Malicious PDF — malware analysis report

Static analysis result for SHA-256 e8d01cad877276ee…

MALICIOUS

PDF

41.6 KB Created: 2021-05-15 14:22:31 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: 994191d6d6a369a369dd8e82fce3524a SHA-1: 264cfca63057c17c1340867579f0c1157eb21f7a SHA-256: e8d01cad877276ee423d15d7d3ca2191dc19db3ce54db13c895381b715421c66
82 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1203 Exploitation for Client Execution

The document presents a fake CAPTCHA to trick users into interacting with it, likely leading to the download of malicious content via embedded URLs. The ML classifier strongly flagged this PDF as malicious, and the presence of multiple URLs associated with game hacks and free spins suggests a lure for potentially unwanted or malicious applications. No scripts were extracted, but the embedded URLs are the primary indicators of malicious intent.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9971

Heuristics 4

  • Fake CAPTCHA / human verification prompt high SE_FAKE_CAPTCHA
    Document displays a fake CAPTCHA or human-verification prompt — used to trick users into running commands or pressing keyboard shortcuts
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://netcdn.xyz/app/406889139/free-spins-coin-master-app-ios-game-hack
    • http://demenagementlandry.com/images/free-robux-no-human-verification-or-survey-2021_GM431946152.pdf
    • http://demenagementlandry.com/images/free-spins-coin-master-hack-2021_GM406889139.pdf
    • http://demenagementlandry.com/images/roblox-royale-high-diamond-hack_GM431946152.pdf
    • http://demenagementlandry.com/images/websites-to-get-free-robux_GM431946152.pdf
    • http://demenagementlandry.com/images/free-robux-earn_GM431946152.pdf
    • http://demenagementlandry.com/images/martian-lettuce-coin-master-free_GM406889139.pdf
    • http://demenagementlandry.com/images/free-spins-coin-master-2021_GM406889139.pdf
    • http://demenagementlandry.com/images/coin-master-hack-mod-apk-2021_GM406889139.pdf
    • http://demenagementlandry.com/images/coin-master-free-spins-and-coins-link-today_GM406889139.pdf
    • http://demenagementlandry.com/images/free-robux-app_GM431946152.pdf
    • http://demenagementlandry.com/images/cool-free-roblox-outfits_GM431946152.pdf
    • http://demenagementlandry.com/images/cm-spins_GM406889139.pdf
    • http://demenagementlandry.com/images/minecraft-images-free_GM479516143.pdf
    • http://demenagementlandry.com/images/minecraft-free-demo_GM479516143.pdf
    • http://demenagementlandry.com/images/coin-master-daily-free-spins-and-coins-link_GM406889139.pdf
    • http://demenagementlandry.com/images/free-robux-youtube_GM431946152.pdf
    • http://demenagementlandry.com/images/hack-coin-master-download_GM406889139.pdf
    • http://demenagementlandry.com/images/coin-master-free-spins-link-2021_GM406889139.pdf
    • http://demenagementlandry.com/images/coin-master-free-spin-today-2021_GM406889139.pdf
    • http://demenagementlandry.com/images/roblox-april-fools-hack_GM431946152.pdf
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_003_off000048a4.bin
dc5d2c1cdd9627470b19a4c2a1b8dbb863b5864cea8aee947a1abe20d3eab88c
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x48A4 24732 bytes
font_01_sfnt_off0000817f.bin
baa69023d18af7e6e292b7ed0352255ac8c665d65dfdd35f206937513cc9840e
pdf-font-stream PDF embedded font (sfnt) at offset 0x817F 17884 bytes