Malicious PDF — malware analysis report

Static analysis result for SHA-256 cde17202e5b3a0a3…

MALICIOUS

PDF

42.5 KB Created: 2021-05-15 10:28:59 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: dd848ad040cad23a793f6129fea92c08 SHA-1: 15c6f917dce5e7b8920deeb42369a8cdaec8b247 SHA-256: cde17202e5b3a0a3d3d4981e405c71a7acc111092bd1feebdfb810f545f543a6
142 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF document contains a "download" button lure and embeds a large number of external links, many of which point to other PDF files, suggesting a link farm or SEO abuse tactic. The document body and embedded URLs indicate a theme of offering free game hacks and cheats, likely to trick users into clicking malicious links or downloading further malware. The ML classifier also strongly flagged this PDF as malicious.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9971

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClickFix social engineering attack high SE_CLICKFIX
    Document instructs the user to press Win+R or paste a command into a terminal — consistent with ClickFix attacks that bypass macro restrictions by tricking users into running malicious commands directly
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://netcdn.xyz/app/479516143/how-to-download-minecraft-for-free-ios-game-hack
    • http://lawnn.ru/images/roblox-survey-for-robux_GM431946152.pdf
    • http://lawnn.ru/images/coin-master-free-attack-link_GM406889139.pdf
    • http://lawnn.ru/images/a-lot-of-robux_GM431946152.pdf
    • http://lawnn.ru/images/coin-master-free-spins-2021-hack_GM406889139.pdf
    • http://lawnn.ru/images/windows-10-minecraft-hacks_GM479516143.pdf
    • http://lawnn.ru/images/coin-master-free-spins-link-today_GM406889139.pdf
    • http://lawnn.ru/images/coin-master-daily-free-spin-and-coin_GM406889139.pdf
    • http://lawnn.ru/images/free-coin-master-gift-link_GM406889139.pdf
    • http://lawnn.ru/images/free-robux-mod_GM431946152.pdf
    • http://lawnn.ru/images/free-group-roblox_GM431946152.pdf
    • http://lawnn.ru/images/coin-master-free-spins-link-whatsapp-group_GM406889139.pdf
    • http://lawnn.ru/images/coin-master-free-spins-a2z-help_GM406889139.pdf
    • http://lawnn.ru/images/coin-master-hack-without-human-verification-2021_GM406889139.pdf
    • http://lawnn.ru/images/roblox-speed-hack_GM431946152.pdf
    • http://lawnn.ru/images/minecraft-xbox-one-code-free_GM479516143.pdf
    • http://lawnn.ru/images/free-robux-generator-2021-no-human-verification_GM431946152.pdf
    • http://lawnn.ru/images/get-free-spins-in-coin-master_GM406889139.pdf
    • http://lawnn.ru/images/how-to-get-free-faces-on-roblox_GM431946152.pdf
    • http://lawnn.ru/images/how-can-i-get-free-robux_GM431946152.pdf
    • http://lawnn.ru/images/minecraft-bedrock-free-with-java_GM479516143.pdf
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_003_off00004b10.bin
f0cc2ed360df077f6ba8589640fa6ad27d7132442e32931d6e736d82846a09bc
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x4B10 24756 bytes
font_01_sfnt_off000083a1.bin
6bfa7f6d06191d232a4e1dc6d24987c59b1603f32861b15c5e4613e2ba4a1bec
pdf-font-stream PDF embedded font (sfnt) at offset 0x83A1 18292 bytes