PDF static analysis report

Static analysis result for SHA-256 d2b3d176d3ea4870…

SUSPICIOUS

PDF

35.8 KB Created: 2021-07-08 01:26:58 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7) First seen: 2021-09-16
MD5: 1b60a913144c23a5871c9b5e7bdf6442 SHA-1: 86d420945f427cd06a0c743ca42e4312c50857ea SHA-256: d2b3d176d3ea4870721763354494fdc46b29985bcb779b16590836e1ba3aea00
42 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF document contains numerous embedded URLs and a document body that explicitly promotes free in-game currency and hacks for popular games like Coin Master and Roblox. The ML classifier strongly flagged this PDF as malicious, and the presence of external URIs suggests an attempt to redirect the user to a malicious download or phishing site. No scripts were extracted from this sample, but the overall pattern indicates a social engineering lure to trick users into downloading potentially harmful files.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9980

Heuristics 3

  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://netcdn.tw/app/406889139/coin-master-game-2021-free-spin-link-game-hack PDF link annotation
    • http://e-learning.mtsn7kediri.sch.id/__statics/gudangsoal/files/legit-coin-master-hack-no-human-verification_GM406889139.pdfIn PDF document text
    • http://e-learning.mtsn7kediri.sch.id/__statics/gudangsoal/files/oginject-co_GM406889139.pdfIn PDF document text
    • https://e-learning.mtsn7kediri.sch.id/__statics/gudangsoal/files/hack-para-robux-gratis-2021_GM431946152.pdfIn PDF document text
    • https://e-learning.mtsn7kediri.sch.id/__statics/gudangsoal/files/free-robux-generator-2021-no-human-verification-or-survey_GM431946152.pdfIn PDF document text
    • https://e-learning.mtsn7kediri.sch.id/__statics/gudangsoal/files/coin-master-key-free-spin_GM406889139.pdfIn PDF document text
    • https://e-learning.mtsn7kediri.sch.id/__statics/gudangsoal/files/coin-master-hack-pc-2021_GM406889139.pdfIn PDF document text
    • https://e-learning.mtsn7kediri.sch.id/__statics/gudangsoal/files/how-to-get-free-face-on-roblox_GM431946152.pdfIn PDF document text
    • http://e-learning.mtsn7kediri.sch.id/__statics/gudangsoal/files/coinmaster-rewards_GM406889139.pdfIn PDF document text
    • http://e-learning.mtsn7kediri.sch.id/__statics/gudangsoal/files/roblox-sexually_GM431946152.pdfIn PDF document text
    • http://e-learning.mtsn7kediri.sch.id/__statics/gudangsoal/files/free-robux-book_GM431946152.pdfIn PDF document text
    • https://e-learning.mtsn7kediri.sch.id/__statics/gudangsoal/files/pokemon-go-free-7-km-eggs_GM1094591345.pdfIn PDF document text
    • https://e-learning.mtsn7kediri.sch.id/__statics/gudangsoal/files/coin-master-link_GM406889139.pdfIn PDF document text
    • https://e-learning.mtsn7kediri.sch.id/__statics/gudangsoal/files/ways-to-get-robux_GM431946152.pdfIn PDF document text
    • https://e-learning.mtsn7kediri.sch.id/__statics/gudangsoal/files/coin-master-hack-2021-free_GM406889139.pdfIn PDF document text
    • http://e-learning.mtsn7kediri.sch.id/__statics/gudangsoal/files/haktuts-coin-master_GM406889139.pdfIn PDF document text
    • https://e-learning.mtsn7kediri.sch.id/__statics/gudangsoal/files/pokemon-go-free-remote-raid-pass_GM1094591345.pdfIn PDF document text
    • https://e-learning.mtsn7kediri.sch.id/__statics/gudangsoal/files/free-minecraft-for-kids_GM479516143.pdfIn PDF document text
    • https://e-learning.mtsn7kediri.sch.id/__statics/gudangsoal/files/roblox-fun-com-free-robux_GM431946152.pdfIn PDF document text
    • https://e-learning.mtsn7kediri.sch.id/__statics/gudangsoal/files/free-robux-codes-2021_GM431946152.pdfIn PDF document text
    • https://e-learning.mtsn7kediri.sch.id/__statics/gudangsoal/files/coin-master-free-gold-cards_GM406889139.pdfIn PDF document text
    • http://en.wikipedia.org/wiki/MIT_LicenseIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000033df.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x33DF 22788 bytes
SHA-256: 9416ed886536c408e27743dc168e5d29e3340a6d3f97274502f8609546f0d5c0
font_01_sfnt_off00006704.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x6704 19004 bytes
SHA-256: 0380ea631ae9459a709a33ae7c12e24ce61e57c36bba07f41eb8bd34d02fd060