Malicious PDF — malware analysis report

Static analysis result for SHA-256 280b11e7b6360a7c…

MALICIOUS

PDF

34.9 KB Created: 2021-07-03 17:06:42 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: 3b5a18ad7c5cbf3e23cbbca0f6eb7756 SHA-1: 6c3d52af59cc7802ecbc87607b88e2022f2530a3 SHA-256: 280b11e7b6360a7cc77e90b1850e93052ea41d5f38a334b5fc68335213c9e8d0
102 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious File

The PDF contains numerous embedded links to external websites, many of which are related to game hacks and cheats. The ML classifier and PDF heuristics strongly indicate malicious intent, likely to trick users into downloading malware or visiting phishing sites. The presence of a 'download button' lure further supports this conclusion.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9980

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://netcdn.tw/app/406889139/coin-master-unlimited-spins-game-hack
    • http://www.travelone.ae/userfiles/files/free-robux-pfficial_GM431946152.pdf
    • http://www.travelone.ae/userfiles/files/free-robux-codes-not-used_GM431946152.pdf
    • http://www.travelone.ae/userfiles/files/rc-roblox-hack_GM431946152.pdf
    • http://www.travelone.ae/userfiles/files/how-to-buy-robux-for-free_GM431946152.pdf
    • http://www.travelone.ae/userfiles/files/online-coin-master-hack-here_GM406889139.pdf
    • http://www.travelone.ae/userfiles/files/free-robux-no-survey-or-password_GM431946152.pdf
    • http://www.travelone.ae/userfiles/files/cheats-to-speed-city-on-roblox_GM431946152.pdf
    • http://www.travelone.ae/userfiles/files/cpat-hacker-in-madcity-roblox_GM431946152.pdf
    • http://www.travelone.ae/userfiles/files/my-roblox-account-was-hacked_GM431946152.pdf
    • http://www.travelone.ae/userfiles/files/how-to-make-a-minecraft-pe-server-for-free_GM479516143.pdf
    • http://www.travelone.ae/userfiles/files/roblox-feed-your-pets-hack_GM431946152.pdf
    • http://www.travelone.ae/userfiles/files/minecraft-mojang-free_GM479516143.pdf
    • http://www.travelone.ae/userfiles/files/how-to-get-any-shirt-for-free-on-roblox_GM431946152.pdf
    • http://www.travelone.ae/userfiles/files/free-minecraft-codes-2021_GM479516143.pdf
    • http://www.travelone.ae/userfiles/files/can-you-get-robux-for-free_GM431946152.pdf
    • http://www.travelone.ae/userfiles/files/coin-master-hack-unlimited-spins-apk_GM406889139.pdf
    • http://www.travelone.ae/userfiles/files/how-to-get-free-skins-in-minecraft_GM479516143.pdf
    • http://www.travelone.ae/userfiles/files/coin-master-2021-free-spins-link_GM406889139.pdf
    • http://www.travelone.ae/userfiles/files/minecraft-pe-hack-client_GM479516143.pdf
    • http://www.travelone.ae/userfiles/files/free-spins-coin-master-links-blogspot_GM406889139.pdf
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000034ce.bin
20c990c7a4488127282f0f473d524c3a8b7469436aadde9041840f29ca619cd0
pdf-font-stream PDF embedded font (sfnt) at offset 0x34CE 21752 bytes
font_01_sfnt_off000064a3.bin
2e8c7de27f3ba86e55e5e355ae95bc495c43d663aeff332330d22d9f8881b6ba
pdf-font-stream PDF embedded font (sfnt) at offset 0x64A3 18704 bytes