Malicious PDF — malware analysis report

Static analysis result for SHA-256 4ba730d71c41047b…

MALICIOUS

PDF

42.8 KB Created: 2021-05-18 01:31:31 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: c01ce434d663d5b783693ed7de09730f SHA-1: e595f2cf6319210299442cf86e81a13706fb210d SHA-256: 4ba730d71c41047bcc78884974a07a0252ad4601520359209602e02344115718
82 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF document contains multiple embedded URLs and a visual call-to-action button, directing users to websites that appear to be related to free game currency or hacks. The ML classifier strongly flagged this PDF as malicious, and the presence of MFA/one-time-code harvesting lures suggests a phishing attempt. The document's content and embedded links indicate an attempt to trick users into visiting potentially malicious sites.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9971

Heuristics 4

  • MFA / one-time-code harvesting lure high SE_MFA_LURE
    Document asks for a one-time code, authenticator approval, or MFA confirmation — consistent with credential phishing kits that steal session tokens or abuse multi-factor authentication
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://netcdn.xyz/app/406889139/daily-free-spins-for-coin-master-game-hack
    • http://xn--80adcduozbpo4eve.xn--p1ai/images/robux-free-co_GM431946152.pdf
    • http://xn--80adcduozbpo4eve.xn--p1ai/images/free-spins-coin-master-2021_GM406889139.pdf
    • http://xn--80adcduozbpo4eve.xn--p1ai/images/coin-master-daily-spin-free_GM406889139.pdf
    • http://xn--80adcduozbpo4eve.xn--p1ai/images/earn-free-spins-coin-master_GM406889139.pdf
    • http://xn--80adcduozbpo4eve.xn--p1ai/images/how-to-get-minecraft-for-free-on-laptop_GM479516143.pdf
    • http://xn--80adcduozbpo4eve.xn--p1ai/images/free-coins-and-spins-in-coin-master_GM406889139.pdf
    • http://xn--80adcduozbpo4eve.xn--p1ai/images/roblox-hack-codes_GM431946152.pdf
    • http://xn--80adcduozbpo4eve.xn--p1ai/images/minecraft-creative-mode-free_GM479516143.pdf
    • http://xn--80adcduozbpo4eve.xn--p1ai/images/roblox-free-skin_GM431946152.pdf
    • http://xn--80adcduozbpo4eve.xn--p1ai/images/block-best-robux_GM431946152.pdf
    • http://xn--80adcduozbpo4eve.xn--p1ai/images/coin-master-hack-app-download-free_GM406889139.pdf
    • http://xn--80adcduozbpo4eve.xn--p1ai/images/robux-get-com_GM431946152.pdf
    • http://xn--80adcduozbpo4eve.xn--p1ai/images/to-get-free-robux_GM431946152.pdf
    • http://xn--80adcduozbpo4eve.xn--p1ai/images/roblox-www-com_GM431946152.pdf
    • http://xn--80adcduozbpo4eve.xn--p1ai/images/coin-master-free-spin-bonus_GM406889139.pdf
    • http://xn--80adcduozbpo4eve.xn--p1ai/images/free-roblox-avatar_GM431946152.pdf
    • http://xn--80adcduozbpo4eve.xn--p1ai/images/play-minecraft-pocket-edition-for-free_GM479516143.pdf
    • http://xn--80adcduozbpo4eve.xn--p1ai/images/master-coin-hack-game_GM406889139.pdf
    • http://xn--80adcduozbpo4eve.xn--p1ai/images/coin-master-link-daily-get-free-spins-amp_GM406889139.pdf
    • http://xn--80adcduozbpo4eve.xn--p1ai/images/how-to-hack-to-get-robux_GM431946152.pdf
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_003_off00004bdd.bin
401c9aedcc80c6103f70a1582348f1c9dd46cb5d2c4be9a15f0d8c8be4ad6932
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x4BDD 25812 bytes
font_01_sfnt_off000084c3.bin
b750d5a8b44caccc122b2ff8294eb9307e18e87e3916697a2a7f0c063c77f291
pdf-font-stream PDF embedded font (sfnt) at offset 0x84C3 18308 bytes