Malicious PDF — malware analysis report

Static analysis result for SHA-256 2873c2c0f5be20ab…

MALICIOUS

PDF

34.0 KB Created: 2021-06-23 12:35:14 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: 125568f0853a560a71c470ed797c4a99 SHA-1: adac00c940bdd76e68a13a4d2af49de37480a22a SHA-256: 2873c2c0f5be20abcd6ca572068ce21cbfe9472d7ace859d145c47a22fd025dd
102 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF document contains numerous embedded links, many of which are presented as download opportunities for game hacks and cheats. The heuristic 'PDF_SEO_LINK_FARM' indicates a large number of external links, and the ML classifier strongly flagged this PDF as malicious. The primary goal appears to be directing users to external sites that likely host malware or facilitate further compromise.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9980

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://netcdn.co/app/431946152/roblox-speed-hack-for-pc-game-hack
    • https://perpus.uwhs.ac.id/repository/coin-master-hack-mod-apk-2021_GM406889139.pdf
    • https://perpus.uwhs.ac.id/repository/coin-master-daily-free-rewards_GM406889139.pdf
    • https://perpus.uwhs.ac.id/repository/free-robux-without-human-verification-2021_GM431946152.pdf
    • https://perpus.uwhs.ac.id/repository/download-hacked-games-com-roblox_GM431946152.pdf
    • https://perpus.uwhs.ac.id/repository/free-robux-no-verification-no-survey_GM431946152.pdf
    • https://perpus.uwhs.ac.id/repository/how-did-i-get-hacked-on-roblox_GM431946152.pdf
    • https://perpus.uwhs.ac.id/repository/how-to-get-back-your-hacked-roblox-account_GM431946152.pdf
    • https://perpus.uwhs.ac.id/repository/roblox-hack-snow-shoveling-simulator_GM431946152.pdf
    • https://perpus.uwhs.ac.id/repository/how-to-hack-roblox-for-robux_GM431946152.pdf
    • https://perpus.uwhs.ac.id/repository/free-robux-generator-without-verification_GM431946152.pdf
    • https://perpus.uwhs.ac.id/repository/roblox-studio-how-to-make-a-free-robux-game_GM431946152.pdf
    • https://perpus.uwhs.ac.id/repository/does-roblox-give-you-free-robux_GM431946152.pdf
    • https://perpus.uwhs.ac.id/repository/coin-master-free-spins-and-free-coins_GM406889139.pdf
    • https://perpus.uwhs.ac.id/repository/minecraft-bedrock-download_GM479516143.pdf
    • https://perpus.uwhs.ac.id/repository/25-free-spins-coin-master_GM406889139.pdf
    • https://perpus.uwhs.ac.id/repository/roblox-help-free-robux_GM431946152.pdf
    • https://perpus.uwhs.ac.id/repository/rbxcity-free-robux_GM431946152.pdf
    • https://perpus.uwhs.ac.id/repository/coin-master-hack-without-human-verification-2021_GM406889139.pdf
    • https://perpus.uwhs.ac.id/repository/free-robux-hacks-no-verification_GM431946152.pdf
    • https://perpus.uwhs.ac.id/repository/minecraft-for-ipad-free_GM479516143.pdf
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00002d8c.bin
26809188b9d15e7d50a649bcbef6b12753a985c7ff240fc32b93541d1b28d74a
pdf-font-stream PDF embedded font (sfnt) at offset 0x2D8C 22244 bytes
font_01_sfnt_off00005f25.bin
ff4fbd005697c7c078a93b3ac1eb1c43bf740d2364e7e5b28389370e15f537aa
pdf-font-stream PDF embedded font (sfnt) at offset 0x5F25 19324 bytes