Malicious PDF — malware analysis report

Static analysis result for SHA-256 f72e5f20887eb406…

MALICIOUS

PDF

42.6 KB Created: 2021-05-10 17:31:05 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: df2f4f8b109d7d5acbfe90abaf63fb7c SHA-1: 09a835598ab651dcee1d7faee5bfe62f50267a9f SHA-256: f72e5f20887eb4060177ef23d6501e9c0b2c5f95169db472eeda6dfe58f623b3
82 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1203 Exploitation for Client Execution

The PDF document employs social engineering tactics, presenting itself as a free game hack to lure users into downloading malicious content. It contains external URIs pointing to suspicious domains, and the ML classifier strongly indicates maliciousness. The document instructs the user to press Win+R or paste a command into a terminal, which is a common ClickFix technique to bypass macro restrictions and execute arbitrary code.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9971

Heuristics 4

  • ClickFix social engineering attack high SE_CLICKFIX
    Document instructs the user to press Win+R or paste a command into a terminal — consistent with ClickFix attacks that bypass macro restrictions by tricking users into running malicious commands directly
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://netcdn.xyz/app/479516143/bad-minecraft-free-game-hack
    • http://elearning-mtsn35.net/__statics/gudangsoal/files/roblox-hack-game_GM431946152.pdf
    • http://elearning-mtsn35.net/__statics/gudangsoal/files/hack-coin-master-xyz_GM406889139.pdf
    • http://elearning-mtsn35.net/__statics/gudangsoal/files/coin-master-links-to-get-free-spins_GM406889139.pdf
    • https://elearning-mtsn35.net/__statics/gudangsoal/files/apk-coin-master-hack_GM406889139.pdf
    • http://elearning-mtsn35.net/__statics/gudangsoal/files/coin-master-free-spin-facebook-link_GM406889139.pdf
    • http://elearning-mtsn35.net/__statics/gudangsoal/files/can-you-earn-robux_GM431946152.pdf
    • https://elearning-mtsn35.net/__statics/gudangsoal/files/how-to-get-free-robux-without-human-verification-2021_GM431946152.pdf
    • http://elearning-mtsn35.net/__statics/gudangsoal/files/how-to-get-free-robux-without-human-verification_GM431946152.pdf
    • http://elearning-mtsn35.net/__statics/gudangsoal/files/como-sacar-buen-puntaje-en-juego-coin-master-free-spins_GM406889139.pdf
    • https://elearning-mtsn35.net/__statics/gudangsoal/files/minecraft-realms-free_GM479516143.pdf
    • https://elearning-mtsn35.net/__statics/gudangsoal/files/impact-minecraft-hack_GM479516143.pdf
    • http://elearning-mtsn35.net/__statics/gudangsoal/files/how-to-hack-coin-master-ios_GM406889139.pdf
    • http://elearning-mtsn35.net/__statics/gudangsoal/files/how-to-hack-roblox-to-get-free-robux_GM431946152.pdf
    • http://elearning-mtsn35.net/__statics/gudangsoal/files/roblox-avatar-girl_GM431946152.pdf
    • https://elearning-mtsn35.net/__statics/gudangsoal/files/coin-master-free-cards-link-2021_GM406889139.pdf
    • http://elearning-mtsn35.net/__statics/gudangsoal/files/coin-master-free-spins-link-2021-today_GM406889139.pdf
    • http://elearning-mtsn35.net/__statics/gudangsoal/files/free-coin-master-account_GM406889139.pdf
    • https://elearning-mtsn35.net/__statics/gudangsoal/files/coin-master-hack-apk-no-fb-login_GM406889139.pdf
    • https://elearning-mtsn35.net/__statics/gudangsoal/files/free-spins-and-coins-for-coin-master-game_GM406889139.pdf
    • http://elearning-mtsn35.net/__statics/gudangsoal/files/coin-master-hack-2021-android_GM406889139.pdf
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_003_off00004bb3.bin
6b7142c17f920a135d5aa71935ac40f9916b050a1a8514f61e4a1e4ffadd07c1
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x4BB3 25228 bytes
font_01_sfnt_off0000851d.bin
384105d45f3b455646b6eb64dcdb09349e5e1756e4baf8ede6c7c1462ef2dc47
pdf-font-stream PDF embedded font (sfnt) at offset 0x851D 17956 bytes