Malicious PDF — malware analysis report

Static analysis result for SHA-256 e83b975eae158499…

MALICIOUS

PDF

33.8 KB Created: 2021-07-05 09:06:20 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: 962dfad5ccbd31f7209a83d0672c2720 SHA-1: 588bb89e8ec4e6803e620fe2454b8125dd26179a SHA-256: e83b975eae158499e0f92e556ce60726a206a7cc2b1de53639d50ab3bfd6048e
102 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF document contains numerous links to external websites, many of which are SEO-optimized and promise game hacks or free items. The primary URL, http://netcdn.tw/app/406889139/coin-master-free-spins-hack-link-game-hack, is directly associated with a heuristic firing for a malicious URI. The ML classifier also flagged this PDF as malicious with high confidence. The document body, though partially corrupted, contains similar lure text and URLs, reinforcing the phishing and potential malware distribution intent.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9980

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://netcdn.tw/app/406889139/coin-master-free-spins-hack-link-game-hack
    • https://www.dahu-villa.com.tw/upload/files/how-to-use-process-hacker-for-roblox-for-robux_GM431946152.pdf
    • https://www.dahu-villa.com.tw/upload/files/static-moonactive-net-free-spins-coin-master_GM406889139.pdf
    • https://www.dahu-villa.com.tw/upload/files/robux-hack-2021_GM431946152.pdf
    • https://www.dahu-villa.com.tw/upload/files/minecraft-112-hacked-client_GM479516143.pdf
    • https://www.dahu-villa.com.tw/upload/files/free-printable-roblox-images_GM431946152.pdf
    • https://www.dahu-villa.com.tw/upload/files/coin-master-gold-cards-hack_GM406889139.pdf
    • https://www.dahu-villa.com.tw/upload/files/hox-to-get-free-item-in-roblox-2021_GM431946152.pdf
    • https://www.dahu-villa.com.tw/upload/files/coin-master-hack-online-pc_GM406889139.pdf
    • https://www.dahu-villa.com.tw/upload/files/how-to-get-free-robux-28-august-2021_GM431946152.pdf
    • https://www.dahu-villa.com.tw/upload/files/daily-free-spins-coin-master_GM406889139.pdf
    • https://www.dahu-villa.com.tw/upload/files/how-to-get-free-robux-without-downloading-anything_GM431946152.pdf
    • https://www.dahu-villa.com.tw/upload/files/free-minecraft-mods-for-ps4_GM479516143.pdf
    • https://www.dahu-villa.com.tw/upload/files/robux-hack-deutsch_GM431946152.pdf
    • https://www.dahu-villa.com.tw/upload/files/roblox-reach-hack_GM431946152.pdf
    • https://www.dahu-villa.com.tw/upload/files/get-free-robux-on-roblox-with-coputer_GM431946152.pdf
    • https://www.dahu-villa.com.tw/upload/files/anarchy-hacks-roblox_GM431946152.pdf
    • https://www.dahu-villa.com.tw/upload/files/are-the-free-robux-fake_GM431946152.pdf
    • https://www.dahu-villa.com.tw/upload/files/bit-slicer-hack-jump-roblox_GM431946152.pdf
    • https://www.dahu-villa.com.tw/upload/files/coin-master-free-spins-link_GM406889139.pdf
    • https://www.dahu-villa.com.tw/upload/files/can-you-get-robux-for-free_GM431946152.pdf
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00002fdd.bin
b0df5ef68a9e263dcaa0ef9374e4d8631c0893cb39b2d03dca37760c731b4da7
pdf-font-stream PDF embedded font (sfnt) at offset 0x2FDD 22184 bytes
font_01_sfnt_off00006118.bin
bda74eba5f039297e511dddd57f660cdccd001576784cab1ba2dc4ebdf08fb85
pdf-font-stream PDF embedded font (sfnt) at offset 0x6118 18344 bytes