Malicious PDF — malware analysis report

Static analysis result for SHA-256 f2b1dee357465ce1…

MALICIOUS

PDF

42.4 KB Created: 2021-05-14 10:20:18 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: db6386becfa987401effb795ffd992e9 SHA-1: beb0f73ff90b0189221fbcd9ef2258a09c566b07 SHA-256: f2b1dee357465ce1887529fc7c477f417f94e92dccfffa989cd9ad4ab6b8fc20
162 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF document contains numerous embedded links and a link farm heuristic indicates a high volume of external URLs, suggesting a phishing or malware distribution attempt. The document body and heuristics like 'SE_SECRET_RECOVERY_LURE' and 'PDF_SEO_LINK_FARM' point towards a lure for game-related cheats or exploits, likely leading to credential harvesting or malware download. No scripts were extracted, but the presence of external links and the ML classifier's high confidence score support the malicious verdict.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9971

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Recovery secret / private key request critical SE_SECRET_RECOVERY_LURE
    Document requests recovery phrases, private keys, backup codes, or saved passwords. Requests for these secrets in a document are high-risk.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://netcdn.xyz/app/406889139/hack-coin-master-nyc-game-hack
    • http://firesafetyservices.biz/images/coin-master-unlimited-spin-link_GM406889139.pdf
    • http://firesafetyservices.biz/images/coin-master-hack-spins-android_GM406889139.pdf
    • http://firesafetyservices.biz/images/coin-master-hack-no-human-verification-2021_GM406889139.pdf
    • http://firesafetyservices.biz/images/public-enemy-sun-prairie-coin-master-free-spins_GM406889139.pdf
    • http://firesafetyservices.biz/images/coin-master-spin-hack-app_GM406889139.pdf
    • http://firesafetyservices.biz/images/free-coins-and-spins-in-coin-master_GM406889139.pdf
    • http://firesafetyservices.biz/images/give-me-free-robux_GM431946152.pdf
    • http://firesafetyservices.biz/images/minecraft-education-edition-free_GM479516143.pdf
    • http://firesafetyservices.biz/images/how-to-get-free-minecraft-skins_GM479516143.pdf
    • http://firesafetyservices.biz/images/how-to-hack-in-arsenal_GM431946152.pdf
    • http://firesafetyservices.biz/images/free-coins-and-spins-for-coin-master-game_GM406889139.pdf
    • http://firesafetyservices.biz/images/robux-hack-tools_GM431946152.pdf
    • http://firesafetyservices.biz/images/haktuts-coin-master-spins_GM406889139.pdf
    • http://firesafetyservices.biz/images/coin-master-free-daily-rewards_GM406889139.pdf
    • http://firesafetyservices.biz/images/how-to-hack-someones-account-on-roblox_GM431946152.pdf
    • http://firesafetyservices.biz/images/hackear-juego-coin-master-espaol_GM406889139.pdf
    • http://firesafetyservices.biz/images/robux-download_GM431946152.pdf
    • http://firesafetyservices.biz/images/free-robux-website_GM431946152.pdf
    • http://firesafetyservices.biz/images/getrobux-now_GM431946152.pdf
    • http://firesafetyservices.biz/images/wahoogaming-co-free-robux_GM431946152.pdf
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_003_off00004b6e.bin
2dd5d1c34c3aecc25f726f31fa0035319d40467ad3061671cb0528a02755cce3
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x4B6E 25232 bytes
font_01_sfnt_off0000845c.bin
6bda2244236a3c42e7a8523e9dc799500b38f97cf514babfc865537c80dbf03b
pdf-font-stream PDF embedded font (sfnt) at offset 0x845C 17896 bytes