Malicious PDF — malware analysis report

Static analysis result for SHA-256 825afd7a76bb87e3…

MALICIOUS

PDF

46.0 KB Created: 2021-05-13 16:51:03 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: d0d366d9f2c78b127cad66c6778e8714 SHA-1: eeba2280236ac4ef386a90f9313e8099656baebc SHA-256: 825afd7a76bb87e342f7237659dcbbcf4285ef092c65549733a3aab71b7c3923
102 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

This PDF document is classified as malicious by an ML model and contains multiple embedded URLs pointing to potentially malicious content. The document body explicitly requests sensitive recovery secrets or private keys, indicating a phishing or credential harvesting attempt. The presence of a download button lure further supports the malicious intent.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9432

Heuristics 4

  • Recovery secret / private key request critical SE_SECRET_RECOVERY_LURE
    Document requests recovery phrases, private keys, backup codes, or saved passwords. Requests for these secrets in a document are high-risk.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://netcdn.xyz/app/406889139/coin-master-hack-without-verification-code-game-hack
    • http://bagliomangiapane.com/images/www-robux_GM431946152.pdf
    • http://bagliomangiapane.com/images/hack-coin-master-app-ios_GM406889139.pdf
    • http://bagliomangiapane.com/images/minecraft-hax-download-no-virus_GM479516143.pdf
    • http://bagliomangiapane.com/images/free-appsfor-coin-master-daily-rewards_GM406889139.pdf
    • http://bagliomangiapane.com/images/how-to-get-free-spins-on-coin-master-2021_GM406889139.pdf
    • http://bagliomangiapane.com/images/coin-master-hack-progamers_GM406889139.pdf
    • http://bagliomangiapane.com/images/coin-master-hack-2021_GM406889139.pdf
    • http://bagliomangiapane.com/images/lazyblox-com-free-robux_GM431946152.pdf
    • http://bagliomangiapane.com/images/free-robux-2021_GM431946152.pdf
    • http://bagliomangiapane.com/images/coin-master-free-spins-1-coin-master_GM406889139.pdf
    • http://bagliomangiapane.com/images/download-coin-master-hack-apk_GM406889139.pdf
    • http://bagliomangiapane.com/images/free-robux-without-doing-anything_GM431946152.pdf
    • http://bagliomangiapane.com/images/hacker-minecraft-song_GM479516143.pdf
    • http://bagliomangiapane.com/images/2021-no-human-verification-hack-for-coin-master_GM406889139.pdf
    • http://bagliomangiapane.com/images/roblox-robux-hack_GM431946152.pdf
    • http://bagliomangiapane.com/images/play-full-version-of-minecraft-for-free-no-download_GM479516143.pdf
    • http://bagliomangiapane.com/images/robux-free-2021_GM431946152.pdf
    • http://bagliomangiapane.com/images/coin-master-hack-android-2021_GM406889139.pdf
    • http://bagliomangiapane.com/images/free-robux-hacks-no-verification_GM431946152.pdf
    • http://bagliomangiapane.com/images/coin-master-free-spin-27_GM406889139.pdf
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_003_off0000495d.bin
f07842e094694db5a325a6155a4f984ed9ef2ea9ebad035af5051c53cebc5db7
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x495D 26088 bytes
font_01_sfnt_off0000845d.bin
6c64b2d5ed5363ca6cc07fbe34a3bfd9eea5f1aa19e3454382e4953d304576a5
pdf-font-stream PDF embedded font (sfnt) at offset 0x845D 3444 bytes
font_02_sfnt_off00009087.bin
73698aa0d04f612b8edcfc98417ef0f8be184b3e572c91f5f0109cbf791ef469
pdf-font-stream PDF embedded font (sfnt) at offset 0x9087 18528 bytes