Malicious PDF — malware analysis report

Static analysis result for SHA-256 4bf2ee0be770fc89…

MALICIOUS

PDF

35.6 KB Created: 2021-06-18 08:34:51 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: 3d022af3d9c78cc6f0ba6e81405bac69 SHA-1: e25c43b36ff44945a80058ac928e24179acc8de9 SHA-256: 4bf2ee0be770fc891748b967c13082c703043e35e5542d7ae074ffa93cff8aec
102 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF document contains numerous embedded URLs and a primary URL pointing to a download for a 'free cafe roblox game hack'. The document body and heuristics indicate a link farm designed to lure users to download applications by advertising cheats and hacks for popular games. The ML classifier strongly flagged this PDF as malicious, supporting the conclusion that it is a malicious lure.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9980

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://netcdn.co/app/431946152/free-cafe-roblox-game-hack
    • https://www.ergolight.at/images/how-to-get-free-robux-not-a-scam_GM431946152.pdf
    • https://www.ergolight.at/images/how-to-get-free-robux-easy_GM431946152.pdf
    • https://www.ergolight.at/images/cmaster-club-coin-master-hack_GM406889139.pdf
    • https://www.ergolight.at/images/minecraft-114-4-download_GM479516143.pdf
    • https://www.ergolight.at/images/master-coin-hack-game_GM406889139.pdf
    • https://www.ergolight.at/images/games-that-give-free-robux_GM431946152.pdf
    • https://www.ergolight.at/images/roblox-avatar-customizer-free_GM431946152.pdf
    • https://www.ergolight.at/images/is-minecraft-java-edition-free_GM479516143.pdf
    • https://www.ergolight.at/images/roblox-hacking-website_GM431946152.pdf
    • https://www.ergolight.at/images/today-free-spin-coin-master_GM406889139.pdf
    • https://www.ergolight.at/images/coin-master-free-spins-link-31-march-2021_GM406889139.pdf
    • https://www.ergolight.at/images/coin-master-100-spin-slot_GM406889139.pdf
    • https://www.ergolight.at/images/coin-master-free-coins-and-spins-link_GM406889139.pdf
    • https://www.ergolight.at/images/google-how-do-you-get-robux_GM431946152.pdf
    • https://www.ergolight.at/images/free-minecraft-account_GM479516143.pdf
    • https://www.ergolight.at/images/roblox-free-clothes-hack_GM431946152.pdf
    • https://www.ergolight.at/images/how-to-get-free-spins-for-coin-master_GM406889139.pdf
    • https://www.ergolight.at/images/apps-for-friends-2021-free-robux-site-playgooglecom_GM431946152.pdf
    • https://www.ergolight.at/images/legit-free-spins-coin-master_GM406889139.pdf
    • https://www.ergolight.at/images/free-scripts-for-roblox-studio_GM431946152.pdf
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00003465.bin
957cae5b23d9005bbe22f2313ae12dc99ad27a39112bda7086f9f154ad710b94
pdf-font-stream PDF embedded font (sfnt) at offset 0x3465 23224 bytes
font_01_sfnt_off000067f8.bin
c9b42c4108404f56886579a6fc9bfca46333a59f2f9a28ff53642eda6a59be04
pdf-font-stream PDF embedded font (sfnt) at offset 0x67F8 18464 bytes