Malicious PDF — malware analysis report

Static analysis result for SHA-256 51ef5e046114e637…

MALICIOUS

PDF

37.5 KB Created: 2021-06-26 14:25:02 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: 0ca1d7ec0990b4ce7ad6f63f6bb127f5 SHA-1: bfdeba1cba6ebb6b0ba3971b5345f51d273e2fbb SHA-256: 51ef5e046114e6373a4cd239412b56e871c845442da03d66a7fa98fe2ac84ff2
102 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains numerous embedded URLs and a document body that advertises free downloads and hacks for popular games, indicating a lure for potentially malicious content. The heuristic 'PDF_SEO_LINK_FARM' and the ML classifier strongly suggest malicious intent, likely to redirect users to phishing or malware download sites. No scripts were extracted, but the extensive list of external links points to a content-luring attack pattern.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9981

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://netcdn.co/app/431946152/roblox-avatar-free-download-game-hack
    • http://uas.com.my/uploaded_files/userfiles/files/www-roblox-com-free-items_GM431946152.pdf
    • http://uas.com.my/uploaded_files/userfiles/files/daily-free-spins-coin-master-2021_GM406889139.pdf
    • http://uas.com.my/uploaded_files/userfiles/files/free-robux-easy_GM431946152.pdf
    • http://uas.com.my/uploaded_files/userfiles/files/how-to-get-free-faces-on-roblox_GM431946152.pdf
    • http://uas.com.my/uploaded_files/userfiles/files/fast-hacks-robux_GM431946152.pdf
    • http://uas.com.my/uploaded_files/userfiles/files/how-to-get-free-robux-no-waiting-2021_GM431946152.pdf
    • http://uas.com.my/uploaded_files/userfiles/files/how-to-get-roblox-free-aventures_GM431946152.pdf
    • http://uas.com.my/uploaded_files/userfiles/files/free-spin-in-coin-master_GM406889139.pdf
    • http://uas.com.my/uploaded_files/userfiles/files/how-to-play-minecraft-for-free-on-pc_GM479516143.pdf
    • http://uas.com.my/uploaded_files/userfiles/files/coin-master-free-spins-link-2021-iphone_GM406889139.pdf
    • http://uas.com.my/uploaded_files/userfiles/files/minecraft-dungeons-free-download-pc_GM479516143.pdf
    • http://uas.com.my/uploaded_files/userfiles/files/coin-master-free-daily-spins-and-coins_GM406889139.pdf
    • http://uas.com.my/uploaded_files/userfiles/files/chronosploit-roblox-hack_GM431946152.pdf
    • http://uas.com.my/uploaded_files/userfiles/files/coin-master-twitter_GM406889139.pdf
    • http://uas.com.my/uploaded_files/userfiles/files/202100-robux-promo-code-free_GM431946152.pdf
    • http://uas.com.my/uploaded_files/userfiles/files/roblox-superhero-package-free_GM431946152.pdf
    • http://uas.com.my/uploaded_files/userfiles/files/daily-free-spins-coin-master_GM406889139.pdf
    • http://uas.com.my/uploaded_files/userfiles/files/how-to-free-robux_GM431946152.pdf
    • http://uas.com.my/uploaded_files/userfiles/files/como-generar-coin-master-free-spins_GM406889139.pdf
    • http://uas.com.my/uploaded_files/userfiles/files/free-spins-and-coins-coin-master-2021-link_GM406889139.pdf
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00003b59.bin
f721c9b47c5211a835d50b24bc8bce2cc868b31911b88b6ad39c823e57525ae8
pdf-font-stream PDF embedded font (sfnt) at offset 0x3B59 22248 bytes
font_01_sfnt_off00006cd3.bin
01fb4f33a883e04b551ccd9585ba5377978b0a3b980e0cb7449e7d2171b8d75c
pdf-font-stream PDF embedded font (sfnt) at offset 0x6CD3 19372 bytes