Malicious PDF — malware analysis report

Static analysis result for SHA-256 e8fa2bf0c6be48ef…

MALICIOUS

PDF

46.7 KB Created: 2021-05-19 23:30:57 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: fefda82cafa57584e35ebe041e4c6172 SHA-1: e212c0f617fb74f08414fc79e694277d25226d2c SHA-256: e8fa2bf0c6be48ef13696d044930649ace710299dfa3b06010a03fc8e114765b
122 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a large number of embedded links, many pointing to raw IP addresses, suggesting a link farm designed to redirect users to potentially malicious content. The ML classifier also flagged this PDF as malicious. The document body, though heavily obfuscated, contains URLs related to game hacks and free spins, indicating a lure for potentially unwanted or malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.8948

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Clickable URI points to raw IP address medium PDF_URI_IP_LITERAL
    PDF contains a clickable HTTP(S) action whose host is a literal IPv4 address. Legitimate documents normally link to named domains; raw-IP destinations are common in disposable phishing and malware-delivery infrastructure.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://netcdn.xyz/app/406889139/www.haktuts.in-2021-08-coin-master-free-spin-and-coin-link.html-m-1-game-hack
    • http://110.232.83.89/slimsppks/repository/how-do-you-hack-minecraft_GM479516143.pdf
    • http://110.232.83.89/slimsppks/repository/free-minecraft-alt-generator_GM479516143.pdf
    • http://110.232.83.89/slimsppks/repository/coin-master-20-free-spins-link-today_GM406889139.pdf
    • http://110.232.83.89/slimsppks/repository/roblox-accounts-for-sale-free_GM431946152.pdf
    • http://110.232.83.89/slimsppks/repository/how-to-get-free-robux-without-downloading-apps_GM431946152.pdf
    • http://110.232.83.89/slimsppks/repository/coin-master-support_GM406889139.pdf
    • http://110.232.83.89/slimsppks/repository/free-robux-no-human-verification-or-survey-2021_GM431946152.pdf
    • http://110.232.83.89/slimsppks/repository/coin-master-daily-free-spins-link-today-2021_GM406889139.pdf
    • http://110.232.83.89/slimsppks/repository/how-to-get-free-robux-without-downloading-anything_GM431946152.pdf
    • http://110.232.83.89/slimsppks/repository/coin-master-free-spins-link_GM406889139.pdf
    • http://110.232.83.89/slimsppks/repository/how-to-change-your-roblox-username-for-free_GM431946152.pdf
    • http://110.232.83.89/slimsppks/repository/coin-master-free-spins-2021_GM406889139.pdf
    • http://110.232.83.89/slimsppks/repository/freerubux_GM431946152.pdf
    • http://110.232.83.89/slimsppks/repository/free-coin-master-coins-and-spins_GM406889139.pdf
    • http://110.232.83.89/slimsppks/repository/rewards-robux_GM431946152.pdf
    • http://110.232.83.89/slimsppks/repository/robuxmatchcom-free-robux_GM431946152.pdf
    • http://110.232.83.89/slimsppks/repository/free-spins-coin-master-hack-2021_GM406889139.pdf
    • http://110.232.83.89/slimsppks/repository/minecraft-hacks-wurst_GM479516143.pdf
    • http://110.232.83.89/slimsppks/repository/how-to-get-free-food-on-coin-master_GM406889139.pdf
    • http://110.232.83.89/slimsppks/repository/play-minecraft-online-free_GM479516143.pdf
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_003_off00004c78.bin
188d16075d6ace92c31570a720806e59367f0719a5e635a667b50039e5b67982
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x4C78 24816 bytes
font_01_sfnt_off000085e5.bin
3fb127b764b9d10f5525bc4de5ec8316de704409ccb0cf21cff3ad8a30d11676
pdf-font-stream PDF embedded font (sfnt) at offset 0x85E5 2840 bytes
font_02_sfnt_off00008f97.bin
bf7f2ec23d312a45e96f2d807c6b497bbe2235e066fc4c290a35779047d8ab0d
pdf-font-stream PDF embedded font (sfnt) at offset 0x8F97 19780 bytes