Malicious PDF — malware analysis report

Static analysis result for SHA-256 cba8e3974f24bdac…

MALICIOUS

PDF

43.0 KB Created: 2021-05-12 12:08:18 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: 7a47ecaf4d55f4bb2b6248acf81b24f4 SHA-1: 6d6c9d249ac1ea5d3909ea2f922c07972d68ed28 SHA-256: cba8e3974f24bdac222fdef81a51726a756493949aba3b095b8d4c1976e1591e
102 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1203 Exploitation for Client Execution

The PDF contains numerous links to external websites, many of which are structured as SEO link farms for game cheats and hacks. The ML classifier strongly indicated maliciousness, and the presence of a download button lure suggests an attempt to trick users into visiting potentially harmful sites. The primary attack pattern is likely a phishing or scam lure to drive traffic to malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9971

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://netcdn.xyz/app/406889139/coin-master-hacks-no-human-verification-game-hack
    • https://library.pqm.co.id/repository/haktuts-coin-master-free-spins-2021_GM406889139.pdf
    • https://library.pqm.co.id/repository/daily-free-spin-coin-master-link_GM406889139.pdf
    • https://library.pqm.co.id/repository/robux-gainer_GM431946152.pdf
    • https://library.pqm.co.id/repository/grab-points-login_GM431946152.pdf
    • https://library.pqm.co.id/repository/coin-master-hack-mod_GM406889139.pdf
    • https://library.pqm.co.id/repository/how-do-you-get-free-roblox_GM431946152.pdf
    • https://library.pqm.co.id/repository/coin-master-free-spins-promo-code_GM406889139.pdf
    • https://library.pqm.co.id/repository/coin-master-hack-apk-2021-ios_GM406889139.pdf
    • https://library.pqm.co.id/repository/how-to-hack-into-someones-roblox-account_GM431946152.pdf
    • https://library.pqm.co.id/repository/free-coin-and-spin-for-coin-master_GM406889139.pdf
    • https://library.pqm.co.id/repository/show-me-how-to-get-free-robux_GM431946152.pdf
    • https://library.pqm.co.id/repository/how-to-get-free-robux-easy-2021_GM431946152.pdf
    • https://library.pqm.co.id/repository/free-spin-link-coin-master-today_GM406889139.pdf
    • https://library.pqm.co.id/repository/coin-master-free-spins-links-app_GM406889139.pdf
    • https://library.pqm.co.id/repository/minecraft-xbox-one-code-free_GM479516143.pdf
    • https://library.pqm.co.id/repository/coin-master-free-spins-link-today_GM406889139.pdf
    • https://library.pqm.co.id/repository/how-do-you-get-free-robux-without-doing-anything_GM431946152.pdf
    • https://library.pqm.co.id/repository/free-robux-generator-without-verification_GM431946152.pdf
    • https://library.pqm.co.id/repository/get-free-robux-generator_GM431946152.pdf
    • https://library.pqm.co.id/repository/websites-that-give-you-free-robux_GM431946152.pdf
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_003_off00004a2d.bin
2106792ba9b516467334f553cf48db426062caffe232dc5393ac645a1fedca7d
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x4A2D 26128 bytes
font_01_sfnt_off000085e9.bin
b53d611e96a32094425b068729023046bb1db9f19d10500fe1599e8fd30759af
pdf-font-stream PDF embedded font (sfnt) at offset 0x85E9 18248 bytes