Malicious PDF — malware analysis report

Static analysis result for SHA-256 7c878d00b2c99f82…

MALICIOUS

PDF

34.3 KB Created: 2021-07-05 21:18:21 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: 9eb81f51ce34775f82094d931c0dd92f SHA-1: d63da118ef056e887b4fcabd4715b58e7e0306d5 SHA-256: 7c878d00b2c99f821dd999c591d24fd464a1f91a60621e32ca091cf8dee6bc6c
62 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The document body and extracted URLs indicate a lure for game-related cheats and freebies, specifically for Coin Master and Roblox. The presence of multiple links to external sites suggests an attempt to redirect users to potentially malicious content or phishing pages. The ML classifier also flagged this PDF as malicious with high confidence.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9980

Heuristics 4

  • Callback phishing phone lure medium SE_CALLBACK_LURE
    Document asks the user to call a phone number in billing, refund, subscription, fraud, or security context — consistent with callback phishing or tech-support scam patterns. Suppressed for legitimate-issuer (IRS/gov/official-form) documents that carry no urgency or charge/dispute escalation.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://netcdn.tw/app/406889139/coin-master-daily-free-spins-link-today-blog-game-hack
    • http://opac.acehresearch.org/repository/free-coin-master-links_GM406889139.pdf
    • http://opac.acehresearch.org/repository/free-coin-master-account_GM406889139.pdf
    • http://opac.acehresearch.org/repository/coin-master-apk-hack-2021_GM406889139.pdf
    • http://opac.acehresearch.org/repository/free-links-for-coin-master_GM406889139.pdf
    • http://opac.acehresearch.org/repository/free-roblox-youtube_GM431946152.pdf
    • http://opac.acehresearch.org/repository/easy-robux-today-com_GM431946152.pdf
    • http://opac.acehresearch.org/repository/titan-hack-roblox_GM431946152.pdf
    • http://opac.acehresearch.org/repository/roblox-a_GM431946152.pdf
    • http://opac.acehresearch.org/repository/coin-master-rewards-free-spins_GM406889139.pdf
    • http://opac.acehresearch.org/repository/roblox-free-online-game_GM431946152.pdf
    • http://opac.acehresearch.org/repository/how-to-hack-roblox-accounts-on-phone-2021_GM431946152.pdf
    • http://opac.acehresearch.org/repository/hack-roblox-players_GM431946152.pdf
    • http://opac.acehresearch.org/repository/free-spins-on-coin-master_GM406889139.pdf
    • http://opac.acehresearch.org/repository/free-accessories-roblox_GM431946152.pdf
    • http://opac.acehresearch.org/repository/how-to-hack-to-get-robux_GM431946152.pdf
    • http://opac.acehresearch.org/repository/how-to-hack-roblox-games_GM431946152.pdf
    • http://opac.acehresearch.org/repository/tiktok-free-movie-hack_GM835599320.pdf
    • http://opac.acehresearch.org/repository/coin-master-free-spins-whatsapp-link_GM406889139.pdf
    • http://opac.acehresearch.org/repository/roblox-obbys-that-give-you-free-robux_GM431946152.pdf
    • http://opac.acehresearch.org/repository/coin-master-free-spins-link-2021_GM406889139.pdf
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000030c1.bin
7928103cc8616b960d3ce88cd70d695cce373f97134246c778a4e05007f4d3a3
pdf-font-stream PDF embedded font (sfnt) at offset 0x30C1 21788 bytes
font_01_sfnt_off000060ad.bin
09b1cdc1283068c485bfced7c85533ce23b9c20e7767d1eac4088bba3ec2de37
pdf-font-stream PDF embedded font (sfnt) at offset 0x60AD 19156 bytes