Malicious PDF — malware analysis report

Static analysis result for SHA-256 43a8dd61e3194dff…

MALICIOUS

PDF

43.0 KB Created: 2021-05-19 23:33:36 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: 4daf2087b5100e6bb805c4da82c5872d SHA-1: a94e50bdda5cea1b44daf69ca30c9f3299ae179d SHA-256: 43a8dd61e3194dff303e9b47eb4d3d7a9a83e37006688442192912bcda5a5807
102 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1203 Exploitation for Client Execution

The PDF contains numerous embedded links to external PDF files, many of which appear to be related to game cheats and free downloads, suggesting a lure for users to download potentially malicious content. The presence of a 'download button' heuristic further supports this. The ML classifier also strongly indicated maliciousness.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9971

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://netcdn.xyz/app/479516143/if-you-delete-minecraft-can-you-redownload-it-for-free-game-hack
    • http://laboratorium.sman2metro.sch.id//repository/minecraft-windows-10-free-with-java_GM479516143.pdf
    • http://laboratorium.sman2metro.sch.id/repository/coin-master-hack-game-download-ios_GM406889139.pdf
    • http://laboratorium.sman2metro.sch.id/repository/free-robux-net_GM431946152.pdf
    • http://laboratorium.sman2metro.sch.id/repository/coin-master-links-that-don-t-expire_GM406889139.pdf
    • http://laboratorium.sman2metro.sch.id//repository/free-account-roblox-2021_GM431946152.pdf
    • http://laboratorium.sman2metro.sch.id//repository/how-to-get-free-robux-no-scam_GM431946152.pdf
    • http://laboratorium.sman2metro.sch.id//repository/free-spins-and-coins-coin-master-facebook_GM406889139.pdf
    • http://laboratorium.sman2metro.sch.id/repository/how-to-make-a-minecraft-server-for-free_GM479516143.pdf
    • http://laboratorium.sman2metro.sch.id//repository/coin-master-free-coins-cheat_GM406889139.pdf
    • http://laboratorium.sman2metro.sch.id/repository/coin-master-club-hack_GM406889139.pdf
    • http://laboratorium.sman2metro.sch.id/repository/how-to-make-a-minecraft-java-server-for-free_GM479516143.pdf
    • http://laboratorium.sman2metro.sch.id/repository/minecraft-cracked-client_GM479516143.pdf
    • http://laboratorium.sman2metro.sch.id//repository/minecraft-pe-016-0-apk-download-free_GM479516143.pdf
    • http://laboratorium.sman2metro.sch.id//repository/roblox-rewards-robux_GM431946152.pdf
    • http://laboratorium.sman2metro.sch.id/repository/coin-master-unlimited-spin-link_GM406889139.pdf
    • http://laboratorium.sman2metro.sch.id//repository/coin-master-hacker-club_GM406889139.pdf
    • http://laboratorium.sman2metro.sch.id//repository/coin-master-hack-tool-v1-9-download_GM406889139.pdf
    • http://laboratorium.sman2metro.sch.id/repository/how-to-hack-coin-master_GM406889139.pdf
    • http://laboratorium.sman2metro.sch.id/repository/how-to-get-infinite-robux_GM431946152.pdf
    • http://laboratorium.sman2metro.sch.id/repository/moonactive-free-spins-2021_GM406889139.pdf
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00004cd9.bin
2a7e0304ccdb71999a5959dc5bb323f676905ca7675b4df5a11f7ecb18a3d0e1
pdf-font-stream PDF embedded font (sfnt) at offset 0x4CD9 24912 bytes
font_01_sfnt_off000084fd.bin
18962371c76fb720bd28e976e47cbcb39c5d47198828412c269f5aef32a49cfd
pdf-font-stream PDF embedded font (sfnt) at offset 0x84FD 18592 bytes