PDF static analysis report

Static analysis result for SHA-256 9fedba15ef729dcc…

SUSPICIOUS

PDF

40.9 KB Created: 2021-05-15 12:09:06 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7) First seen: 2021-09-27
MD5: 6c74743389e38328e502303fc24543ce SHA-1: 535d648277945f2db38c01eee4cebbe287655406 SHA-256: 9fedba15ef729dcc11e01f9b1669d3d260f9163348e0581e723878b28ac14acd
42 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF document contains multiple embedded URLs and a prominent link related to "Coin Master Reward Link" and game hacks, strongly suggesting a lure for phishing or malware distribution. The ML classifier also flagged this PDF as malicious with high confidence. No scripts were extracted, but the presence of external URIs indicates an attempt to redirect the user to a potentially malicious site.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9971

Heuristics 3

  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://netcdn.xyz/app/406889139/coin-master-reward-link-game-hack PDF link annotation
    • http://huananhai.net/images/how-to-hack-robux_GM431946152.pdfIn PDF document text
    • http://huananhai.net/images/robux-hack-free-robux_GM431946152.pdfIn PDF document text
    • http://huananhai.net/images/minecraft-free-download-windows-10_GM479516143.pdfIn PDF document text
    • http://huananhai.net/images/free-spin-coin-master-hacktoman_GM406889139.pdfIn PDF document text
    • http://huananhai.net/images/how-to-hack-roblox_GM431946152.pdfIn PDF document text
    • http://huananhai.net/images/how-to-hack-coin-master-with-game-guardian_GM406889139.pdfIn PDF document text
    • http://huananhai.net/images/free-robux-generator-no-human-verification-or-surveys_GM431946152.pdfIn PDF document text
    • http://huananhai.net/images/how-to-get-free-robux-no-human-verification-2021_GM431946152.pdfIn PDF document text
    • http://huananhai.net/images/free-robux-for-kids_GM431946152.pdfIn PDF document text
    • http://huananhai.net/images/free-spins-for-coin-master-2021_GM406889139.pdfIn PDF document text
    • http://huananhai.net/images/coin-master-free-spins-link-blogspot-today_GM406889139.pdfIn PDF document text
    • http://huananhai.net/images/coin-master-unlimited-spin-link_GM406889139.pdfIn PDF document text
    • http://huananhai.net/images/free-spins-and-coins-coin-master-facebook_GM406889139.pdfIn PDF document text
    • http://huananhai.net/images/coin-master-game-free_GM406889139.pdfIn PDF document text
    • http://huananhai.net/images/minecraft-pe-hacks-2021_GM479516143.pdfIn PDF document text
    • http://huananhai.net/images/bux-gg-robux-free_GM431946152.pdfIn PDF document text
    • http://huananhai.net/images/coin-master-hack-unlimited-spins-apk-download_GM406889139.pdfIn PDF document text
    • http://huananhai.net/images/how-to-get-free-robux-app_GM431946152.pdfIn PDF document text
    • http://huananhai.net/images/coin-master-free-spins-1701-20_GM406889139.pdfIn PDF document text
    • http://huananhai.net/images/coin-master-spin-link-free_GM406889139.pdfIn PDF document text
    • http://en.wikipedia.org/wiki/MIT_LicenseIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_003_off00004720.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x4720 23980 bytes
SHA-256: b1113a1bae8f8984799c69b1c0f81dfa947d1fe4e1e3d8ca1c146e56860e7507
font_01_sfnt_off00007dcb.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x7DCB 18056 bytes
SHA-256: c2793d17727503817a30064ba8beed92adc1bd6ab198ac538296771cbb61b552