Malicious PDF — malware analysis report

Static analysis result for SHA-256 d0fee5c230ab5adc…

MALICIOUS

PDF

47.2 KB Created: 2021-05-15 15:05:16 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: 95a9448be6b36e880eec99db9d6f24e0 SHA-1: da788a8384c675242460b322d71a9b85bee539ff SHA-256: d0fee5c230ab5adc013cda4355765e8e68ae56d35f6ed4ec7bfe868826f4363b
102 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

This PDF document contains a large number of external links, many of which are SEO-farmed and point to other PDFs, suggesting a link farm or redirection scheme. The document body and extracted URLs indicate a lure for free in-game currency and cheats for popular games like Coin Master and Roblox. The ML classifier also flagged this PDF as malicious, supporting the conclusion that it is designed to lead users to potentially harmful content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.8948

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://netcdn.xyz/app/406889139/coin-master-free-spins-link-2021-haktuts-game-hack
    • http://hindicenter.com/images/roblox-robux-hack_GM431946152.pdf
    • http://hindicenter.com/images/roblox-password-hacker_GM431946152.pdf
    • http://hindicenter.com/images/free-robux-no-anti-bot-verification_GM431946152.pdf
    • http://hindicenter.com/images/free-robux-generator-com-roblox-hack_GM431946152.pdf
    • http://hindicenter.com/images/coin-master-hack-no-survey_GM406889139.pdf
    • http://hindicenter.com/images/links-for-free-spins-for-coin-master_GM406889139.pdf
    • http://hindicenter.com/images/games-that-give-free-robux_GM431946152.pdf
    • http://hindicenter.com/images/games-that-give-you-free-robux_GM431946152.pdf
    • http://hindicenter.com/images/free-robux-only-1-step_GM431946152.pdf
    • http://hindicenter.com/images/coin-master-hack-app-android-download_GM406889139.pdf
    • http://hindicenter.com/images/fighting-free-card-coin-master_GM406889139.pdf
    • http://hindicenter.com/images/free-spins-coin-master-2021_GM406889139.pdf
    • http://hindicenter.com/images/daily-free-spins-coin-master-2021_GM406889139.pdf
    • http://hindicenter.com/images/latest-coin-master-free-spins-link_GM406889139.pdf
    • http://hindicenter.com/images/100-free-spins-coin-master_GM406889139.pdf
    • http://hindicenter.com/images/blox-supply-free-robux_GM431946152.pdf
    • http://hindicenter.com/images/free-robux-generator-2021-no-survey_GM431946152.pdf
    • http://hindicenter.com/images/coin-master-free-spins-april-2021_GM406889139.pdf
    • http://hindicenter.com/images/how-to-get-free-coins-in-minecraft_GM479516143.pdf
    • http://hindicenter.com/images/coin-master-hack-8-ball-pool_GM406889139.pdf
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_003_off00004a45.bin
65a153276e033b10872819dbdf68252fec1dc481d92afd07d8c3ddb1e42449e2
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x4A45 23896 bytes
font_01_sfnt_off00008091.bin
e06aca5f85e50ae6cefda302c5299c18ab6d27c174f74f0bb0ee8efa7ccb4468
pdf-font-stream PDF embedded font (sfnt) at offset 0x8091 8676 bytes
font_02_sfnt_off0000951c.bin
17fca5a110173985813f3878a6a354acd9691d8bd8a3bfb3ba74e1722aeabc4d
pdf-font-stream PDF embedded font (sfnt) at offset 0x951C 18600 bytes