Malicious PDF — malware analysis report

Static analysis result for SHA-256 25ff199a448ac070…

MALICIOUS

PDF

44.9 KB Created: 2021-06-11 00:06:40 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: 55acea21a1145b8580fca1c4c21f3e55 SHA-1: d0d7c058ceb378324facfc787aca34fcf644f1a3 SHA-256: 25ff199a448ac0705d74ab258aa41e2a76f29c0db2a8f1ad25024f85f36e1f08
102 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains numerous embedded links, identified as a link farm, directing users to external sites. The document body and extracted URLs suggest a lure related to 'free Robux' or game hacks, likely to drive traffic to SEO spam or potentially malicious content. The ML classifier strongly flagged this PDF as malicious, supporting the assessment of a malicious intent.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9865

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://netcdn.tw/app/431946152/earn-free-robux-rbx-blaster-game-hack
    • http://opac.pps.uin-alauddin.ac.id/repository/coin-master-heaven-links-free-spins_GM406889139.pdf
    • http://opac.pps.uin-alauddin.ac.id/repository/how-to-hack-coin-master-with-lucky-patcher_GM406889139.pdf
    • http://opac.pps.uin-alauddin.ac.id/repository/minecraft-apk-download-v1-144-2-free_GM479516143.pdf
    • http://opac.pps.uin-alauddin.ac.id/repository/coin-master-15-free-spin-link-of-last-5-days_GM406889139.pdf
    • http://opac.pps.uin-alauddin.ac.id/repository/rbx-points-get-free-robux_GM431946152.pdf
    • http://opac.pps.uin-alauddin.ac.id/repository/how-to-get-free-robux-2021_GM431946152.pdf
    • http://opac.pps.uin-alauddin.ac.id/repository/robuxlove-net-free-robux_GM431946152.pdf
    • http://opac.pps.uin-alauddin.ac.id/repository/roblox-god-admin-hacks_GM431946152.pdf
    • http://opac.pps.uin-alauddin.ac.id/repository/blue-shirt-roblox-free_GM431946152.pdf
    • http://opac.pps.uin-alauddin.ac.id/repository/how-to-make-a-group-on-roblox-for-free_GM431946152.pdf
    • http://opac.pps.uin-alauddin.ac.id/repository/coin-master-hack-blog_GM406889139.pdf
    • http://opac.pps.uin-alauddin.ac.id/repository/hack-coin-master-spin-apk_GM406889139.pdf
    • http://opac.pps.uin-alauddin.ac.id/repository/free-robux-gift-card-codes_GM431946152.pdf
    • http://opac.pps.uin-alauddin.ac.id/repository/minecraft-free-download-apk-softonic_GM479516143.pdf
    • http://opac.pps.uin-alauddin.ac.id/repository/artmoney-roblox-hack_GM431946152.pdf
    • http://opac.pps.uin-alauddin.ac.id/repository/free-robux-with-no-human-verification_GM431946152.pdf
    • http://opac.pps.uin-alauddin.ac.id/repository/free-robux-just-click_GM431946152.pdf
    • http://opac.pps.uin-alauddin.ac.id/repository/coin-master-daily-free-spin-app_GM406889139.pdf
    • http://opac.pps.uin-alauddin.ac.id/repository/free-roblox-outfits_GM431946152.pdf
    • http://opac.pps.uin-alauddin.ac.id/repository/free-robux-games-that-actually-work-2021_GM431946152.pdf
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_004_off000050d9.bin
3b47b31171d97630a2144b0e257c9686b35352437b208c5a98b777146e9e92a8
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x50D9 25968 bytes
font_01_sfnt_off00008c85.bin
cc0659aaafca46356e06867c8fb1a77ad1bf2056e902c3b9998494ea0c062fff
pdf-font-stream PDF embedded font (sfnt) at offset 0x8C85 18420 bytes