Malicious PDF — malware analysis report

Static analysis result for SHA-256 48583548e851ba2d…

MALICIOUS

PDF

42.4 KB Created: 2021-05-19 02:38:50 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: 4ac8b738ce6f0444058376f6bddce8f3 SHA-1: 9eb11c409a020d90c166a0bac46fd7ec02f6401b SHA-256: 48583548e851ba2dc76706378874b28479f95a02e6a33cfd1d6cd9634c927cb3
82 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The sample is a PDF document that contains embedded URLs and lures the user with promises of game cheats and free currency. The ML classifier and the presence of external URIs strongly indicate malicious intent. The document body, though heavily obfuscated, contains references to game hacks and a primary URL pointing to a potential download site, suggesting it's designed to trick users into downloading a second-stage payload.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9971

Heuristics 4

  • Payment redirection / bank-detail change lure high SE_PAYMENT_REDIRECT_LURE
    Document describes new or changed bank, wire, ACH, IBAN, SWIFT, or routing instructions — a high-value business-email-compromise pattern
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://netcdn.xyz/app/1094591345/pokemon-go-free-trades-game-hack
    • https://digilib.stieama.ac.id/repository/how-to-get-free-robux-no-verification_GM431946152.pdf
    • https://digilib.stieama.ac.id/repository/free-minecraft-java-edition-account_GM479516143.pdf
    • https://digilib.stieama.ac.id/repository/easy-roblox-today_GM431946152.pdf
    • https://digilib.stieama.ac.id/repository/free-coins--spins-coin-master_GM406889139.pdf
    • https://digilib.stieama.ac.id/repository/minecraft-survival-hacks_GM479516143.pdf
    • https://digilib.stieama.ac.id/repository/rare-free-links-to-coin-master_GM406889139.pdf
    • https://digilib.stieama.ac.id/repository/hacks-minecraft_GM479516143.pdf
    • https://digilib.stieama.ac.id/repository/how-to-get-free-robux-without-doing-anything-2021_GM431946152.pdf
    • https://digilib.stieama.ac.id/repository/coin-master-unlimited-spins-hack_GM406889139.pdf
    • https://digilib.stieama.ac.id/repository/minecraft-client-download_GM479516143.pdf
    • https://digilib.stieama.ac.id/repository/coin-master-free-coins-and-spins-daily_GM406889139.pdf
    • https://digilib.stieama.ac.id/repository/coin-master-free-spin-codes_GM406889139.pdf
    • https://digilib.stieama.ac.id/repository/coin-master-free-coins-and-spins-app_GM406889139.pdf
    • https://digilib.stieama.ac.id/repository/free-roblox-girl-clothes_GM431946152.pdf
    • https://digilib.stieama.ac.id/repository/free-coin-master-spins_GM406889139.pdf
    • https://digilib.stieama.ac.id/repository/coin-master-free-spins_GM406889139.pdf
    • https://digilib.stieama.ac.id/repository/robux-com-free_GM431946152.pdf
    • https://digilib.stieama.ac.id/repository/roblox-hack-2021_GM431946152.pdf
    • https://digilib.stieama.ac.id/repository/free-robux-games-on-roblox_GM431946152.pdf
    • https://digilib.stieama.ac.id/repository/coin-master-free-spinv1-0apkpure-com-apk_GM406889139.pdf
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_003_off00004ad8.bin
718da06495a7eeef1501b6c47ded09eb11f6f6d7599d55a6b91d00386b5d1639
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x4AD8 24796 bytes
font_01_sfnt_off000083a5.bin
8657a42b980980d1f4450aa186a6474296c722852d82b14457773c912d780a6a
pdf-font-stream PDF embedded font (sfnt) at offset 0x83A5 18244 bytes