Malicious PDF — malware analysis report

Static analysis result for SHA-256 2e2438f11718edbc…

MALICIOUS

PDF

36.5 KB Created: 2021-05-10 17:07:01 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: 6102740c246a98e75d2bcd6d165620e9 SHA-1: 21034516e40520bb0bd51cb0b5cdb79d1abbec19 SHA-256: 2e2438f11718edbccd2ef8877b53855d32e08bd29746d6c5b9994cc314227150
94 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

This PDF document contains numerous links to external websites, many of which are SEO-optimized and promise free Robux or game hacks. The ML classifier and the PDF link farm heuristic strongly indicate malicious intent, likely to direct users to scam or phishing sites. Although no scripts were explicitly extracted, the PDF structure and embedded URLs suggest a phishing or social engineering attack.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9997

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://netcdn.xyz/app/431946152/robuxmatch.com-free-robux-game-hack
    • http://library.ulb.ac.id/repository/apps-to-get-free-robux_GM431946152.pdf
    • http://library.ulb.ac.id/repository/free-coin-coin-master_GM406889139.pdf
    • http://library.ulb.ac.id//repository/demon-roblox_GM431946152.pdf
    • http://library.ulb.ac.id//repository/toolbox-mod_GM479516143.pdf
    • http://library.ulb.ac.id//repository/coin-master-spin-hack-no-verification_GM406889139.pdf
    • http://library.ulb.ac.id//repository/coin-master-free-coins-link-march-2021_GM406889139.pdf
    • http://library.ulb.ac.id//repository/coin-master-daily-free-spins-link-haktuts_GM406889139.pdf
    • http://library.ulb.ac.id//repository/how-can-i-get-free-spins-on-coin-master_GM406889139.pdf
    • http://library.ulb.ac.id//repository/coin-master-free-spins-may-11-2021_GM406889139.pdf
    • http://library.ulb.ac.id//repository/coin-master-unlimited-spin-apk-free-download_GM406889139.pdf
    • http://library.ulb.ac.id/repository/coin-master-time-speed-hack_GM406889139.pdf
    • http://library.ulb.ac.id//repository/haktuts-coin-master-hack_GM406889139.pdf
    • http://library.ulb.ac.id/repository/moonactive-coin-master_GM406889139.pdf
    • http://library.ulb.ac.id/repository/can-you-get-robux-for-free_GM431946152.pdf
    • http://library.ulb.ac.id//repository/minecraft-java-edition-free_GM479516143.pdf
    • http://library.ulb.ac.id//repository/get-free-robux-without-human-verification_GM431946152.pdf
    • http://library.ulb.ac.id/repository/free-coin-and-spin-in-coin-master_GM406889139.pdf
    • http://library.ulb.ac.id/repository/coin-master-free-spins-today-39_GM406889139.pdf
    • http://library.ulb.ac.id//repository/roblox-free-clothes-generator_GM431946152.pdf
    • http://library.ulb.ac.id//repository/free-coins-and-spins-for-coin-master-game_GM406889139.pdf
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_003_off00004730.bin
7220c02864220dda8293052ec4ed60e21547a7cda9befc225206c87fff6a406d
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x4730 29668 bytes