Malicious PDF — malware analysis report

Static analysis result for SHA-256 ea40695d43ccb9e5…

MALICIOUS

PDF

47.9 KB Created: 2021-06-08 12:14:34 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: d1d1f1f82f0ebf3961f1f47b30a89cdc SHA-1: 974b8a1f05620c2bbc99198d0abb9b34174e1647 SHA-256: ea40695d43ccb9e59c0517caac555dbb0d14e4497050a86b1fe059a45885163d
62 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The document contains embedded URLs and a call-to-action phrase, suggesting it is designed to trick users into downloading malicious files disguised as game hacks or cheats. The ML classifier also flagged this PDF as malicious, increasing confidence in its malicious intent. The primary lure appears to be related to game exploits and free item acquisition.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9769

Heuristics 4

  • Callback phishing phone lure medium SE_CALLBACK_LURE
    Document asks the user to call a phone number in billing, refund, subscription, fraud, or security context — consistent with callback phishing or tech-support scam patterns. Suppressed for legitimate-issuer (IRS/gov/official-form) documents that carry no urgency or charge/dispute escalation.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://netcdn.tw/app/431946152/descargar-hacks-para-roblox-2021-game-hack
    • http://elsenorcafe.com.co/images/coin-master-free-coins-and-spins-daily_GM406889139.pdf
    • http://elsenorcafe.com.co/images/can-you-get-minecraft-for-free_GM479516143.pdf
    • http://elsenorcafe.com.co/images/minecraft-windows-10-edition-free_GM479516143.pdf
    • http://elsenorcafe.com.co/images/cheats-to-get-free-spins-on-coin-master_GM406889139.pdf
    • http://elsenorcafe.com.co/images/minecraft-survival-hacks_GM479516143.pdf
    • http://elsenorcafe.com.co/images/daily-coin-master-free-link_GM406889139.pdf
    • http://elsenorcafe.com.co/images/how-to-minecraft-for-free_GM479516143.pdf
    • http://elsenorcafe.com.co/images/how-to-hack-someone-on-roblox_GM431946152.pdf
    • http://elsenorcafe.com.co/images/daily-free-spins-coin-master-2021_GM406889139.pdf
    • http://elsenorcafe.com.co/images/how-to-get-free-things-on-roblox_GM431946152.pdf
    • http://elsenorcafe.com.co/images/roblox-assassin-hack-knives_GM431946152.pdf
    • http://elsenorcafe.com.co/images/free-tiktok-likes-generator_GM835599320.pdf
    • http://elsenorcafe.com.co/images/roblox-hack-apk_GM431946152.pdf
    • http://elsenorcafe.com.co/images/get-minecraft-windows-10-free_GM479516143.pdf
    • http://elsenorcafe.com.co/images/free-robux-no-verification_GM431946152.pdf
    • http://elsenorcafe.com.co/images/free-ways-to-get-robux_GM431946152.pdf
    • http://elsenorcafe.com.co/images/coin-master-fan-page-free-spins_GM406889139.pdf
    • http://elsenorcafe.com.co/images/robux-game_GM431946152.pdf
    • http://elsenorcafe.com.co/images/how-to-hack-roblox-accounts-on-phone_GM431946152.pdf
    • http://elsenorcafe.com.co/images/free-coin-app_GM406889139.pdf
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000051d6.bin
537d91aee97357367f020731610895009a0993d85b46bec764666a43acfecd4a
pdf-font-stream PDF embedded font (sfnt) at offset 0x51D6 24036 bytes
font_01_sfnt_off00008899.bin
63a179d8a9645bea05c6d53b1776faf4e4a7281930de6cf484e639846bec2e20
pdf-font-stream PDF embedded font (sfnt) at offset 0x8899 3656 bytes
font_02_sfnt_off00009553.bin
bf8b5ff9a9d2bef0758465398ceb98fb87e52110abbf6f59ec3777e6c7a035d6
pdf-font-stream PDF embedded font (sfnt) at offset 0x9553 19196 bytes