Malicious PDF — malware analysis report

Static analysis result for SHA-256 f218063a4b5f5dbe…

MALICIOUS

PDF

45.2 KB Created: 2021-05-12 15:30:15 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: d6a9840ed50aa75d9b2093bfb45b2e66 SHA-1: ad96805fe1a9966766a5e1abf5d500cfedf8e023 SHA-256: f218063a4b5f5dbe5ded0660076c49a00b1ae80f972659aac10e205c2be4c9a8
102 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The document contains lures for free in-game currency and cheats, a common tactic for distributing malware or conducting phishing. The presence of embedded URLs pointing to suspicious domains, combined with a critical heuristic firing for 'Secret Recovery Lure', indicates a high likelihood of malicious intent. While no scripts were explicitly extracted, the PDF structure and embedded URLs suggest it may attempt to download or redirect the user to malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9551

Heuristics 4

  • Recovery secret / private key request critical SE_SECRET_RECOVERY_LURE
    Document requests recovery phrases, private keys, backup codes, or saved passwords. Requests for these secrets in a document are high-risk.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://netcdn.xyz/app/406889139/free-coins-coin-master-daily-game-hack
    • https://estalagemmonteverde.com.br/images/get-me-robux_GM431946152.pdf
    • https://estalagemmonteverde.com.br/images/how-do-i-get-free-robux-on-roblox_GM431946152.pdf
    • https://estalagemmonteverde.com.br/images/how-to-get-robux-for-free-2021_GM431946152.pdf
    • https://estalagemmonteverde.com.br/images/how-to-free-robux_GM431946152.pdf
    • https://estalagemmonteverde.com.br/images/minecraft-dungeons-free_GM479516143.pdf
    • https://estalagemmonteverde.com.br/images/coin-master-hack-apk-download-2021_GM406889139.pdf
    • https://estalagemmonteverde.com.br/images/free-robux-no-human-verification-2021_GM431946152.pdf
    • https://estalagemmonteverde.com.br/images/aimbot-exe-roblox_GM431946152.pdf
    • https://estalagemmonteverde.com.br/images/coin-master-spin-cheat_GM406889139.pdf
    • https://estalagemmonteverde.com.br/images/roblox-free-roblox_GM431946152.pdf
    • https://estalagemmonteverde.com.br/images/how-to-hack-roblox-to-get-free-robux_GM431946152.pdf
    • https://estalagemmonteverde.com.br/images/roblox-hacks-and-cheats_GM431946152.pdf
    • https://estalagemmonteverde.com.br/images/minecraft-114-4-download-free_GM479516143.pdf
    • https://estalagemmonteverde.com.br/images/coin-master-free-spins-8-14-2021_GM406889139.pdf
    • https://estalagemmonteverde.com.br/images/minecraft-story-mode-free_GM479516143.pdf
    • https://estalagemmonteverde.com.br/images/free-robux-generator-codes_GM431946152.pdf
    • https://estalagemmonteverde.com.br/images/free-robux-come_GM431946152.pdf
    • https://estalagemmonteverde.com.br/images/coin-master-heaven-links-free-spins_GM406889139.pdf
    • https://estalagemmonteverde.com.br/images/does-roblox-premium-expire_GM431946152.pdf
    • https://estalagemmonteverde.com.br/images/hack-coin-master-apk-32-download_GM406889139.pdf
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_003_off00004c5b.bin
9985f8a3a786833455d90404a1a4ce7ae8fb8d8f03cfd4b015187baa117061ed
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x4C5B 25172 bytes
font_01_sfnt_off00008524.bin
381f6d859be141449dd645f7be1484d2a1cf49218dc471b402dae69eaa2b11d5
pdf-font-stream PDF embedded font (sfnt) at offset 0x8524 2824 bytes
font_02_sfnt_off00008ec6.bin
1e224f5f91abe618aa90885726d1546ed761136b94692ecd0d001fc6fdb96963
pdf-font-stream PDF embedded font (sfnt) at offset 0x8EC6 18132 bytes