Malicious PDF — malware analysis report

Static analysis result for SHA-256 39f27945812be9e1…

MALICIOUS

PDF

39.0 KB Created: 2021-06-03 13:34:07 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: c73cac61e889f6aba7cda1b61dd54d01 SHA-1: 27eb8d4ad2e92cff3d49e5aa9d248c51d1c668fd SHA-256: 39f27945812be9e162ed036b8e0c1c4ad2f38a1f4f8931802ca80d805f900442
94 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF document contains numerous links to external websites, identified by the PDF_SEO_LINK_FARM heuristic, which are likely part of a phishing or scam campaign. The ML classifier also strongly indicated maliciousness. The document body, though heavily obfuscated, contains references to 'Coin Master' and URLs related to game hacks and free currency, reinforcing the lure-based attack pattern.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9963

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://netcdn.online/app/406889139/coin-master-free-coins-and-spins-2021-game-hack
    • https://www.armera.co.uk/uploads/files/files/coin-master-daily-rewards-link_GM406889139.pdf
    • https://www.armera.co.uk/uploads/files/files/moonactive-coin-master-free-spins-link_GM406889139.pdf
    • https://www.armera.co.uk/uploads/files/files/free-clothing-on-roblox_GM431946152.pdf
    • https://www.armera.co.uk/uploads/files/files/coin-master-hacks-that-actually-work_GM406889139.pdf
    • https://www.armera.co.uk/uploads/files/files/best-way-to-get-free-robux_GM431946152.pdf
    • https://www.armera.co.uk/uploads/files/files/rbx-com_GM431946152.pdf
    • https://www.armera.co.uk/uploads/files/files/how-to-hack-roblox-to-get-free-robux_GM431946152.pdf
    • https://www.armera.co.uk/uploads/files/files/coin-master-hack-xyz-download-free_GM406889139.pdf
    • https://www.armera.co.uk/uploads/files/files/how-to-get-free-spins-in-coin-master-2021_GM406889139.pdf
    • https://www.armera.co.uk/uploads/files/files/free-tiktok-followers-generator_GM835599320.pdf
    • https://www.armera.co.uk/uploads/files/files/coin-master-free-spins-link-today-new-2021_GM406889139.pdf
    • https://www.armera.co.uk/uploads/files/files/roblox-promo-codes-2021-robux_GM431946152.pdf
    • https://www.armera.co.uk/uploads/files/files/free-spin-coin-master-ios_GM406889139.pdf
    • https://www.armera.co.uk/uploads/files/files/how-to-hack-and-get-free-robux_GM431946152.pdf
    • https://www.armera.co.uk/uploads/files/files/twitter-coin-master-free-spins_GM406889139.pdf
    • https://www.armera.co.uk/uploads/files/files/haktuts-coin-master-free-spin-link_GM406889139.pdf
    • https://www.armera.co.uk/uploads/files/files/coin-master-free-spin-daily-link_GM406889139.pdf
    • https://www.armera.co.uk/uploads/files/files/coin-master-attack-hack_GM406889139.pdf
    • https://www.armera.co.uk/uploads/files/files/free-mojang-account-with-minecraft_GM479516143.pdf
    • https://www.armera.co.uk/uploads/files/files/coin-master-hack-download-2021_GM406889139.pdf
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_004_off000053b2.bin
126ad79db0f5bd6e4bc0c53a73cbed7b6ca5168fe3851755428a674d6f9d8255
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x53B2 25156 bytes
font_01_sfnt_off00008c5a.bin
3fb127b764b9d10f5525bc4de5ec8316de704409ccb0cf21cff3ad8a30d11676
pdf-font-stream PDF embedded font (sfnt) at offset 0x8C5A 2840 bytes