Malicious PDF — malware analysis report

Static analysis result for SHA-256 d93e122cc44c38e0…

MALICIOUS

PDF

43.8 KB Created: 2021-05-16 07:13:06 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: 6cc293b60a7813a7d608e9a50c902cf0 SHA-1: 83dcc4fca4680f61f1d8306c24ba06cab9490169 SHA-256: d93e122cc44c38e0ed2cef117bbcf4420e50c340cc65d190f8e1950ba19819c3
102 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF document contains numerous embedded URLs that form a link farm, directing users to websites that promise game hacks and cheats. The ML classifier and the PDF link farm heuristic strongly indicate malicious intent. While no scripts were directly extracted, the nature of the links suggests a lure for users to download potentially malicious content or engage in fraudulent activities.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9648

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://netcdn.xyz/app/406889139/free-spin-card-exchange-coin-master-game-hack
    • https://zszolesno.pl/images/coin-master-hack-generator-tool_GM406889139.pdf
    • https://zszolesno.pl/images/how-to-get-free-robux-without-verification_GM431946152.pdf
    • https://zszolesno.pl/images/master-coin-free-link_GM406889139.pdf
    • https://zszolesno.pl/images/coin-master-hack-generator_GM406889139.pdf
    • https://zszolesno.pl/images/how-to-get-free-robux-without-human-verification_GM431946152.pdf
    • https://zszolesno.pl/images/free-spins-and-coins-for-coin-master_GM406889139.pdf
    • https://zszolesno.pl/images/coin-master-free-spins-2021-app_GM406889139.pdf
    • https://zszolesno.pl/images/how-many-levels-in-coin-master_GM406889139.pdf
    • https://zszolesno.pl/images/how-can-you-get-free-robux_GM431946152.pdf
    • https://zszolesno.pl/images/can-i-get-robux-for-free_GM431946152.pdf
    • https://zszolesno.pl/images/how-to-hack-roblox-accounts-for-robux_GM431946152.pdf
    • https://zszolesno.pl/images/minecraft-windows-10-edition-free-download_GM479516143.pdf
    • https://zszolesno.pl/images/free-coins-and-spins-coin-master-2021_GM406889139.pdf
    • https://zszolesno.pl/images/coin-master-free-stuff_GM406889139.pdf
    • https://zszolesno.pl/images/coin-master-free-shield-link_GM406889139.pdf
    • https://zszolesno.pl/images/how-to-earn-robux-on-roblox_GM431946152.pdf
    • https://zszolesno.pl/images/how-to-get-a-free-minecraft-account_GM479516143.pdf
    • https://zszolesno.pl/images/free-robux-games-that-actually-work_GM431946152.pdf
    • https://zszolesno.pl/images/hack-coin-master-nyc_GM406889139.pdf
    • https://zszolesno.pl/images/coin-master-mod-free-download_GM406889139.pdf
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_003_off0000474e.bin
029edb02304fea5898f99c4ab1b8b23edd92dd280cdd30b3bb8887a805750d3b
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x474E 24220 bytes
font_01_sfnt_off00007d7c.bin
10d025f04f706eb71cdda4f99784df1b9ccb52e48080e43095e0398eaef6f132
pdf-font-stream PDF embedded font (sfnt) at offset 0x7D7C 2880 bytes
font_02_sfnt_off00008767.bin
ed2a774088debdf1cc09dc311144fce9846218577fb7d098d74f3e3c5a234c04
pdf-font-stream PDF embedded font (sfnt) at offset 0x8767 18724 bytes