Malicious PDF — malware analysis report

Static analysis result for SHA-256 dcc9d26265bf8d50…

MALICIOUS

PDF

41.9 KB Created: 2021-05-14 21:36:15 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: c92f196c60299e09e261d904b64f8f43 SHA-1: 03782071350636b783db97c719de562cc6028a0f SHA-256: dcc9d26265bf8d50b3eec1363ffb7a438f6c5766b7dd3379763a5cd64b9a4c0b
102 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF document contains numerous external links, many of which are structured as SEO-optimized links to other PDF files, suggesting a link farm or content-loading mechanism. The document body and extracted URLs indicate a lure for game-related hacks and generators, a common social engineering tactic. While no scripts were explicitly extracted, the PDF structure and the presence of external links strongly suggest an attempt to redirect the user to malicious content, likely hosted at the provided URLs.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9971

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://netcdn.xyz/app/406889139/hacks-for-coin-master-game-hack
    • http://mklista.ru/images/install-free-game-coin-master_GM406889139.pdf
    • http://mklista.ru/images/haktuts-coin-master-free-spins-2021_GM406889139.pdf
    • http://mklista.ru/images/roblox-promo-codes-generator-no-human-verification_GM431946152.pdf
    • http://mklista.ru/images/how-to-get-free-robux-hack-2021_GM431946152.pdf
    • http://mklista.ru/images/free-roblox-avatar_GM431946152.pdf
    • http://mklista.ru/images/free-robux-apk_GM431946152.pdf
    • http://mklista.ru/images/coin-master-free-in-app-purchases_GM406889139.pdf
    • http://mklista.ru/images/free-links-for-coin-master_GM406889139.pdf
    • http://mklista.ru/images/free-robux-glitch-2021_GM431946152.pdf
    • http://mklista.ru/images/free-robux-generator-no-human-verification-2021_GM431946152.pdf
    • http://mklista.ru/images/coin-master-free-spins-generator-no-human-verification_GM406889139.pdf
    • http://mklista.ru/images/roblox-hacked-accounts-list_GM431946152.pdf
    • http://mklista.ru/images/robux-hacks-2021_GM431946152.pdf
    • http://mklista.ru/images/how-to-hack-any-roblox-account_GM431946152.pdf
    • http://mklista.ru/images/coin-master-download-hack-ios_GM406889139.pdf
    • http://mklista.ru/images/robloxheroxyz-free-robux_GM431946152.pdf
    • http://mklista.ru/images/hacks-to-get-free-robux_GM431946152.pdf
    • http://mklista.ru/images/hacks-for-coin-master-game_GM406889139.pdf
    • http://mklista.ru/images/haktuts-2021-coin-master-free-spin-link_GM406889139.pdf
    • http://mklista.ru/images/coin-master-free-spins-link-october-2021_GM406889139.pdf
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_003_off00004a5b.bin
d97f7af899244f5c8bf937ce221d057d530f6a3133244b93487775a9446008dd
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x4A5B 24508 bytes
font_01_sfnt_off000082b8.bin
aa3394458939619806496cbc198b043db21b7abc6a7e758b364f4c9fc0519879
pdf-font-stream PDF embedded font (sfnt) at offset 0x82B8 17880 bytes