Malicious PDF — malware analysis report

Static analysis result for SHA-256 0f126568cbe71272…

MALICIOUS

PDF

34.3 KB Created: 2021-07-01 19:25:39 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: f5cacb7f897352a7cdc0e9aa7bab20c6 SHA-1: 52d9027f0c87eb93785dc716fb7eb38ac471b3d2 SHA-256: 0f126568cbe7127295eb5b6a5f47f3a02eb867f71efe50b25f3025a1e162fc87
102 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains numerous embedded links, many of which are presented as 'SEO links' pointing to pages offering game hacks and cheats. The ML classifier strongly indicated maliciousness, and the presence of a 'download button' lure further supports a phishing or malware distribution attempt. The document's content and structure suggest it is designed to trick users into clicking malicious links, likely leading to malware downloads or further phishing attempts.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9980

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://netcdn.co/app/431946152/gun-simulator-hack-roblox-game-hack
    • http://perpustakaan.litbang.kemkes.go.id/tawangmangu//repository/coin-master-daily-free-spins-link-today-2021_GM406889139.pdf
    • http://perpustakaan.litbang.kemkes.go.id/tawangmangu/repository/free-roblox-accounts-with-eto3k_GM431946152.pdf
    • http://perpustakaan.litbang.kemkes.go.id/tawangmangu//repository/how-to-get-more-robux_GM431946152.pdf
    • http://perpustakaan.litbang.kemkes.go.id/tawangmangu/repository/hack-coin-master-android_GM406889139.pdf
    • http://perpustakaan.litbang.kemkes.go.id/tawangmangu/repository/coin-master-free-redeem-code_GM406889139.pdf
    • http://perpustakaan.litbang.kemkes.go.id/tawangmangu/repository/proof-how-to-steal-hack-accountson-roblox-get-free-robux_GM431946152.pdf
    • http://perpustakaan.litbang.kemkes.go.id/tawangmangu//repository/free-robux-codes-no-verification-2021_GM431946152.pdf
    • http://perpustakaan.litbang.kemkes.go.id/tawangmangu/repository/coin-master-bonus_GM406889139.pdf
    • http://perpustakaan.litbang.kemkes.go.id/tawangmangu/repository/how-to-get-free-knives-in-roblox-murder-mystery-2_GM431946152.pdf
    • http://perpustakaan.litbang.kemkes.go.id/tawangmangu/repository/get-free-robux_GM431946152.pdf
    • http://perpustakaan.litbang.kemkes.go.id/tawangmangu/repository/how-to-get-free-robux-and-tix-2021_GM431946152.pdf
    • http://perpustakaan.litbang.kemkes.go.id/tawangmangu/repository/coin-master-free-spin-game_GM406889139.pdf
    • http://perpustakaan.litbang.kemkes.go.id/tawangmangu/repository/free-roblox-followers-generator-2021_GM431946152.pdf
    • http://perpustakaan.litbang.kemkes.go.id/tawangmangu/repository/www-roblox-hack-site_GM431946152.pdf
    • http://perpustakaan.litbang.kemkes.go.id/tawangmangu/repository/roblox-hacks-pc_GM431946152.pdf
    • http://perpustakaan.litbang.kemkes.go.id/tawangmangu/repository/free-roblox-accounts-2021-bugmenot_GM431946152.pdf
    • http://perpustakaan.litbang.kemkes.go.id/tawangmangu/repository/free-coin-spin-daily-link-coin-master_GM406889139.pdf
    • http://perpustakaan.litbang.kemkes.go.id/tawangmangu/repository/roblox-free-codes-for-items_GM431946152.pdf
    • http://perpustakaan.litbang.kemkes.go.id/tawangmangu/repository/roblox-gas-station-simulator-money-hack_GM431946152.pdf
    • http://perpustakaan.litbang.kemkes.go.id/tawangmangu//repository/easy-ways-to-get-free-robux_GM431946152.pdf
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000030ac.bin
789103290bd856de88abd2dc84e02c362501d0877426486b0bba0b5afec85a76
pdf-font-stream PDF embedded font (sfnt) at offset 0x30AC 21812 bytes
font_01_sfnt_off00006085.bin
50ed2bef7644b425b21e1a1bc3e7d07c1b833345d6af09e677d9adf5ae413ffd
pdf-font-stream PDF embedded font (sfnt) at offset 0x6085 19280 bytes