Malicious PDF — malware analysis report

Static analysis result for SHA-256 84609a51a4fe8986…

MALICIOUS

PDF

44.1 KB Created: 2021-05-16 18:55:03 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: 0ec369645a9723ff9033086953fbd202 SHA-1: ad4e709cf30c4daf9325342ca9f65373d813e8b1 SHA-256: 84609a51a4fe8986a66ca6775462ca69a6e8abcb7ad8c4f468e7aa5ef8c2ab57
102 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF document contains a large number of external links, many of which are SEO-optimized and point to other PDF files, suggesting a link farm or content-spinning operation. The primary URL, https://netcdn.xyz/app/406889139/coin-master-spins-gratis-game-hack, and numerous others hosted on jdlrelocation.com, are likely used to distribute malicious content or facilitate scams related to games like Coin Master and Roblox. The ML classifier also flagged this PDF as malicious with high confidence.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9648

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://netcdn.xyz/app/406889139/coin-master-spins-gratis-game-hack
    • http://jdlrelocation.com/images/you-promised-my-son-free-robux_GM431946152.pdf
    • http://jdlrelocation.com/images/roblox-game-free-download_GM431946152.pdf
    • http://jdlrelocation.com/images/free-robux-2021-no-human-verification_GM431946152.pdf
    • http://jdlrelocation.com/images/how-to-get-coin-master-free-spin-link_GM406889139.pdf
    • http://jdlrelocation.com/images/gaming-dunia-coin-master-free-spins_GM406889139.pdf
    • http://jdlrelocation.com/images/free-robux-no-verification-no-download_GM431946152.pdf
    • http://jdlrelocation.com/images/how-to-get-hacks-on-minecraft_GM479516143.pdf
    • http://jdlrelocation.com/images/how-to-make-your-own-minecraft-pe-server-for-free_GM479516143.pdf
    • http://jdlrelocation.com/images/como-hackear-coin-master-2021_GM406889139.pdf
    • http://jdlrelocation.com/images/coin-master-website_GM406889139.pdf
    • http://jdlrelocation.com/images/how-to-hack-any-roblox-account_GM431946152.pdf
    • http://jdlrelocation.com/images/does-coin-master-hack-work_GM406889139.pdf
    • http://jdlrelocation.com/images/coin-master-free-spins-link-today-facebook_GM406889139.pdf
    • http://jdlrelocation.com/images/real-free-robux-codes_GM431946152.pdf
    • http://jdlrelocation.com/images/blox-best-robux_GM431946152.pdf
    • http://jdlrelocation.com/images/free-robux-2021_GM431946152.pdf
    • http://jdlrelocation.com/images/how-to-get-free-coins-on-coin-master_GM406889139.pdf
    • http://jdlrelocation.com/images/how-to-get-free-spins-on-coin-master-2021_GM406889139.pdf
    • http://jdlrelocation.com/images/how-to-get-minecraft-for-free-on-xbox-one_GM479516143.pdf
    • http://jdlrelocation.com/images/how-do-you-get-free-robux-2021_GM431946152.pdf
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_003_off00004935.bin
f175f8f0d2628a235423ad0d239dde8bc05c3d7f199081747a902e826165fafa
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x4935 24512 bytes
font_01_sfnt_off0000816e.bin
3fb127b764b9d10f5525bc4de5ec8316de704409ccb0cf21cff3ad8a30d11676
pdf-font-stream PDF embedded font (sfnt) at offset 0x816E 2840 bytes
font_02_sfnt_off00008b1f.bin
14ee5d8b12066898ac0dd126fd621bcbe737ddb1f68eadc349fa8e2a98ba3f20
pdf-font-stream PDF embedded font (sfnt) at offset 0x8B1F 17724 bytes