Malicious PDF — malware analysis report

Static analysis result for SHA-256 57aec32ce8e385d1…

MALICIOUS

PDF

42.9 KB Created: 2021-05-14 10:58:33 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: b281696c68793c20ca6bf11e88fe848c SHA-1: d85c6803a077b41e80b034d6dfa1bf2aa06c2cae SHA-256: 57aec32ce8e385d1a9075c06aa7a4baa5ef95e88d24a6716a046d7988beeaa49
142 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF document exhibits characteristics of an advance-fee scam, using lures related to popular games like Minecraft and Coin Master to entice users. It contains numerous external links, many pointing to PDF files hosted on suspicious domains, suggesting a link farm designed to distribute malware or facilitate phishing. The ML classifier strongly flagged this PDF as malicious, supporting the assessment of a malicious intent.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9971

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Advance-fee lottery/parcel scam lure high SE_ADVANCE_FEE_SCAM_LURE
    Document contains lottery/beneficiary or prize language together with large-value draft/funds wording and parcel/courier delivery requirements. This is a classic advance-fee fraud document shape.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://netcdn.xyz/app/479516143/minecraft-free-download-android-apk-game-hack
    • https://ballaratcaravans.com.au/images/how-to-get-free-coins-on-coin-master_GM406889139.pdf
    • https://ballaratcaravans.com.au/images/free-gifts-coin-master_GM406889139.pdf
    • https://ballaratcaravans.com.au/images/how-to-get-robux_GM431946152.pdf
    • https://ballaratcaravans.com.au/images/free-minecraft-skin-packs_GM479516143.pdf
    • https://ballaratcaravans.com.au/images/free-robux-apps-that-work_GM431946152.pdf
    • https://ballaratcaravans.com.au/images/free-roblox-gift-card-codes_GM431946152.pdf
    • https://ballaratcaravans.com.au/images/coin-master-hack-fast-org_GM406889139.pdf
    • https://ballaratcaravans.com.au/images/minecraft-xbox-one-code-free_GM479516143.pdf
    • https://ballaratcaravans.com.au/images/clean-master-hack-coins_GM406889139.pdf
    • https://ballaratcaravans.com.au/images/coin-master-time-speed-hack_GM406889139.pdf
    • https://ballaratcaravans.com.au/images/how-to-earn-robux-by-playing-games_GM431946152.pdf
    • https://ballaratcaravans.com.au/images/how-to-get-free-robux-without-downloading-any-apps_GM431946152.pdf
    • https://ballaratcaravans.com.au/images/spins-for-coin-master_GM406889139.pdf
    • https://ballaratcaravans.com.au/images/how-to-get-free-robux-on-roblox_GM431946152.pdf
    • https://ballaratcaravans.com.au/images/free-robux-without-verification-or-survey_GM431946152.pdf
    • https://ballaratcaravans.com.au/images/coin-master-daily-free-spins-link-today-facebook_GM406889139.pdf
    • https://ballaratcaravans.com.au/images/how-to-get-free-robux-easy-no-download_GM431946152.pdf
    • https://ballaratcaravans.com.au/images/free-coin-master-spins-daily_GM406889139.pdf
    • https://ballaratcaravans.com.au/images/is-free-robux-real_GM431946152.pdf
    • https://ballaratcaravans.com.au/images/coin-master-hack-tool-2021_GM406889139.pdf
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_003_off00004c06.bin
a306aa647a4f8d467e8bead5ac8cd9a9dd6a9d3811e07c324071a77b8c3db4a6
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x4C06 24660 bytes
font_01_sfnt_off00008430.bin
653028bcb0f2fb6608854d40a7a9db9360db480d39b3fa53a0b8dd523b133d01
pdf-font-stream PDF embedded font (sfnt) at offset 0x8430 18636 bytes