Malicious PDF — malware analysis report

Static analysis result for SHA-256 33581614387180ff…

MALICIOUS

PDF

42.4 KB Created: 2021-05-19 08:42:02 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: 46c8cfcd807b7a2bc40ad6f06d97815e SHA-1: e27c066d8372842667048c6821fd492314869cf0 SHA-256: 33581614387180ff80b23453176d977d2ba005232132ec4889276e180c67427c
82 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF document contains lures for downloading applications, specifically mentioning 'Pokemon Go Free Download' and 'game hack'. It also embeds multiple URLs pointing to sites offering similar game-related hacks and freebies. The ML classifier strongly flagged this PDF as malicious, and the presence of external URIs and payment redirection lures further supports a malicious intent to trick users into downloading potentially unwanted or harmful software.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9971

Heuristics 4

  • Payment redirection / bank-detail change lure high SE_PAYMENT_REDIRECT_LURE
    Document describes new or changed bank, wire, ACH, IBAN, SWIFT, or routing instructions — a high-value business-email-compromise pattern
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://netcdn.xyz/app/1094591345/pokemon-go-free-download-for-windows-10-game-hack
    • http://szekelymozes.ro/images/free-spin-appscoin-master_GM406889139.pdf
    • http://szekelymozes.ro/images/free-robux-hacks-no-verification_GM431946152.pdf
    • http://szekelymozes.ro/images/minecraft-sign-up-free_GM479516143.pdf
    • http://szekelymozes.ro/images/coin-master-free-spin-and-coin-link-haktuts-hacking-news_GM406889139.pdf
    • http://szekelymozes.ro/images/free-roblox-app_GM431946152.pdf
    • http://szekelymozes.ro/images/coin-master-hack-account_GM406889139.pdf
    • http://szekelymozes.ro/images/robux-download_GM431946152.pdf
    • http://szekelymozes.ro/images/coin-master-free-coins_GM406889139.pdf
    • http://szekelymozes.ro/images/como-hackear-coin-master-2021-espaol_GM406889139.pdf
    • http://szekelymozes.ro/images/minecraft-xray-hack_GM479516143.pdf
    • http://szekelymozes.ro/images/free-roblox-money_GM431946152.pdf
    • http://szekelymozes.ro/images/free-spins-coin-master-2021-hack_GM406889139.pdf
    • http://szekelymozes.ro/images/free-robux-gen_GM431946152.pdf
    • http://szekelymozes.ro/images/best-way-to-get-free-robux_GM431946152.pdf
    • http://szekelymozes.ro/images/how-do-you-get-free-robux-on-roblox_GM431946152.pdf
    • http://szekelymozes.ro/images/how-to-get-free-robux-with-no-verification_GM431946152.pdf
    • http://szekelymozes.ro/images/roblox-arsenal-hacks-download_GM431946152.pdf
    • http://szekelymozes.ro/images/coin-master-free-spins_GM406889139.pdf
    • http://szekelymozes.ro/images/coin-master-hack-tool-v1-9-apk_GM406889139.pdf
    • http://szekelymozes.ro/images/coin-master-online-hack-link_GM406889139.pdf
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_003_off0000491a.bin
9f06995a2421f6b672fff9c78eacb65f0a84656f806492f379e87bbc92cf3489
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x491A 24452 bytes
font_01_sfnt_off0000808a.bin
4228d80739e31afbfe3ed8b82874d4cb00450351dca4a0142e27bf57359bee0b
pdf-font-stream PDF embedded font (sfnt) at offset 0x808A 19244 bytes