Malicious PDF — malware analysis report

Static analysis result for SHA-256 ae5bf997da04949b…

MALICIOUS

PDF

44.4 KB Created: 2021-05-16 17:25:17 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: 4c896a41234d5ed9a1e343b05d26d1a9 SHA-1: b902c3d015ef5da9a60e04d2ea9b9447eb2f9368 SHA-256: ae5bf997da04949b3bb9f39c737dbf16ff2173da286dc71176416565e2a8ddbe
82 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The document presents a fake CAPTCHA or human verification prompt to trick the user into clicking a link. This is a common lure for phishing or to download a second-stage payload. The embedded URLs point to resources related to game hacks and rewards, reinforcing the social engineering aspect.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9632

Heuristics 4

  • Fake CAPTCHA / human verification prompt high SE_FAKE_CAPTCHA
    Document displays a fake CAPTCHA or human-verification prompt — used to trick users into running commands or pressing keyboard shortcuts
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://netcdn.xyz/app/406889139/coin-master-reward-link-2021-game-hack
    • http://warehousewestllc.com/images/roblox-verification_GM431946152.pdf
    • http://warehousewestllc.com/images/free-spins-on-coin-master-link_GM406889139.pdf
    • http://warehousewestllc.com/images/roblox-hack-site_GM431946152.pdf
    • http://warehousewestllc.com/images/coin-master-free-spins-twitter_GM406889139.pdf
    • http://warehousewestllc.com/images/coin-master-hacks-2021_GM406889139.pdf
    • http://warehousewestllc.com/images/free-robux-games-on-roblox_GM431946152.pdf
    • http://warehousewestllc.com/images/how-do-you-earn-robux_GM431946152.pdf
    • http://warehousewestllc.com/images/hack-coin-master-download-ios_GM406889139.pdf
    • http://warehousewestllc.com/images/free-robux-with-no-verification-2021_GM431946152.pdf
    • http://warehousewestllc.com/images/free-robux-on-phone_GM431946152.pdf
    • http://warehousewestllc.com/images/freecoins_GM406889139.pdf
    • http://warehousewestllc.com/images/coin-master-new-cards-hack_GM406889139.pdf
    • http://warehousewestllc.com/images/coin-master-links-for-today_GM406889139.pdf
    • http://warehousewestllc.com/images/roblox-hack-apk_GM431946152.pdf
    • http://warehousewestllc.com/images/80-free-spins-coin-master_GM406889139.pdf
    • http://warehousewestllc.com/images/roblox-free-bundles_GM431946152.pdf
    • http://warehousewestllc.com/images/free-roblox-avatar_GM431946152.pdf
    • http://warehousewestllc.com/images/60-free-spins-coin-master_GM406889139.pdf
    • http://warehousewestllc.com/images/coin-master_GM406889139.pdf
    • http://warehousewestllc.com/images/robux-app_GM431946152.pdf
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_003_off0000484a.bin
4bcb65f6ec4d4b3118d0ac26c8d9766ae8397b6fc993914555d205634df481ff
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x484A 24548 bytes
font_01_sfnt_off00008056.bin
381f6d859be141449dd645f7be1484d2a1cf49218dc471b402dae69eaa2b11d5
pdf-font-stream PDF embedded font (sfnt) at offset 0x8056 2824 bytes
font_02_sfnt_off000089f9.bin
6040a5d317e0c15c3b91341419c6951bd8a72d731c40e3937b88b452a10d0332
pdf-font-stream PDF embedded font (sfnt) at offset 0x89F9 18456 bytes