Malicious PDF — malware analysis report

Static analysis result for SHA-256 4ebf577ebdde9c26…

MALICIOUS

PDF

41.8 KB Created: 2021-05-19 22:34:09 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: fba59b43c16ec04bc7d4afa4b67e26b3 SHA-1: f1f1559085e188798f0c3f55582b32e1d01190f0 SHA-256: 4ebf577ebdde9c266d1d7b8964b8f248f6c22a6b98ff68713c41c86887758788
62 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF document contains multiple embedded URIs and clickable links that direct users to external websites, some of which are hosted on an IP address. These links are disguised as offers for game-related cheats or items, indicating a phishing or malware distribution attempt. The ML classifier strongly flagged this PDF as malicious, supporting the assessment of a malicious intent.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9971

Heuristics 4

  • Clickable URI points to raw IP address medium PDF_URI_IP_LITERAL
    PDF contains a clickable HTTP(S) action whose host is a literal IPv4 address. Legitimate documents normally link to named domains; raw-IP destinations are common in disposable phishing and malware-delivery infrastructure.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://netcdn.xyz/app/479516143/free-minecraft-alts-game-hack
    • http://118.174.0.244/UserFiles/File/free-spins-and-coins-for-coin-master_GM406889139.pdf
    • http://118.174.0.244/UserFiles/File/free-robux-promo-codes-2021_GM431946152.pdf
    • http://118.174.0.244/UserFiles/File/coin-master-game-hacking-tricks_GM406889139.pdf
    • http://118.174.0.244/UserFiles/File/robux-hacks-2021_GM431946152.pdf
    • http://118.174.0.244/UserFiles/File/coin-master-daily-rewards-link_GM406889139.pdf
    • http://118.174.0.244/UserFiles/File/coin-master-daily-free-spins-link-march-2021_GM406889139.pdf
    • http://118.174.0.244/UserFiles/File/how-to-get-2021-robux-for-free_GM431946152.pdf
    • http://118.174.0.244/UserFiles/File/free-coin-master-hacks-no-verification-or-survey_GM406889139.pdf
    • http://118.174.0.244/UserFiles/File/coin-master-free-spin-and-coins-links-2021_GM406889139.pdf
    • http://118.174.0.244/UserFiles/File/free-robux-websites-that-actually-work_GM431946152.pdf
    • http://118.174.0.244/UserFiles/File/coin-master-cheats-2021_GM406889139.pdf
    • http://118.174.0.244/UserFiles/File/free-robux-no-verification-at-all_GM431946152.pdf
    • http://118.174.0.244/UserFiles/File/free-robux-legit_GM431946152.pdf
    • http://118.174.0.244/UserFiles/File/how-to-get-free-roebucks-in-roblox_GM431946152.pdf
    • http://118.174.0.244/UserFiles/File/free-robux-mod_GM431946152.pdf
    • http://118.174.0.244/UserFiles/File/coin-master-free-spins-hack_GM406889139.pdf
    • http://118.174.0.244/UserFiles/File/how-to-get-robux-easy_GM431946152.pdf
    • http://118.174.0.244/UserFiles/File/coin-master-free-spins-link-2021_GM406889139.pdf
    • http://118.174.0.244/UserFiles/File/free-robux-gift-card-codes_GM431946152.pdf
    • http://118.174.0.244/UserFiles/File/coin-master-free-spin-links-december-30-2021_GM406889139.pdf
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_003_off00004ac6.bin
efe160741f22cec7893d39dba5f7f939529cd839721d5a761aea4d63cb5fa41e
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x4AC6 24900 bytes
font_01_sfnt_off0000830e.bin
4350bb70586d7d356c834f80239bf16b03274066df9e9143be1036ee17eff588
pdf-font-stream PDF embedded font (sfnt) at offset 0x830E 17644 bytes