Malicious PDF — malware analysis report

Static analysis result for SHA-256 364de053e7db11ad…

MALICIOUS

PDF

48.5 KB Created: 2021-06-09 07:12:57 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: 1915885b61acf8107fb98b089b5bd559 SHA-1: d6e0d5d11149f36a37eab0af25963ad6a17a32c7 SHA-256: 364de053e7db11ad4e86f66ce3645704127b6e3f7c28da328744695f22ebf2dd
102 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1203 Exploitation for Client Execution

The PDF file contains numerous external links, many of which are structured as a link farm pointing to game hacking related content, suggesting a lure for users to download potentially malicious files. The ML classifier also strongly indicated maliciousness. The document body, though heavily obfuscated, contains references to game hacking and URLs that align with the heuristic findings.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9796

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://netcdn.tw/app/431946152/how-to-hack-roblox-model-not-for-sealf-game-hack
    • http://www.dallahgrp.com/uploaded_files/userfiles/files/free-robux-generator-com-roblox-hack_GM431946152.pdf
    • http://www.dallahgrp.com/uploaded_files/userfiles/files/roblox-hack-robux-download-android_GM431946152.pdf
    • http://www.dallahgrp.com/uploaded_files/userfiles/files/how-to-use-cheat-engine-undetected-on-roblox_GM431946152.pdf
    • http://www.dallahgrp.com/uploaded_files/userfiles/files/how-to-get-free-robux-without-doing-anything_GM431946152.pdf
    • http://www.dallahgrp.com/uploaded_files/userfiles/files/can-you-host-a-minecraft-server-for-free_GM479516143.pdf
    • http://www.dallahgrp.com/uploaded_files/userfiles/files/free-robux-sites-2021_GM431946152.pdf
    • http://www.dallahgrp.com/uploaded_files/userfiles/files/how-to-get-free-robux-without-paying_GM431946152.pdf
    • http://www.dallahgrp.com/uploaded_files/userfiles/files/coin-master-daily-link_GM406889139.pdf
    • http://www.dallahgrp.com/uploaded_files/userfiles/files/coin-master-apk-mod-free-download_GM406889139.pdf
    • http://www.dallahgrp.com/uploaded_files/userfiles/files/how-to-get-coin-master-free-spin-link_GM406889139.pdf
    • http://www.dallahgrp.com/uploaded_files/userfiles/files/free-robux-codes_GM431946152.pdf
    • http://www.dallahgrp.com/uploaded_files/userfiles/files/how-to-get-free-robux-without-downloading-any-apps_GM431946152.pdf
    • http://www.dallahgrp.com/uploaded_files/userfiles/files/microsoft-roblox_GM431946152.pdf
    • http://www.dallahgrp.com/uploaded_files/userfiles/files/how-to-get-free-coins-and-free-spins-coin-master_GM406889139.pdf
    • http://www.dallahgrp.com/uploaded_files/userfiles/files/pokemon-go-free-download-for-pc_GM1094591345.pdf
    • http://www.dallahgrp.com/uploaded_files/userfiles/files/how-to-get-free-robux-for-kids_GM431946152.pdf
    • http://www.dallahgrp.com/uploaded_files/userfiles/files/free-robux-no-survey_GM431946152.pdf
    • http://www.dallahgrp.com/uploaded_files/userfiles/files/free-spins-and-coins-coin-master-2021-link_GM406889139.pdf
    • http://www.dallahgrp.com/uploaded_files/userfiles/files/free-coin-master-links_GM406889139.pdf
    • http://www.dallahgrp.com/uploaded_files/userfiles/files/how-to-get-minecraft-for-free-ios_GM479516143.pdf
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_004_off0000546a.bin
6c814888465555ada563103493075717401e74d0b69a6857c03ba5bf3139ca13
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x546A 26272 bytes
font_01_sfnt_off00008ee2.bin
baad2f3f6808f4af03fa9398e38c580c8d846f7f773a947d8cc1f39b2753d31a
pdf-font-stream PDF embedded font (sfnt) at offset 0x8EE2 2844 bytes
font_02_sfnt_off000098a4.bin
1775c1533603c2a0bf1c9ffbd3070c44e3633a97692d4f2a2f692991cc13e91f
pdf-font-stream PDF embedded font (sfnt) at offset 0x98A4 18984 bytes