Malicious PDF — malware analysis report

Static analysis result for SHA-256 bcdc294405c89a8c…

MALICIOUS

PDF

49.7 KB Created: 2021-05-14 05:06:40 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: 5c858656f9ecc06a14663ab801f5be1a SHA-1: 241a689bfd948528272a2fa9ae6174771a6bbe49 SHA-256: bcdc294405c89a8cdf78f269deefd3fe7bf0ae31a51c08045397534984b7f908
102 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF file contains a large number of embedded URLs, many of which point to pages offering game-related cheats and free items, suggesting a lure for users. The heuristic 'PDF_SEO_LINK_FARM' indicates a mass of external links, and the ML classifier flagged the PDF as malicious. While no scripts were explicitly extracted, the presence of numerous external links and the nature of the lures suggest an attempt to redirect users to malicious content, potentially for credential harvesting or malware delivery.

Machine Learning

  • Nyx PDF Classifier malicious score 0.8642

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://netcdn.xyz/app/406889139/fbchampion-game-hack
    • https://abouttimetech.com/images/free-coins-coin-master-link_GM406889139.pdf
    • https://abouttimetech.com/images/how-to-get-free-robux-without-verifying_GM431946152.pdf
    • https://abouttimetech.com/images/free-robux-on-ipad_GM431946152.pdf
    • https://abouttimetech.com/images/coin-master-free-spins-app-for-iphone_GM406889139.pdf
    • https://abouttimetech.com/images/free-spins-on-coin-master-game_GM406889139.pdf
    • https://abouttimetech.com/images/roblox-free-clothes-hack_GM431946152.pdf
    • https://abouttimetech.com/images/coin-master-spin-and-coins-free_GM406889139.pdf
    • https://abouttimetech.com/images/how-to-coin-master-hack_GM406889139.pdf
    • https://abouttimetech.com/images/google-how-do-you-get-free-robux_GM431946152.pdf
    • https://abouttimetech.com/images/coin-master-free-spin-trick_GM406889139.pdf
    • https://abouttimetech.com/images/daily-free-spin-link-in-coin-master_GM406889139.pdf
    • https://abouttimetech.com/images/free-spins-coin-master-links-2021_GM406889139.pdf
    • https://abouttimetech.com/images/rbx-gg-free-robux_GM431946152.pdf
    • https://abouttimetech.com/images/hack-coin-master-spin-apk_GM406889139.pdf
    • https://abouttimetech.com/images/coin-master-free-coins-no-human-verification_GM406889139.pdf
    • https://abouttimetech.com/images/free-spins-coin-master-hack_GM406889139.pdf
    • https://abouttimetech.com/images/robux-hack-2021_GM431946152.pdf
    • https://abouttimetech.com/images/free-minecraft-packs_GM479516143.pdf
    • https://abouttimetech.com/images/get-free-robux-com_GM431946152.pdf
    • https://abouttimetech.com/images/hack-de-coin-master_GM406889139.pdf
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_003_off000048db.bin
60483d1aeed52b179865c9006ac9ccbc3448070c565b160be9e67c8c0ca03ff5
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x48DB 29868 bytes
font_01_sfnt_off00008859.bin
a17c2a746d49ac23b23e38a371e32fddecfcd91b10cf42ff6155bff6b8a07e91
pdf-font-stream PDF embedded font (sfnt) at offset 0x8859 4028 bytes
font_02_sfnt_off000095fa.bin
6fd7c7f447d66842f81aa8cf197935b17f22157d0c7e9f95622df1b5b4ddf530
pdf-font-stream PDF embedded font (sfnt) at offset 0x95FA 2788 bytes
font_03_sfnt_off00009fea.bin
a6b0af27d4d3b45433f1bf9322c4fc5530f0836706fea914cb1eef9ee3408c10
pdf-font-stream PDF embedded font (sfnt) at offset 0x9FEA 18364 bytes