Malicious PDF — malware analysis report

Static analysis result for SHA-256 37f7c59c6a255864…

MALICIOUS

PDF

34.1 KB Created: 2021-06-19 20:33:57 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: 0827b18a4e0a2bb9d6bb5df4f4489bcd SHA-1: 8a0144a050fd58cd88c22d6aef152ff5f7d3a10c SHA-256: 37f7c59c6a2558643c0bd4ca2ebfd4386ec6ba449ffe38d2204f6708debf4be1
102 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF document contains numerous links to external websites, many of which are related to game cheats and hacks, suggesting a lure for users to download malicious content. The heuristic PDF_SEO_LINK_FARM indicates a large number of such links, and the ML_NYX_PDF_MALICIOUS model strongly flags the file. The presence of embedded URLs and the document body content, which mentions 'Roblox Free Robux Add To Chrome', further supports the phishing and potential malware distribution attack pattern.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9980

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://netcdn.co/app/431946152/roblox-free-robux-add-to-chrome-game-hack
    • http://digilib.ulm.ac.id/pusat/repository/how-to-hack-someones-roblox-account-with-link_GM431946152.pdf
    • http://digilib.ulm.ac.id/pusat/repository/why-does-roblox-shutdown-when-i-use-cheat-engine_GM431946152.pdf
    • http://digilib.ulm.ac.id/pusat/repository/daily-free-spin-link-in-coin-master_GM406889139.pdf
    • http://digilib.ulm.ac.id/pusat/repository/free-robux-generator-no-survey_GM431946152.pdf
    • http://digilib.ulm.ac.id/pusat/repository/avatar-de-roblox_GM431946152.pdf
    • http://digilib.ulm.ac.id/pusat/repository/minecraft-apk-download-free-11-055_GM479516143.pdf
    • http://digilib.ulm.ac.id/pusat/repository/free-robux-kid-friendly-no-human-verification_GM431946152.pdf
    • http://digilib.ulm.ac.id/pusat/repository/legit-coin-master-hack-october-2021_GM406889139.pdf
    • http://digilib.ulm.ac.id/pusat/repository/roblox-hack-script-twisted-murderer_GM431946152.pdf
    • http://digilib.ulm.ac.id/pusat/repository/coin-master-free-spins-2021-hack_GM406889139.pdf
    • http://digilib.ulm.ac.id/pusat/repository/how-to-get-free-robux-2021-inspect-element_GM431946152.pdf
    • http://digilib.ulm.ac.id/pusat/repository/coin-master-hack-xyz_GM406889139.pdf
    • http://digilib.ulm.ac.id/pusat/repository/earn-robux-today_GM431946152.pdf
    • http://digilib.ulm.ac.id/pusat/repository/free-create-accounts-roblox_GM431946152.pdf
    • http://digilib.ulm.ac.id/pusat/repository/how-to-get-free-robux-2021-no-human-verification_GM431946152.pdf
    • http://digilib.ulm.ac.id/pusat/repository/free-coins-and-spins-for-coin-master_GM406889139.pdf
    • http://digilib.ulm.ac.id/pusat/repository/free-roblox-game-card-pins_GM431946152.pdf
    • http://digilib.ulm.ac.id/pusat/repository/25-free-spins-coin-master_GM406889139.pdf
    • http://digilib.ulm.ac.id/pusat/repository/minecraft-java-edition-free_GM479516143.pdf
    • http://digilib.ulm.ac.id/pusat/repository/free-robux-codes-no-verification_GM431946152.pdf
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00002f37.bin
70e12a28ae6a5882ebde99d094b5594c8db816fb49bab434f1f41c1b7ceb43b5
pdf-font-stream PDF embedded font (sfnt) at offset 0x2F37 21992 bytes
font_01_sfnt_off00005f6f.bin
e406e2370f9e6ebf1ae87b21c71d2396a51247843469dfb8c51322ef358bad86
pdf-font-stream PDF embedded font (sfnt) at offset 0x5F6F 19392 bytes