Malicious PDF — malware analysis report

Static analysis result for SHA-256 95f14647b8c503c0…

MALICIOUS

PDF

45.7 KB Created: 2021-05-12 06:33:50 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: cb5b2e6d16f9283def55ef42f4a71340 SHA-1: 6fe85494e01d763e02cd52ca740421a8bdbc548b SHA-256: 95f14647b8c503c06838067ce93a3b70bbbd48b2d595e78e5a3d52a4ca77933c
62 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF document contains embedded URLs and a visual lure suggesting a download, aiming to trick the user into downloading a malicious application. The ML classifier strongly flagged this PDF as malicious, and the presence of multiple external links reinforces the malicious intent. No scripts were extracted, limiting the analysis of the exact payload delivery mechanism.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9507

Heuristics 4

  • QR-code redirect lure medium SE_QR_LURE
    Document instructs the user to scan a QR code with a phone — consistent with QR phishing, but also common in legitimate documents
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://netcdn.xyz/app/479516143/minecraft-pocket-apk-game-hack
    • http://library.stikessuakainsan.ac.id/repository/free-spins-coin-master-links_GM406889139.pdf
    • http://library.stikessuakainsan.ac.id//repository/master-coin-free_GM406889139.pdf
    • http://library.stikessuakainsan.ac.id/repository/download-hacked-games-coin-master_GM406889139.pdf
    • http://library.stikessuakainsan.ac.id//repository/orewards-com-free-robux_GM431946152.pdf
    • http://library.stikessuakainsan.ac.id//repository/cm-spin-link_GM406889139.pdf
    • http://library.stikessuakainsan.ac.id/repository/minecraft-classic-free_GM479516143.pdf
    • http://library.stikessuakainsan.ac.id/repository/free-robux-apps-that-work_GM431946152.pdf
    • http://library.stikessuakainsan.ac.id/repository/free-robux-on-phone_GM431946152.pdf
    • http://library.stikessuakainsan.ac.id/repository/free-spins-coin-master-2021_GM406889139.pdf
    • http://library.stikessuakainsan.ac.id/repository/coin-master-hack-without-verification-2021_GM406889139.pdf
    • http://library.stikessuakainsan.ac.id//repository/robux-generators-that-actually-work_GM431946152.pdf
    • http://library.stikessuakainsan.ac.id//repository/robux-hack-free-robux_GM431946152.pdf
    • http://library.stikessuakainsan.ac.id//repository/new-free-money-links-coin-master_GM406889139.pdf
    • http://library.stikessuakainsan.ac.id/repository/free-coin-spin-daily-link-coin-master_GM406889139.pdf
    • http://library.stikessuakainsan.ac.id//repository/free-robux-generator-no-human-verification-2021_GM431946152.pdf
    • http://library.stikessuakainsan.ac.id//repository/how-to-get-free-clothes-on-roblox-2021_GM431946152.pdf
    • http://library.stikessuakainsan.ac.id/repository/hack-the-game-coin-master_GM406889139.pdf
    • http://library.stikessuakainsan.ac.id/repository/coin-master-official-website_GM406889139.pdf
    • http://library.stikessuakainsan.ac.id//repository/coin-master-free-spin-link-list_GM406889139.pdf
    • http://library.stikessuakainsan.ac.id/repository/how-to-get-free-coins-in-coin-master_GM406889139.pdf
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_003_off00004bb2.bin
48726f0eabbaf8cac76ad0dd568d5d389cd5acc30672dd4820072b49ed285a45
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x4BB2 25964 bytes
font_01_sfnt_off00008680.bin
10d025f04f706eb71cdda4f99784df1b9ccb52e48080e43095e0398eaef6f132
pdf-font-stream PDF embedded font (sfnt) at offset 0x8680 2880 bytes
font_02_sfnt_off0000906a.bin
43fabaa7baa2069dea089d396f6a12271a87df7a231cffc83c7f5458ac3d8eee
pdf-font-stream PDF embedded font (sfnt) at offset 0x906A 18208 bytes