PDF document text
    • http://bit-sky.com/images/coin-master-free-spins-fb-champion_GM406889139.pdfIn PDF document text
    • http://bit-sky.com/images/extra-free-spins-for-coin-master_GM406889139.pdfIn PDF document text
    • http://bit-sky.com/images/can-you-actually-get-free-robux_GM431946152.pdfIn PDF document text
    • http://bit-sky.com/images/coin-master-free-spins-app_GM406889139.pdfIn PDF document text
    • http://bit-sky.com/images/free-roblox-cards-pin-number_GM431946152.pdfIn PDF document text
    • http://bit-sky.com/images/free-robux-no-email_GM431946152.pdfIn PDF document text
    • http://bit-sky.com/images/how-to-get-free-robux-hack_GM431946152.pdfIn PDF document text
    • http://bit-sky.com/images/2021-no-human-verification-hack-for-coin-master_GM406889139.pdfIn PDF document text
    • http://bit-sky.com/images/how-to-hack-coin-master-ios-2021_GM406889139.pdfIn PDF document text
    • http://bit-sky.com/images/free-roebucks-no-human-verification_GM431946152.pdfIn PDF document text
    • http://bit-sky.com/images/minecraft-noob-vs-pro-vs-hacker-vs-god_GM479516143.pdfIn PDF document text
    • http://bit-sky.com/images/how-to-get-free-robux-without-downloading-apps-2021_GM431946152.pdfIn PDF document text
    • http://en.wikipedia.org/wiki/MIT_LicenseIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_003_off00004c26.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x4C26 25280 bytes
SHA-256: 54d5d119ab5e76e989e030632274da41918cc008656f3db1f88bec40ffb9f1d6
font_01_sfnt_off0000852d.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x852D 18828 bytes
SHA-256: a264e86136786ea36ffe75565c0a75df0f10437a5612c71f93040c03370f29a0