Malicious PDF — malware analysis report

Static analysis result for SHA-256 3db3641b435ce560…

MALICIOUS

PDF

42.9 KB Created: 2021-05-16 11:39:31 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: 6faa559a74dabba192f2f25517a0a14a SHA-1: a2066d0ad564adfdf7cdae893f981b20c04d543d SHA-256: 3db3641b435ce5600e844771a91d8902662f79dc5b32c7c4cc7776a548a9991e
142 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1203 Exploitation for Client Execution

The PDF document contains numerous embedded links, many of which are structured as SEO-optimized PDF links, suggesting a link farm. A critical heuristic identified a fake CAPTCHA prompt, a common social engineering tactic to trick users into clicking malicious links. The document body, though heavily obfuscated, contains URLs that likely lead to further malicious content or downloads. The presence of these elements strongly indicates an attempt to deliver a malicious payload.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9971

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Fake CAPTCHA / human verification prompt high SE_FAKE_CAPTCHA
    Document displays a fake CAPTCHA or human-verification prompt — used to trick users into running commands or pressing keyboard shortcuts
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://netcdn.xyz/app/431946152/lazy-blocks-com-free-robux-game-hack
    • http://fs4sms.com/images/coin-master-invite-friends-free-spins_GM406889139.pdf
    • http://fs4sms.com/images/coin-master-free-spin-and-coin-link-haktuts-hacking-news_GM406889139.pdf
    • http://fs4sms.com/images/how-to-get-free-robux-promo-codes_GM431946152.pdf
    • http://fs4sms.com/images/how-to-get-free-robux-website_GM431946152.pdf
    • http://fs4sms.com/images/coin-master-links-to-free-spins_GM406889139.pdf
    • http://fs4sms.com/images/coin-master-free-spin-and-coin-link-2021-today_GM406889139.pdf
    • http://fs4sms.com/images/can-i-get-robux-for-free_GM431946152.pdf
    • http://fs4sms.com/images/free-coins-and-spins-coin-master_GM406889139.pdf
    • http://fs4sms.com/images/coin-master-rewards_GM406889139.pdf
    • http://fs4sms.com/images/coin-master-hack-2021-apk-download_GM406889139.pdf
    • http://fs4sms.com/images/coin-master-free-spins-link-today-twitter_GM406889139.pdf
    • http://fs4sms.com/images/get-free-spins-coin-master-link_GM406889139.pdf
    • http://fs4sms.com/images/coin-master-hack-without-verification_GM406889139.pdf
    • http://fs4sms.com/images/minecraft-windows-10-hack-client-2021_GM479516143.pdf
    • http://fs4sms.com/images/coin-master-hack-no-download_GM406889139.pdf
    • http://fs4sms.com/images/free-robux-codes-2021_GM431946152.pdf
    • http://fs4sms.com/images/free-games-like-roblox_GM431946152.pdf
    • http://fs4sms.com/images/free-robux-with-no-human-verification_GM431946152.pdf
    • http://fs4sms.com/images/do-you-get-minecraft-windows-10-for-free_GM479516143.pdf
    • http://fs4sms.com/images/coin-master-free_GM406889139.pdf
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_003_off00004965.bin
d6993f3992b818dbca86864094251ab7eb62150676d8408f3f8a16e1abc4e72b
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x4965 25280 bytes
font_01_sfnt_off00008325.bin
34c8d34d38b90765c6e33941713304debcf78082891e10a16d595afa5c3321d4
pdf-font-stream PDF embedded font (sfnt) at offset 0x8325 19008 bytes