Malicious PDF — malware analysis report

Static analysis result for SHA-256 38c6fb4ca098a3bd…

MALICIOUS

PDF

44.1 KB Created: 2021-06-03 10:54:35 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: a5d44edc0bdb1ff384101b917e0e2325 SHA-1: ee3b985f4edae2d1e46216d8cdf6988da97a3103 SHA-256: 38c6fb4ca098a3bd270342948c9d745208bb2d46669ca40f937e0e0df73ad59e
62 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1203 Exploitation for Client Execution

The PDF contains multiple embedded URLs and heuristics indicate it is designed to lure users into downloading malicious files, likely related to game cheats or hacks. The ML classifier strongly flagged this PDF as malicious, and the presence of download-related text and external URIs supports a phishing or scam attack pattern. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9865

Heuristics 4

  • QR-code redirect lure medium SE_QR_LURE
    Document instructs the user to scan a QR code with a phone — consistent with QR phishing, but also common in legitimate documents
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://netcdn.online/app/479516143/minecraft-hacker-skin-game-hack
    • https://ifef.es/ckfinder/userfiles/files/roblox-script-hacks_GM431946152.pdf
    • https://ifef.es/ckfinder/userfiles/files/can-you-actually-get-free-robux_GM431946152.pdf
    • https://ifef.es/ckfinder/userfiles/files/coin-master-free-spins-cheat-codes_GM406889139.pdf
    • https://ifef.es/ckfinder/userfiles/files/coin-master-daily-free-spins-and-coins-link_GM406889139.pdf
    • https://ifef.es/ckfinder/userfiles/files/unlimited-robux_GM431946152.pdf
    • https://ifef.es/ckfinder/userfiles/files/coin-master-free-coins-and-spins-link_GM406889139.pdf
    • https://ifef.es/ckfinder/userfiles/files/coin-master-free-stuff_GM406889139.pdf
    • https://ifef.es/ckfinder/userfiles/files/are-tiktok-free-views-hack_GM835599320.pdf
    • https://ifef.es/ckfinder/userfiles/files/spin-free-coin-master_GM406889139.pdf
    • https://ifef.es/ckfinder/userfiles/files/how-to-get-free-spins-on-coin-master-facebook_GM406889139.pdf
    • https://ifef.es/ckfinder/userfiles/files/how-to-get-robux-for-free-2021_GM431946152.pdf
    • https://ifef.es/ckfinder/userfiles/files/new-free-money-links-coin-master_GM406889139.pdf
    • https://ifef.es/ckfinder/userfiles/files/free-coin-master-coins-and-spins_GM406889139.pdf
    • https://ifef.es/ckfinder/userfiles/files/coin-master-daily-free-spin-and-coin_GM406889139.pdf
    • https://ifef.es/ckfinder/userfiles/files/pubg-uc-event_GM1330123889.pdf
    • https://ifef.es/ckfinder/userfiles/files/coin-master-free-spins-link-today-haktuts_GM406889139.pdf
    • https://ifef.es/ckfinder/userfiles/files/como-hackear-coin-master-en-espaol_GM406889139.pdf
    • https://ifef.es/ckfinder/userfiles/files/minecraft-games-free-download_GM479516143.pdf
    • https://ifef.es/ckfinder/userfiles/files/free-robux-com-2021_GM431946152.pdf
    • https://ifef.es/ckfinder/userfiles/files/clients-minecraft_GM479516143.pdf
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_004_off000050c8.bin
c08412deb930df77b272091bd8221854f02d2c49915a08be2fb20b71345f6196
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x50C8 25724 bytes
font_01_sfnt_off00008b9b.bin
91fe2762de83ff68ec278d498415159af7d0ffb5c1d0151dc7294afbb77550eb
pdf-font-stream PDF embedded font (sfnt) at offset 0x8B9B 17740 bytes