Malicious PDF — malware analysis report

Static analysis result for SHA-256 9ea765180b0ab1a9…

MALICIOUS

PDF

42.3 KB Created: 2021-05-14 02:08:00 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: 545be0c215806e95f4454633bec2436e SHA-1: 41533210ebfdc89c3f66246c324451e1dfd8aab8 SHA-256: 9ea765180b0ab1a9e4eb9821255530d47176327043b636df15c302ff1cd2ea9d
62 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The document's content and embedded URLs suggest a social engineering lure to download potentially malicious files, disguised as game hacks or cheats. The ML classifier strongly flagged this PDF as malicious, and the presence of numerous suspicious URLs reinforces this assessment. While no scripts were directly extracted, the PDF structure and embedded URIs indicate an attempt to redirect the user to external resources for downloading further payloads.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9971

Heuristics 4

  • Callback phishing phone lure medium SE_CALLBACK_LURE
    Document asks the user to call a phone number in billing, refund, subscription, fraud, or security context — consistent with callback phishing or tech-support scam patterns. Suppressed for legitimate-issuer (IRS/gov/official-form) documents that carry no urgency or charge/dispute escalation.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://netcdn.xyz/app/406889139/download-hacked-games-coin-master-game-hack
    • http://rlsaluminios.com.pt/images/minecraft-linux-free_GM479516143.pdf
    • http://rlsaluminios.com.pt/images/how-to-get-free-spins-on-coin-master-android_GM406889139.pdf
    • http://rlsaluminios.com.pt/images/free-texture-packs-for-minecraft-pe_GM479516143.pdf
    • http://rlsaluminios.com.pt/images/free-robux-no-offers_GM431946152.pdf
    • http://rlsaluminios.com.pt/images/hack-download_GM431946152.pdf
    • http://rlsaluminios.com.pt/images/how-to-hack-roblox-accounts-on-phone-2021_GM431946152.pdf
    • http://rlsaluminios.com.pt/images/can-you-get-free-robux-on-roblox_GM431946152.pdf
    • http://rlsaluminios.com.pt/images/how-to-hack-and-get-free-robux_GM431946152.pdf
    • http://rlsaluminios.com.pt/images/www-coin-master-hack-tk_GM406889139.pdf
    • http://rlsaluminios.com.pt/images/free-robux-easy-and-fast_GM431946152.pdf
    • http://rlsaluminios.com.pt/images/how-many-levels-in-coin-master_GM406889139.pdf
    • http://rlsaluminios.com.pt/images/coin-master-free-2021-spin-link_GM406889139.pdf
    • http://rlsaluminios.com.pt/images/how-to-hack-roblox-jailbreak_GM431946152.pdf
    • http://rlsaluminios.com.pt/images/how-to-get-free-robux-hack-2021_GM431946152.pdf
    • http://rlsaluminios.com.pt/images/minecraft-complete-handbook_GM479516143.pdf
    • http://rlsaluminios.com.pt/images/free-robux-pins_GM431946152.pdf
    • http://rlsaluminios.com.pt/images/free-robux-codes_GM431946152.pdf
    • http://rlsaluminios.com.pt/images/coin-master-hack-spins_GM406889139.pdf
    • http://rlsaluminios.com.pt/images/coin-master-spin-ml_GM406889139.pdf
    • http://rlsaluminios.com.pt/images/clean-master-free-coins-and-spins_GM406889139.pdf
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_003_off000048ff.bin
ac2cf07a31c699aadcfbc17fde6da356d51cd40663b64ead39f1961882f030f0
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x48FF 25064 bytes
font_01_sfnt_off000081fa.bin
872856dc36b7d0cde2667ea9daae6868ef6ed6eada75fea978a440faa6a0cafa
pdf-font-stream PDF embedded font (sfnt) at offset 0x81FA 18556 bytes