Malicious PDF — malware analysis report

Static analysis result for SHA-256 31d2b2e2bfa3503d…

MALICIOUS

PDF

44.4 KB Created: 2021-06-10 15:17:40 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: 537190a5abb8f0eacfda40311048629f SHA-1: 143310b077d559bdacc8ba4406f6f50a0828a749 SHA-256: 31d2b2e2bfa3503d49ca342f8b18f5432ab28c3c552089b521445c47c2424dd6
102 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The document contains a critical heuristic for requesting recovery secrets or private keys, combined with embedded URLs pointing to game-related cheats and codes. This suggests a phishing or social engineering attack aimed at tricking users into revealing sensitive information or downloading potentially malicious files disguised as game aids. The ML classifier also strongly flagged this PDF as malicious.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9865

Heuristics 4

  • Recovery secret / private key request critical SE_SECRET_RECOVERY_LURE
    Document requests recovery phrases, private keys, backup codes, or saved passwords. Requests for these secrets in a document are high-risk.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://netcdn.tw/app/431946152/cheats-and-codes-for-roblox-on-pc-game-hack
    • http://perpus.masda.ac.id//repository/coin-master-cheats-free_GM406889139.pdf
    • http://perpus.masda.ac.id/repository/free-spins-and-coins-coin-master_GM406889139.pdf
    • http://perpus.masda.ac.id/repository/how-do-i-get-free-spins-on-coin-master_GM406889139.pdf
    • http://perpus.masda.ac.id/repository/how-to-get-robux-for-free-2021_GM431946152.pdf
    • http://perpus.masda.ac.id//repository/coin-master-hack-quora_GM406889139.pdf
    • http://perpus.masda.ac.id/repository/free-coins-coin-master-link-today_GM406889139.pdf
    • http://perpus.masda.ac.id//repository/free-spins-on-coin-master-app_GM406889139.pdf
    • http://perpus.masda.ac.id/repository/minecraft-handbook_GM479516143.pdf
    • http://perpus.masda.ac.id//repository/coin-master-free-daily-spins_GM406889139.pdf
    • http://perpus.masda.ac.id//repository/free-spins-for-coin-master_GM406889139.pdf
    • http://perpus.masda.ac.id/repository/como-hackear-coin-master-2021_GM406889139.pdf
    • http://perpus.masda.ac.id/repository/tiktok-free-view-pro-app-download_GM835599320.pdf
    • http://perpus.masda.ac.id/repository/clean-master-hack-coins_GM406889139.pdf
    • http://perpus.masda.ac.id/repository/how-to-get-free-spins-in-coin-master_GM406889139.pdf
    • http://perpus.masda.ac.id/repository/roblox-hackprogamers-com_GM431946152.pdf
    • http://perpus.masda.ac.id//repository/coin-master-70-spin-link-2021_GM406889139.pdf
    • http://perpus.masda.ac.id/repository/plug-toolbox-for-minecraft-free-ios_GM479516143.pdf
    • http://perpus.masda.ac.id/repository/roblox-booga-booga-hack_GM431946152.pdf
    • http://perpus.masda.ac.id/repository/blogspot-coin-master_GM406889139.pdf
    • http://perpus.masda.ac.id/repository/tiktok-free-followers-generator_GM835599320.pdf
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_004_off00004ee4.bin
c78074c9bbaae23c6d36d00a13ed6009b6ac19d184744158f2df56401ec844ad
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x4EE4 25596 bytes
font_01_sfnt_off00008978.bin
a5e84ef6ecc2b04e202ce6b5a6a5c8cf43e6e1c011a84446bf01571444b50d00
pdf-font-stream PDF embedded font (sfnt) at offset 0x8978 18776 bytes