Malicious PDF — malware analysis report

Static analysis result for SHA-256 b5d8ac85fbd7fe40…

MALICIOUS

PDF

37.1 KB Created: 2021-05-22 21:12:12 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: 3b260a7cce8ee757be3a63ffc4d2c0a0 SHA-1: 30ce55c876c24f0166d93f0a0182a1028a348af4 SHA-256: b5d8ac85fbd7fe40f65a44d3fa049f45efedad533d7ec1313417411ba43f568e
82 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious File

The PDF document contains embedded URLs and text that mimic a download lure for a "Minecraft" game hack. The 'SE_CLICKFIX' heuristic indicates the document likely instructs the user to execute a command, a common social engineering tactic to bypass security measures. The presence of multiple suspicious URLs suggests the document is designed to redirect users to malicious sites for further payload delivery.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9447

Heuristics 4

  • ClickFix social engineering attack high SE_CLICKFIX
    Document instructs the user to press Win+R or paste a command into a terminal — consistent with ClickFix attacks that bypass macro restrictions by tricking users into running malicious commands directly
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://netcdn.xyz/app/479516143/minecraft-free-download-chromebook-game-hack
    • http://carmen-duran.com/images/how-to-get-minecraft-for-free-on-xbox-one_GM479516143.pdf
    • http://carmen-duran.com/images/minecraft-free-android_GM479516143.pdf
    • http://carmen-duran.com/images/coin-master-daily-free-spins-link-app_GM406889139.pdf
    • http://carmen-duran.com/images/coin-master-free-spons-apk-2021_GM406889139.pdf
    • http://carmen-duran.com/images/coin-master-hack-without-verification-code_GM406889139.pdf
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00003624.bin
95a3412eafac39a99ecf8c91b6e5f5e3ccfc95763376312ef0b940b51ff84dd3
pdf-font-stream PDF embedded font (sfnt) at offset 0x3624 24764 bytes
font_01_sfnt_off00006d7d.bin
5dd9560c2144c6e0c163b4f028c4225137fae20b1a5cdfb52854f5b1068f3385
pdf-font-stream PDF embedded font (sfnt) at offset 0x6D7D 19044 bytes