Malicious PDF — malware analysis report

Static analysis result for SHA-256 ef371d05a8c1a08c…

MALICIOUS

PDF

34.3 KB Created: 2021-07-05 17:48:40 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: 1fc8f320d7209f238989984fc62953d2 SHA-1: 2a927aeadac316fd5006b6b387030d1916edba7b SHA-256: ef371d05a8c1a08c810e5f0a1de433b7520ed7e89fd3f75895a18ab875375484
62 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1203 Exploitation for Client Execution

The PDF document contains numerous embedded URLs and a document body that explicitly advertises 'free coins' and 'hacks' for popular games. The ML classifier strongly flagged this PDF as malicious, and heuristics indicate it contains external URIs, including one pointing to a raw IP address. These findings suggest the document is designed to trick users into downloading malicious files, likely second-stage payloads.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9983

Heuristics 4

  • Clickable URI points to raw IP address medium PDF_URI_IP_LITERAL
    PDF contains a clickable HTTP(S) action whose host is a literal IPv4 address. Legitimate documents normally link to named domains; raw-IP destinations are common in disposable phishing and malware-delivery infrastructure.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://netcdn.tw/app/406889139/how-to-get-free-coins-for-coin-master-game-hack
    • http://111.68.26.74/widyapustaka/repository/ex-7-roblox-hack-download_GM431946152.pdf
    • http://111.68.26.74/widyapustaka/repository/coin-master-daily-free-spins-link-march-2021_GM406889139.pdf
    • http://111.68.26.74/widyapustaka/repository/roblox-spiele-hacke_GM431946152.pdf
    • http://111.68.26.74/widyapustaka/repository/coin-master-free-spins-iphone_GM406889139.pdf
    • http://111.68.26.74/widyapustaka/repository/free-robux-de-2021_GM431946152.pdf
    • http://111.68.26.74/widyapustaka/repository/free-robux-stream-roblox_GM431946152.pdf
    • http://111.68.26.74/widyapustaka/repository/beyond-roblox-hack-wiki_GM431946152.pdf
    • http://111.68.26.74/widyapustaka/repository/free-robux-no-survey-or-human-verification_GM431946152.pdf
    • http://111.68.26.74/widyapustaka/repository/get-free-robux-2021-no-survey_GM431946152.pdf
    • http://111.68.26.74/widyapustaka/repository/how-to-hack-apocalypse-rising-roblox-2021_GM431946152.pdf
    • http://111.68.26.74/widyapustaka/repository/pokemon-go-free-walker_GM1094591345.pdf
    • http://111.68.26.74/widyapustaka/repository/free-robux-cards_GM431946152.pdf
    • http://111.68.26.74/widyapustaka/repository/minecraft-pocket-edition-free-ios_GM479516143.pdf
    • http://111.68.26.74/widyapustaka/repository/hacker-des-personne-sur-roblox-pc_GM431946152.pdf
    • http://111.68.26.74/widyapustaka/repository/robux-no-human-verification_GM431946152.pdf
    • http://111.68.26.74/widyapustaka/repository/how-to-get-free-things-on-roblox_GM431946152.pdf
    • http://111.68.26.74/widyapustaka/repository/coin-master-hack-tuts_GM406889139.pdf
    • http://111.68.26.74/widyapustaka/repository/free-roblox-body_GM431946152.pdf
    • http://111.68.26.74/widyapustaka/repository/huskybuckscom-free-robux_GM431946152.pdf
    • http://111.68.26.74/widyapustaka/repository/roblox-apocalypse-rising-item-spawn-hack_GM431946152.pdf
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_002_off00002f4c.bin
2ee7f2bfc9cac5c0fbb96422fe26790c428cc4b553b6420037e0b595fc0fe17e
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x2F4C 23200 bytes
font_01_sfnt_off000063a4.bin
dbcb18f7bfdddec59cdd21c6f01db76fd89479467b7af7aa3f1646e0963d7b6f
pdf-font-stream PDF embedded font (sfnt) at offset 0x63A4 18164 bytes