Malicious PDF — malware analysis report

Static analysis result for SHA-256 a9f1aa8bffd0745e…

MALICIOUS

PDF

43.0 KB Created: 2021-06-03 13:26:02 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: 266a59df45fb74c0c4e2e6b8c6315cf8 SHA-1: 9a5e5155b93195550997d3e994a625b4a2cbd4c5 SHA-256: a9f1aa8bffd0745e19ec263fd28e5699483551eab4735388db045c2d8edbcaa2
62 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1203 Exploitation for Client Execution

The PDF document contains multiple embedded URLs and a document body that promises free in-game currency for popular games like Coin Master and Roblox. The presence of a ML classifier firing and external URI heuristics strongly suggests malicious intent, likely to trick users into downloading malware or visiting phishing sites. No scripts were extracted from this sample, but the overall pattern indicates a lure for potentially harmful downloads.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9874

Heuristics 4

  • Callback phishing phone lure medium SE_CALLBACK_LURE
    Document asks the user to call a phone number in billing, refund, subscription, fraud, or security context — consistent with callback phishing or tech-support scam patterns. Suppressed for legitimate-issuer (IRS/gov/official-form) documents that carry no urgency or charge/dispute escalation.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://netcdn.online/app/406889139/how-to-earn-free-stars-on-coin-master-game-hack
    • http://otomasi.stikesmuhgombong.ac.id/repository/free-games-like-coin-master_GM406889139.pdf
    • http://otomasi.stikesmuhgombong.ac.id/repository/play-games-for-robux_GM431946152.pdf
    • http://otomasi.stikesmuhgombong.ac.id/repository/free-minecraft-alt-accounts_GM479516143.pdf
    • http://otomasi.stikesmuhgombong.ac.id//repository/how-to-get-minecraft-for-free-on-phone_GM479516143.pdf
    • http://otomasi.stikesmuhgombong.ac.id/repository/coin-master-free-gifts_GM406889139.pdf
    • http://otomasi.stikesmuhgombong.ac.id//repository/free-spins-and-coins-for-coin-master-game_GM406889139.pdf
    • http://otomasi.stikesmuhgombong.ac.id/repository/how-to-become-a-hacker-in-roblox_GM431946152.pdf
    • http://otomasi.stikesmuhgombong.ac.id/repository/hack-coin-master-spin-apk_GM406889139.pdf
    • http://otomasi.stikesmuhgombong.ac.id/repository/cm-free-spins_GM406889139.pdf
    • http://otomasi.stikesmuhgombong.ac.id//repository/coin-master-hack-2021-android_GM406889139.pdf
    • http://otomasi.stikesmuhgombong.ac.id//repository/coin-master-cards-hack_GM406889139.pdf
    • http://otomasi.stikesmuhgombong.ac.id/repository/coin-master-fun-hack-online_GM406889139.pdf
    • http://otomasi.stikesmuhgombong.ac.id/repository/coin-master-mod-version-free-download-2021_GM406889139.pdf
    • http://otomasi.stikesmuhgombong.ac.id//repository/is-there-a-way-to-get-free-tiktok-followers_GM835599320.pdf
    • http://otomasi.stikesmuhgombong.ac.id/repository/pubg-uc-94fbr_GM1330123889.pdf
    • http://otomasi.stikesmuhgombong.ac.id//repository/inappropriate-roblox-games-2021_GM431946152.pdf
    • http://otomasi.stikesmuhgombong.ac.id/repository/free-robux-codes-not-used_GM431946152.pdf
    • http://otomasi.stikesmuhgombong.ac.id/repository/hack-xp-net-coin-master_GM406889139.pdf
    • http://otomasi.stikesmuhgombong.ac.id//repository/robux-money_GM431946152.pdf
    • http://otomasi.stikesmuhgombong.ac.id//repository/minecraft-esp_GM479516143.pdf
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_004_off00004faf.bin
2f6650344ca4b5ebad53c6d1dedd530b49bde0b89507fe09b9036806e1bb85ae
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x4FAF 24316 bytes
font_01_sfnt_off000086a4.bin
0709ca684ad5453d4a1c2d42e2fc6702b99f6275411c4f1e468931145e99bc4e
pdf-font-stream PDF embedded font (sfnt) at offset 0x86A4 17872 bytes