Malicious PDF — malware analysis report

Static analysis result for SHA-256 def78d94338b2222…

MALICIOUS

PDF

54.0 KB Created: 2021-06-13 22:59:09 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: 3852180dff2dd88e0b91cf619df49cc8 SHA-1: c8ac4856c305d0728724f0d090708a3a208eea34 SHA-256: def78d94338b2222b0f6befd1474265a56510746116a66cb32ccddec8560bd08
102 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF document contains numerous embedded links, presented as a lure for free in-game currency and hacks, which is a common social engineering tactic. The heuristic 'PDF_SEO_LINK_FARM' indicates a large number of external links, suggesting a link farm designed to drive traffic to potentially malicious sites. The ML classifier also flagged this PDF as malicious with high confidence. While no scripts were directly extracted, the presence of embedded URLs and the nature of the lures strongly suggest a malicious intent to redirect users to harmful content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9365

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://netcdn.co/app/431946152/4-step-way-to-get-free-robux-2021-game-hack
    • http://royalindianjourney.co.in/uploaded_files/userfiles/files/coin-master-free-spins-no-survey_GM406889139.pdf
    • http://royalindianjourney.co.in/uploaded_files/userfiles/files/hackear-coin-master-sin-verificacion_GM406889139.pdf
    • http://royalindianjourney.co.in/uploaded_files/userfiles/files/free-roblox-dominus_GM431946152.pdf
    • http://royalindianjourney.co.in/uploaded_files/userfiles/files/coin-master-free-download-for-pc_GM406889139.pdf
    • http://royalindianjourney.co.in/uploaded_files/userfiles/files/coin-master-hack-tool-2021_GM406889139.pdf
    • http://royalindianjourney.co.in/uploaded_files/userfiles/files/coin-master-daily-free-spins-link-today-haktuts_GM406889139.pdf
    • http://royalindianjourney.co.in/uploaded_files/userfiles/files/easy-free-spins-coin-master_GM406889139.pdf
    • http://royalindianjourney.co.in/uploaded_files/userfiles/files/minecraft-survival-free_GM479516143.pdf
    • http://royalindianjourney.co.in/uploaded_files/userfiles/files/100-free-spins-on-coin-master_GM406889139.pdf
    • http://royalindianjourney.co.in/uploaded_files/userfiles/files/can-i-hack-coin-master-with-lucky-patcher_GM406889139.pdf
    • http://royalindianjourney.co.in/uploaded_files/userfiles/files/free-roblox-acc_GM431946152.pdf
    • http://royalindianjourney.co.in/uploaded_files/userfiles/files/coin-master-golden-card-hack_GM406889139.pdf
    • http://royalindianjourney.co.in/uploaded_files/userfiles/files/free-robux-generator-no-human-verification-2021_GM431946152.pdf
    • http://royalindianjourney.co.in/uploaded_files/userfiles/files/hack-de-coin-master_GM406889139.pdf
    • http://royalindianjourney.co.in/uploaded_files/userfiles/files/download-hacked-games-coin-master_GM406889139.pdf
    • http://royalindianjourney.co.in/uploaded_files/userfiles/files/free-spins-and-coins-coin-master-2021-link_GM406889139.pdf
    • http://royalindianjourney.co.in/uploaded_files/userfiles/files/cheat-engine-roblox-bypass-2021-no-admin_GM431946152.pdf
    • http://royalindianjourney.co.in/uploaded_files/userfiles/files/free-assassin-roblox-coins_GM431946152.pdf
    • http://royalindianjourney.co.in/uploaded_files/userfiles/files/minecraft-mod-menu-apk_GM479516143.pdf
    • http://royalindianjourney.co.in/uploaded_files/userfiles/files/free-coin-master-spins-daily_GM406889139.pdf
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00004d15.bin
9ac183c098791cadb5fc98404ddb29ee10314dc72c1742f3d21dea4727cd25a4
pdf-font-stream PDF embedded font (sfnt) at offset 0x4D15 37516 bytes
font_01_sfnt_off0000a0a0.bin
450e3ee45915afe13702bf1d587eb8b9ad88a8d2113419ac9f2fd116a828e139
pdf-font-stream PDF embedded font (sfnt) at offset 0xA0A0 5696 bytes
font_02_sfnt_off0000adb2.bin
0d8dd053120c3bedc9f47a92068d47d8193bf800725bd60a8ac3daa470fa1eb9
pdf-font-stream PDF embedded font (sfnt) at offset 0xADB2 19364 bytes