Malicious PDF — malware analysis report

Static analysis result for SHA-256 52fb37a4f5c9bff0…

MALICIOUS

PDF

46.3 KB Created: 2021-05-14 02:02:25 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: cc3a33d90e8c7635e68de716ea49f827 SHA-1: 8657b756ebbc14af38417b3fd0309b707d645d2d SHA-256: 52fb37a4f5c9bff057ed41d3fa42ba4ef8b11dea6741044906a6a11eb4ee45df
82 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF document contains a fake CAPTCHA lure, designed to trick users into interacting with malicious links. The primary external URI points to a URL associated with 'coin master free spins', a common lure for scams. While no scripts were explicitly extracted, the PDF structure and heuristics suggest it is designed to facilitate the download or redirection to malicious content, likely via the embedded URLs.

Machine Learning

  • Nyx PDF Classifier malicious score 0.8696

Heuristics 4

  • Fake CAPTCHA / human verification prompt high SE_FAKE_CAPTCHA
    Document displays a fake CAPTCHA or human-verification prompt — used to trick users into running commands or pressing keyboard shortcuts
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://netcdn.xyz/app/406889139/coin-master-free-spins-link-today-game-hack
    • https://belixconstructions.com.au/images/minecraft-windows-10-edition-free-download_GM479516143.pdf
    • https://belixconstructions.com.au/images/www-free-robux-com_GM431946152.pdf
    • https://belixconstructions.com.au/images/minecraft-for-free-games_GM479516143.pdf
    • https://belixconstructions.com.au/images/easy-ways-to-get-free-robux_GM431946152.pdf
    • https://belixconstructions.com.au/images/coin-master-free-chest-link_GM406889139.pdf
    • https://belixconstructions.com.au/images/roblox-hack-codes_GM431946152.pdf
    • https://belixconstructions.com.au/images/minecraft-hacked-client_GM479516143.pdf
    • https://belixconstructions.com.au/images/free-roblox-accounts-with-robux-that-work-not-banned-2021_GM431946152.pdf
    • https://belixconstructions.com.au/images/hack-coin-master-free_GM406889139.pdf
    • https://belixconstructions.com.au/images/earn-robux-com_GM431946152.pdf
    • https://belixconstructions.com.au/images/links-to-free-spins-on-coin-master_GM406889139.pdf
    • https://belixconstructions.com.au/images/coin-master-daily-gift-free-spins-and-coins-link-today_GM406889139.pdf
    • https://belixconstructions.com.au/images/how-to-get-free-robux-easy-hack_GM431946152.pdf
    • https://belixconstructions.com.au/images/how-to-get-hacks-on-minecraft_GM479516143.pdf
    • https://belixconstructions.com.au/images/free-robux-generator-for-roblox-2021_GM431946152.pdf
    • https://belixconstructions.com.au/images/roblox-com-free-robux_GM431946152.pdf
    • https://belixconstructions.com.au/images/hacks-for-roblox-jailbreak_GM431946152.pdf
    • https://belixconstructions.com.au/images/coin-master-free-spin-and-coins-links_GM406889139.pdf
    • https://belixconstructions.com.au/images/minecraft-logo-maker-free_GM479516143.pdf
    • https://belixconstructions.com.au/images/free-roblox-accounts-with-robux-2021_GM431946152.pdf
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_003_off00004970.bin
d02487b9a9d887d948248cda6ed7339c363e29e3aabcd8b29cff73db2c15e253
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x4970 27380 bytes
font_01_sfnt_off0000880e.bin
10d025f04f706eb71cdda4f99784df1b9ccb52e48080e43095e0398eaef6f132
pdf-font-stream PDF embedded font (sfnt) at offset 0x880E 2880 bytes
font_02_sfnt_off000091f8.bin
ee277532c3187caf3da016130e4cbd3fee848ac0b1174d0f40fc16c12ed3c41d
pdf-font-stream PDF embedded font (sfnt) at offset 0x91F8 18412 bytes