Malicious PDF — malware analysis report

Static analysis result for SHA-256 74b52013a13aeab3…

MALICIOUS

PDF

41.9 KB Created: 2021-05-11 15:02:45 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: fde105ce80a0f346cda4dfee67f10add SHA-1: ff0376bb5e472b8221743b667e9499559628e0cf SHA-256: 74b52013a13aeab3cd45c9f1d91107f765d4918dbc196c9fa501f05b8e36d7be
82 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF document contains heuristics indicating it is a browser extension or update installation lure, common for social engineering. It also contains external URIs pointing to what appear to be game hack download sites. The document body, though heavily obfuscated, contains references to Minecraft and game hacks, reinforcing the lure. The primary malicious URL identified is https://netcdn.xyz/app/479516143/minecraft-images-free-game-hack.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9971

Heuristics 4

  • Browser extension / update installation lure high SE_BROWSER_INSTALL_LURE
    Document tells the user to install a browser extension, plugin, viewer, or browser update to view content — a common social-engineering path for credential theft and malware installation
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://netcdn.xyz/app/479516143/minecraft-images-free-game-hack
    • https://elearning.mtsnkampak.sch.id/__statics/gudangsoal/files/coin-master-hack-no-verification-ios_GM406889139.pdf
    • https://elearning.mtsnkampak.sch.id/__statics/gudangsoal/files/how-to-play-minecraft-for-free-on-computer_GM479516143.pdf
    • https://elearning.mtsnkampak.sch.id/__statics/gudangsoal/files/free-robux-hacks-no-verification_GM431946152.pdf
    • https://elearning.mtsnkampak.sch.id/__statics/gudangsoal/files/coin-master-spin-link-today-free_GM406889139.pdf
    • https://elearning.mtsnkampak.sch.id/__statics/gudangsoal/files/toolbox-for-minecraft-pe_GM479516143.pdf
    • https://elearning.mtsnkampak.sch.id/__statics/gudangsoal/files/is-minecraft-bedrock-free_GM479516143.pdf
    • https://elearning.mtsnkampak.sch.id/__statics/gudangsoal/files/coin-master-hacks-xyz_GM406889139.pdf
    • https://elearning.mtsnkampak.sch.id/__statics/gudangsoal/files/free-robux-site_GM431946152.pdf
    • https://elearning.mtsnkampak.sch.id/__statics/gudangsoal/files/coin-master-free-spin-redeem-code_GM406889139.pdf
    • https://elearning.mtsnkampak.sch.id/__statics/gudangsoal/files/how-to-get-robux-for-free-2021_GM431946152.pdf
    • https://elearning.mtsnkampak.sch.id/__statics/gudangsoal/files/free-robux-just-click_GM431946152.pdf
    • https://elearning.mtsnkampak.sch.id/__statics/gudangsoal/files/websites-to-get-free-robux_GM431946152.pdf
    • https://elearning.mtsnkampak.sch.id/__statics/gudangsoal/files/roblox-speed-hack_GM431946152.pdf
    • https://elearning.mtsnkampak.sch.id/__statics/gudangsoal/files/coin-master-generator-free_GM406889139.pdf
    • https://elearning.mtsnkampak.sch.id/__statics/gudangsoal/files/coin-master-free-spins-and-coins-group_GM406889139.pdf
    • https://elearning.mtsnkampak.sch.id/__statics/gudangsoal/files/free-robux-generator-no-verification-2021_GM431946152.pdf
    • https://elearning.mtsnkampak.sch.id/__statics/gudangsoal/files/best-roblox-hacks_GM431946152.pdf
    • https://elearning.mtsnkampak.sch.id/__statics/gudangsoal/files/free-coin-master-cards_GM406889139.pdf
    • https://elearning.mtsnkampak.sch.id/__statics/gudangsoal/files/daily-free-spins-and-coins-coin-master_GM406889139.pdf
    • https://elearning.mtsnkampak.sch.id/__statics/gudangsoal/files/free-robux-no-human-verification-or-survey-2021_GM431946152.pdf
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_003_off00004b5d.bin
3014bf982ea37c70d1d6dc9dfe46e06bb2709c72192742d02e91641889075fba
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x4B5D 24344 bytes
font_01_sfnt_off00008201.bin
76604dd5740139514d3fd46c2a9d9c838f52c59b348f00b4ee9f07d20b77a693
pdf-font-stream PDF embedded font (sfnt) at offset 0x8201 18116 bytes