Malicious PDF — malware analysis report

Static analysis result for SHA-256 3ca1aa98d1df4765…

MALICIOUS

PDF

43.5 KB Created: 2021-05-14 05:04:31 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: 3dcfe9b08194e9dc52d1744f7d1a5ba0 SHA-1: cab221b11d4bf24ff2060dd0cd03e18da4909ed7 SHA-256: 3ca1aa98d1df476556eb8d3c04f0464f78576cf8feafc729e89cd136260701f8
142 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

This PDF document exhibits characteristics of a phishing or scam campaign, using a fake CAPTCHA lure to trick users into downloading files. It contains a large number of external links, many pointing to game-related content, suggesting an attempt to drive traffic to malicious or deceptive sites. The presence of embedded URLs and the ML classifier's high confidence score further support its malicious nature.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9969

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Fake CAPTCHA / human verification prompt high SE_FAKE_CAPTCHA
    Document displays a fake CAPTCHA or human-verification prompt — used to trick users into running commands or pressing keyboard shortcuts
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://netcdn.xyz/app/431946152/free-robux-apk-game-hack
    • http://www.arichuna.com/images/files/minecraft-pe-free-apk_GM479516143.pdf
    • http://www.arichuna.com/images/files/coin-master-free-spin-link-new_GM406889139.pdf
    • http://www.arichuna.com/images/files/coin-master-hack-pro-gamers_GM406889139.pdf
    • http://www.arichuna.com/images/files/free-spins-for-coin-master-2021_GM406889139.pdf
    • http://www.arichuna.com/images/files/free-spins-coin-master-app-ios_GM406889139.pdf
    • http://www.arichuna.com/images/files/rewards-robux_GM431946152.pdf
    • http://www.arichuna.com/images/files/free-robux-no-human-verification-or-survey-or-download-2021_GM431946152.pdf
    • http://www.arichuna.com/images/files/coin-master-free-spin-trick_GM406889139.pdf
    • http://www.arichuna.com/images/files/is-minecraft-education-edition-free_GM479516143.pdf
    • http://www.arichuna.com/images/files/free-coin-master-gifts_GM406889139.pdf
    • http://www.arichuna.com/images/files/online-coin-master-free-spin-app_GM406889139.pdf
    • http://www.arichuna.com/images/files/give-free-robux_GM431946152.pdf
    • http://www.arichuna.com/images/files/hack-coin-master-app_GM406889139.pdf
    • http://www.arichuna.com/images/files/free-spins-october-28-2021-coin-master_GM406889139.pdf
    • http://www.arichuna.com/images/files/free-robux-apps-that-work_GM431946152.pdf
    • http://www.arichuna.com/images/files/coin-master-free-spins-2021_GM406889139.pdf
    • http://www.arichuna.com/images/files/coin-master-70-spin-link-2021_GM406889139.pdf
    • http://www.arichuna.com/images/files/free-spins-for-coin-master-hack_GM406889139.pdf
    • http://www.arichuna.com/images/files/coin-master-daily_GM406889139.pdf
    • http://www.arichuna.com/images/files/real-coin-master-free-spins_GM406889139.pdf
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00004a13.bin
2dbd0399b1421313ff424838b41dc649ac57033e27376ca870cf9fa6d820740d
pdf-font-stream PDF embedded font (sfnt) at offset 0x4A13 27668 bytes
font_01_sfnt_off00008781.bin
e9359734bc9145e2b26d31ba7f580aebc3bf98c57002eb6e857d81b76a5cddb9
pdf-font-stream PDF embedded font (sfnt) at offset 0x8781 18360 bytes