Malicious PDF — malware analysis report

Static analysis result for SHA-256 04e5ec3e70d99d7e…

MALICIOUS

PDF

33.7 KB Created: 2021-06-25 22:55:41 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: f171776d59a19e2cc07b927fc4eae73c SHA-1: 8596aa0591f321e895711f612116ae0e1ecebb42 SHA-256: 04e5ec3e70d99d7e6b9652a977b1cb2c944478e6d473b1fac0393ad193a800a7
102 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF document contains numerous links to external websites, many of which are SEO-optimized and promise free Robux or game hacks, indicating a phishing or scam attempt. The ML classifier also flagged this PDF as malicious with high confidence. The presence of embedded URLs and the document's structure suggest it's designed to redirect users to potentially harmful sites or download unwanted applications.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9980

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://netcdn.co/app/431946152/free-robux-landon-game-hack
    • http://www.woundcare4heroes.org.uk/uploads/files/files/robux-free-com_GM431946152.pdf
    • http://www.woundcare4heroes.org.uk/uploads/files/files/do-u-want-free-robux_GM431946152.pdf
    • http://www.woundcare4heroes.org.uk/uploads/files/files/coin-master-hack-apk-july-2021_GM406889139.pdf
    • http://www.woundcare4heroes.org.uk/uploads/files/files/robux-generator-without-human-verification_GM431946152.pdf
    • http://www.woundcare4heroes.org.uk/uploads/files/files/roblox-cheat-engine-lua-pastebin_GM431946152.pdf
    • http://www.woundcare4heroes.org.uk/uploads/files/files/free-spin-coin-master-app-download_GM406889139.pdf
    • http://www.woundcare4heroes.org.uk/uploads/files/files/roblox-real-hack-robux_GM431946152.pdf
    • http://www.woundcare4heroes.org.uk/uploads/files/files/coin-master-free-coins-amp_GM406889139.pdf
    • http://www.woundcare4heroes.org.uk/uploads/files/files/coin-master-links-to-free-spins_GM406889139.pdf
    • http://www.woundcare4heroes.org.uk/uploads/files/files/how-to-get-free-robux-in-roblox-easy-2021_GM431946152.pdf
    • http://www.woundcare4heroes.org.uk/uploads/files/files/roblox-free-pets_GM431946152.pdf
    • http://www.woundcare4heroes.org.uk/uploads/files/files/minecraft-tower-defense-2-hacked_GM479516143.pdf
    • http://www.woundcare4heroes.org.uk/uploads/files/files/free-minecraft-skins-girl_GM479516143.pdf
    • http://www.woundcare4heroes.org.uk/uploads/files/files/oprewards-com-roblox_GM431946152.pdf
    • http://www.woundcare4heroes.org.uk/uploads/files/files/scaffold-minecraft-hack_GM479516143.pdf
    • http://www.woundcare4heroes.org.uk/uploads/files/files/what-games-give-you-robux_GM431946152.pdf
    • http://www.woundcare4heroes.org.uk/uploads/files/files/minecraft-hacker-skin_GM479516143.pdf
    • http://www.woundcare4heroes.org.uk/uploads/files/files/master-free-spins-and-coins_GM406889139.pdf
    • http://www.woundcare4heroes.org.uk/uploads/files/files/coin-master-hack-without-human-verification-2021_GM406889139.pdf
    • http://www.woundcare4heroes.org.uk/uploads/files/files/get-free-spins-on-coin-master_GM406889139.pdf
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00002da3.bin
1838e15f76a721c06d59e19a77c0763b80e550dab3ef8cd81630e0a0df5aed4f
pdf-font-stream PDF embedded font (sfnt) at offset 0x2DA3 22264 bytes
font_01_sfnt_off00005f0b.bin
c905d2acc74cee0f72d0ce52c519458eed325162574146c212703364c6b4718c
pdf-font-stream PDF embedded font (sfnt) at offset 0x5F0B 18888 bytes