Malicious PDF — malware analysis report

Static analysis result for SHA-256 314c1d11465c9446…

MALICIOUS

PDF

45.4 KB Created: 2021-06-03 05:42:12 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: 63094c99a6ee07ee9b8b559bbc515ebc SHA-1: 49f1225f1746ff449074068cc862719a31dad1a0 SHA-256: 314c1d11465c94461876070da66b7aca8162d83a013b569f2a882fb7403cad4c
102 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains numerous embedded URLs, many of which are part of a link farm, suggesting an attempt to redirect users to malicious content or scams. The ML classifier also flagged this PDF as malicious. While no scripts were explicitly extracted, the presence of embedded URLs and the PDF structure indicate a likely attempt to exploit users through deceptive links, potentially leading to further malware downloads or phishing attempts.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9864

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://netcdn.online/app/431946152/free-robux-codes-generator-no-verification-game-hack
    • https://surpetgarut-tmcollection.com/ckfinder/userfiles/files/http-bitly-coin-master-free-2021-spins_GM406889139.pdf
    • https://surpetgarut-tmcollection.com/ckfinder/userfiles/files/how-to-get-free-roblox-money_GM431946152.pdf
    • https://surpetgarut-tmcollection.com/ckfinder/userfiles/files/free-robux-codes-generator-no-verification_GM431946152.pdf
    • https://surpetgarut-tmcollection.com/ckfinder/userfiles/files/coin-master-links-free-spins_GM406889139.pdf
    • https://surpetgarut-tmcollection.com/ckfinder/userfiles/files/ways-to-get-free-robux-2021_GM431946152.pdf
    • https://surpetgarut-tmcollection.com/ckfinder/userfiles/files/coin-master-spin-blogspot_GM406889139.pdf
    • https://surpetgarut-tmcollection.com/ckfinder/userfiles/files/how-do-you-get-free-robux-on-roblox_GM431946152.pdf
    • https://surpetgarut-tmcollection.com/ckfinder/userfiles/files/coin-master-free-spins-2021-haktuts_GM406889139.pdf
    • https://surpetgarut-tmcollection.com/ckfinder/userfiles/files/minecraft-education-edition-free_GM479516143.pdf
    • https://surpetgarut-tmcollection.com/ckfinder/userfiles/files/coin-master-free-stuff_GM406889139.pdf
    • https://surpetgarut-tmcollection.com/ckfinder/userfiles/files/hacks-roblox_GM431946152.pdf
    • https://surpetgarut-tmcollection.com/ckfinder/userfiles/files/80-free-spins-coin-master_GM406889139.pdf
    • https://surpetgarut-tmcollection.com/ckfinder/userfiles/files/coin-master-free-spins-app_GM406889139.pdf
    • https://surpetgarut-tmcollection.com/ckfinder/userfiles/files/coin-master-free-spins-link-2021_GM406889139.pdf
    • https://surpetgarut-tmcollection.com/ckfinder/userfiles/files/roblox-its-free_GM431946152.pdf
    • https://surpetgarut-tmcollection.com/ckfinder/userfiles/files/minecraft-pe-apk-download-free-015-0_GM479516143.pdf
    • https://surpetgarut-tmcollection.com/ckfinder/userfiles/files/free-minecraft-java-edition_GM479516143.pdf
    • https://surpetgarut-tmcollection.com/ckfinder/userfiles/files/sites-for-free-spins-for-coin-master_GM406889139.pdf
    • https://surpetgarut-tmcollection.com/ckfinder/userfiles/files/get-free-neon-blue-animal-hat-on-roblox_GM431946152.pdf
    • https://surpetgarut-tmcollection.com/ckfinder/userfiles/files/how-to-make-robux_GM431946152.pdf
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_004_off000053af.bin
28858632749ee89d29320b89ceb1fa4ea84fade6e33124cc1a371648ff049c60
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x53AF 24868 bytes
font_01_sfnt_off00008d5b.bin
a4a7f46a8ec4e4fe0089faa119d4be48f59112184e2c655defb35f5102acccee
pdf-font-stream PDF embedded font (sfnt) at offset 0x8D5B 18776 bytes