Malicious PDF — malware analysis report

Static analysis result for SHA-256 cd8a385f50aa834c…

MALICIOUS

PDF

42.6 KB Created: 2021-05-15 13:49:21 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: e361ccf6bd0e1d22385acd87a7d9823c SHA-1: d78a522dbb9921cf55089c2a96e7e9f5d2dba6df SHA-256: cd8a385f50aa834c374587989c08d806cbe442852f5af69ba1e13e60d7e4b887
102 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF document contains a large number of embedded links, forming a link farm, that point to sites offering free in-game currency or game downloads. The document body and extracted URLs suggest a lure for popular games like Robux and Coin Master, likely to trick users into visiting malicious sites or downloading further malware. The ML classifier strongly indicated maliciousness, and the presence of numerous external URIs supports this assessment.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9971

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://netcdn.xyz/app/431946152/how-to-get-free-robux-games-game-hack
    • http://huounaixunghe.com/images/free-robux-2021-no-human-verification_GM431946152.pdf
    • http://huounaixunghe.com/images/coin-master-mod-free-download_GM406889139.pdf
    • http://huounaixunghe.com/images/how-to-change-roblox-username-for-free-2021_GM431946152.pdf
    • http://huounaixunghe.com/images/coin-master-free-spins-uk_GM406889139.pdf
    • http://huounaixunghe.com/images/free-spins-on-coin-master-game_GM406889139.pdf
    • http://huounaixunghe.com/images/minecraft-free-download-apk-softonic_GM479516143.pdf
    • http://huounaixunghe.com/images/coin-master-game-free-spin-download_GM406889139.pdf
    • http://huounaixunghe.com/images/coin-master-promo-code-2021_GM406889139.pdf
    • http://huounaixunghe.com/images/coin-master-hack-version-33-2_GM406889139.pdf
    • http://huounaixunghe.com/images/free-minecraft-domain_GM479516143.pdf
    • http://huounaixunghe.com/images/i-need-robux_GM431946152.pdf
    • http://huounaixunghe.com/images/robux-earning-sites_GM431946152.pdf
    • http://huounaixunghe.com/images/free-spins-coin-master-2021_GM406889139.pdf
    • http://huounaixunghe.com/images/coin-master-hacks-2021_GM406889139.pdf
    • http://huounaixunghe.com/images/how-to-get-free-robux-without-paying_GM431946152.pdf
    • http://huounaixunghe.com/images/how-to-get-robux-easy_GM431946152.pdf
    • http://huounaixunghe.com/images/free-robux-place_GM431946152.pdf
    • http://huounaixunghe.com/images/free-robux-promo-codes_GM431946152.pdf
    • http://huounaixunghe.com/images/free-spins-for-coin-master-game_GM406889139.pdf
    • http://huounaixunghe.com/images/online-coin-master-hack-here_GM406889139.pdf
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_003_off00004a6e.bin
83b9c5f4b16c4f8e32730557ddd875f1610078116071b7548b8edbfb43192169
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x4A6E 24456 bytes
font_01_sfnt_off000082ac.bin
f0658a260a8345a08039bbf50682235c712e1d6bfd9b3eebd82ad720f29012b5
pdf-font-stream PDF embedded font (sfnt) at offset 0x82AC 18768 bytes