Malicious PDF — malware analysis report

Static analysis result for SHA-256 c37dc8040bd07b63…

MALICIOUS

PDF

45.5 KB Created: 2021-05-17 20:54:10 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: 5154f6b6d64c246fee6c9533b9cd416f SHA-1: 1f18a69fbbc381fc7151dd04263fa71d901ae9a2 SHA-256: c37dc8040bd07b639f0b1b5717ff302d2060874fd583c46e4a7e6a3e656b9c62
102 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains numerous embedded links, identified as a link farm, pointing to sites offering game hacks and free currency for popular games like Coin Master and Roblox. The ML classifier strongly indicated maliciousness, and the presence of external URIs suggests a redirection to potentially malicious content or phishing pages. Although no scripts were explicitly extracted, the PDF structure and embedded links are indicative of a lure to download further malicious content or visit a compromised site.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9507

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://netcdn.xyz/app/406889139/easy-free-spins-coin-master-game-hack
    • https://www.alloywheels.in/uploaded_files/userfiles/files/how-to-get-free-robux-games_GM431946152.pdf
    • https://www.alloywheels.in/uploaded_files/userfiles/files/robux-gift-card-free_GM431946152.pdf
    • https://www.alloywheels.in/uploaded_files/userfiles/files/how-many-levels-does-coin-master-have_GM406889139.pdf
    • https://www.alloywheels.in/uploaded_files/userfiles/files/minecraft-java-edition-free-trial_GM479516143.pdf
    • https://www.alloywheels.in/uploaded_files/userfiles/files/free-spins-on-coin-master-2021_GM406889139.pdf
    • https://www.alloywheels.in/uploaded_files/userfiles/files/safe-hack-for-coin-master-android_GM406889139.pdf
    • https://www.alloywheels.in/uploaded_files/userfiles/files/scaffold-minecraft-hack_GM479516143.pdf
    • https://www.alloywheels.in/uploaded_files/userfiles/files/minecraft-windows-10-free-with-java_GM479516143.pdf
    • https://www.alloywheels.in/uploaded_files/userfiles/files/minecraft-for-macbook-free_GM479516143.pdf
    • https://www.alloywheels.in/uploaded_files/userfiles/files/free-roblox-followers_GM431946152.pdf
    • https://www.alloywheels.in/uploaded_files/userfiles/files/fighting-free-card-coin-master_GM406889139.pdf
    • https://www.alloywheels.in/uploaded_files/userfiles/files/coin-master-app_GM406889139.pdf
    • https://www.alloywheels.in/uploaded_files/userfiles/files/minecraft-dungeons-free-download-pc_GM479516143.pdf
    • https://www.alloywheels.in/uploaded_files/userfiles/files/coin-master-jackpot-madness-hack_GM406889139.pdf
    • https://www.alloywheels.in/uploaded_files/userfiles/files/free-coins-coin-master-2021_GM406889139.pdf
    • https://www.alloywheels.in/uploaded_files/userfiles/files/free-robux-mod_GM431946152.pdf
    • https://www.alloywheels.in/uploaded_files/userfiles/files/how-to-host-a-minecraft-server-for-free_GM479516143.pdf
    • https://www.alloywheels.in/uploaded_files/userfiles/files/coin-master-free-spins-link-today-2021_GM406889139.pdf
    • https://www.alloywheels.in/uploaded_files/userfiles/files/minecraft-free-download-no-virus_GM479516143.pdf
    • https://www.alloywheels.in/uploaded_files/userfiles/files/free-robux-app-real_GM431946152.pdf
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_003_off00004cfd.bin
c6c9cf79284c7fa4c2c0088efabb48ac843ae4ca0872e5410718ebecc7a13a06
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x4CFD 24900 bytes
font_01_sfnt_off00008561.bin
2b5bcb60036e8604cee537a76a0c1d845177aa2c28f1eb7ce8b27015c89bb61f
pdf-font-stream PDF embedded font (sfnt) at offset 0x8561 18068 bytes
font_02_sfnt_off0000a6b5.bin
e32c06502c11b52acb5e814091c5fdbffd1e2a904ac7a9cfb8b5b180bd139088
pdf-font-stream PDF embedded font (sfnt) at offset 0xA6B5 3264 bytes