Malicious PDF — malware analysis report

Static analysis result for SHA-256 30ce66b47b2f8f1e…

MALICIOUS

PDF

47.3 KB Created: 2021-05-19 22:01:32 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7) First seen: 2021-09-29
MD5: 1b6d1bc4852293657d1cc38e0482660f SHA-1: 290fc143e25e996ab7694fc00c3b405dfeff8908 SHA-256: 30ce66b47b2f8f1ed507e3a745244e3b0f6dad5785d2af469f853ed2c98bca9e
82 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains embedded links that are identified as lures for "game hacks" and "free generators", specifically mentioning TikTok. The primary malicious URL identified is https://netcdn.xyz/app/835599320/tiktok-free-app-download-game-hack. While no scripts were extracted, the presence of these lures and the ML classifier's high confidence suggest the document is designed to redirect users to potentially malicious sites or downloads.

Machine Learning

  • Nyx PDF Classifier malicious score 0.8619

Heuristics 4

  • PDF links to a 'free generator / game hack' redirector high PDF_GAME_HACK_REDIRECT_LURE
    PDF's clickable action targets a redirector of the form /app/<id>/<slug>-game-hack — the landing-page shape of a large SEO 'free spins / generator / game hack' lure family that funnels victims through rotating disposable hosts to a malware/scam payload. The multi-link variants also trip ML/link-farm rules; this catches the single-link variants that otherwise score clean.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://netcdn.xyz/app/835599320/tiktok-free-app-download-game-hack PDF link annotation
    • https://www.e-learning.man1majalengka.sch.id/__statics/gudangsoal/files/roblox-games-that-give-you-free-robux_GM431946152.pdfIn PDF document text
    • https://e-learning.man1majalengka.sch.id/__statics/gudangsoal/files/coin-master-hacks-free-spins_GM406889139.pdfIn PDF document text
    • https://e-learning.man1majalengka.sch.id/__statics/gudangsoal/files/free-robux-without-human-verification-2021_GM431946152.pdfIn PDF document text
    • https://e-learning.man1majalengka.sch.id/__statics/gudangsoal/files/coin-master-hack-september-2021_GM406889139.pdfIn PDF document text
    • https://e-learning.man1majalengka.sch.id/__statics/gudangsoal/files/coin-master-hack-ios-2021_GM406889139.pdfIn PDF document text
    • https://www.e-learning.man1majalengka.sch.id/__statics/gudangsoal/files/bux-life-free-robux_GM431946152.pdfIn PDF document text
    • https://e-learning.man1majalengka.sch.id/__statics/gudangsoal/files/free-coin-master-spins-for-today_GM406889139.pdfIn PDF document text
    • https://e-learning.man1majalengka.sch.id/__statics/gudangsoal/files/all-links-for-free-spins-coin-master_GM406889139.pdfIn PDF document text
    • https://e-learning.man1majalengka.sch.id/__statics/gudangsoal/files/roblox-robux-hack_GM431946152.pdfIn PDF document text
    • https://www.e-learning.man1majalengka.sch.id/__statics/gudangsoal/files/download-coin-master-apk-hacked_GM406889139.pdfIn PDF document text
    • https://www.e-learning.man1majalengka.sch.id/__statics/gudangsoal/files/coin-master-free-coins--spins_GM406889139.pdfIn PDF document text
    • https://www.e-learning.man1majalengka.sch.id/__statics/gudangsoal/files/minecraft-pe-mod-menu_GM479516143.pdfIn PDF document text
    • https://www.e-learning.man1majalengka.sch.id/__statics/gudangsoal/files/2021-coin-master-hack_GM406889139.pdfIn PDF document text
    • https://www.e-learning.man1majalengka.sch.id/__statics/gudangsoal/files/legit-coin-master-hack-no-human-verification_GM406889139.pdfIn PDF document text
    • https://www.e-learning.man1majalengka.sch.id/__statics/gudangsoal/files/i-got-hacked-on-roblox_GM431946152.pdfIn PDF document text
    • https://www.e-learning.man1majalengka.sch.id/__statics/gudangsoal/files/free-star-codes-roblox_GM431946152.pdfIn PDF document text
    • https://e-learning.man1majalengka.sch.id/__statics/gudangsoal/files/cool-free-minecraft-skins_GM479516143.pdfIn PDF document text
    • https://e-learning.man1majalengka.sch.id/__statics/gudangsoal/files/roblox-apocalypse-rising-hack_GM431946152.pdfIn PDF document text
    • https://e-learning.man1majalengka.sch.id/__statics/gudangsoal/files/how-to-get-free-robux-for-real_GM431946152.pdfIn PDF document text
    • https://www.e-learning.man1majalengka.sch.id/__statics/gudangsoal/files/coin-master-hack-tool_GM406889139.pdfIn PDF document text
    • http://en.wikipedia.org/wiki/MIT_LicenseIn PDF document text

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_003_off000049c4.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x49C4 23412 bytes
SHA-256: 0a9c8c464048513be500f29ee90d0f593bf8520e1853bccb4dde90bcb06ff99b
font_01_sfnt_off00007ebb.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x7EBB 3372 bytes
SHA-256: dfbbf67cbc7ecc66ac4d03805ccfff7e5c1407898ea3c5e2b9241b85217ff1cd
font_02_sfnt_off00008a3d.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x8A3D 3120 bytes
SHA-256: 49734f51977507cba6bc8d3ad0cee0363aa119856db094427deb9cf565bb7bca
font_03_sfnt_off00009551.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x9551 18440 bytes
SHA-256: 4a0ca55a738a85790a5837a32fbf5a9dd76efc5f52598b5f6f533652721a60a8