Malicious PDF — malware analysis report

Static analysis result for SHA-256 066e3d49939ad05d…

MALICIOUS

PDF

34.5 KB Created: 2021-06-26 22:36:43 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: ab6ffbb877ff6f7011c0b18e0c6a5e2b SHA-1: 73106e773ad24f40a21768c7280f1e290ddca311 SHA-256: 066e3d49939ad05dff91d8e3dbbe3071d103517a0598664b788bbcc6ed19ea7a
102 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF document contains numerous embedded links, many of which are presented as download opportunities for game hacks and cheats. The ML classifier and the PDF_SEO_LINK_FARM heuristic strongly indicate malicious intent, likely to distribute malware or lead users to phishing sites. The document body and extracted URLs reinforce this, suggesting a lure-based attack pattern.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9980

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://netcdn.co/app/431946152/medieval-warfare-roblox-hack-game-hack
    • http://elibrary.smknesbu.sch.id/repository/coin-master-free-gold-cards-link-2021ee-spins_GM406889139.pdf
    • http://elibrary.smknesbu.sch.id/repository/hack-para-roblox-final-stand_GM431946152.pdf
    • http://elibrary.smknesbu.sch.id/repository/hack-card-collection-coin-master_GM406889139.pdf
    • http://elibrary.smknesbu.sch.id/repository/coin-master-free-spins-link-2021-today_GM406889139.pdf
    • http://elibrary.smknesbu.sch.id/repository/coin-master-free-spins-and-coins-without-human-verification_GM406889139.pdf
    • http://elibrary.smknesbu.sch.id/repository/how-to-buy-robux-for-free_GM431946152.pdf
    • http://elibrary.smknesbu.sch.id/repository/roblox-hack-top_GM431946152.pdf
    • http://elibrary.smknesbu.sch.id/repository/coin-master-free-spins-link-today-new-2021_GM406889139.pdf
    • http://elibrary.smknesbu.sch.id/repository/coin-master-free-spins-link-blogspot_GM406889139.pdf
    • http://elibrary.smknesbu.sch.id/repository/free-roblox-tix-generator-download_GM431946152.pdf
    • http://elibrary.smknesbu.sch.id/repository/cheat-engine-roblox-dbor_GM431946152.pdf
    • http://elibrary.smknesbu.sch.id/repository/how-to-get-robux-fast-no-hack-2021_GM431946152.pdf
    • http://elibrary.smknesbu.sch.id/repository/soros-roblox-hacks-pastebin_GM431946152.pdf
    • http://elibrary.smknesbu.sch.id/repository/hacked-robux-oh-shit-meme_GM431946152.pdf
    • http://elibrary.smknesbu.sch.id/repository/roblox-hack-safe-download_GM431946152.pdf
    • http://elibrary.smknesbu.sch.id/repository/install-roblox-jailbreak-hacks_GM431946152.pdf
    • http://elibrary.smknesbu.sch.id/repository/free-apk-mod-coin-master_GM406889139.pdf
    • http://elibrary.smknesbu.sch.id/repository/veste-arme-free-roblox_GM431946152.pdf
    • http://elibrary.smknesbu.sch.id/repository/how-to-hack-robux_GM431946152.pdf
    • http://elibrary.smknesbu.sch.id/repository/coin-master-hack-without-verification_GM406889139.pdf
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00003027.bin
0465c45e07b8c034daec4366e9ee65e5efb6758c59ffa957fa90e8bdca957fdc
pdf-font-stream PDF embedded font (sfnt) at offset 0x3027 21924 bytes
font_01_sfnt_off00006057.bin
92da4b80f34b066b92318a2ecbfc9d25abcc1e1bb794ec89a2196a54cf146202
pdf-font-stream PDF embedded font (sfnt) at offset 0x6057 19456 bytes