Malicious PDF — malware analysis report

Static analysis result for SHA-256 54f9c5554bb46599…

MALICIOUS

PDF

45.1 KB Created: 2021-06-03 05:52:40 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: fa8d0551a95cab5493bf4d14d3c81bc8 SHA-1: 1c8691f4846e5a840063edca3ddb034be777230f SHA-256: 54f9c5554bb46599db2454731468a39f8140edd217220c25f8f2f459c6bed8dc
102 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains numerous links to external resources, many of which appear to be SEO-optimized lures for game-related cheats and currency. The presence of a 'download button' heuristic and the ML classifier's high confidence score indicate a malicious intent to direct users to potentially harmful content. While no scripts were directly extracted, the structure suggests it may embed or link to malicious JavaScript or other executable content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9865

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://netcdn.online/app/431946152/robux-earning-sites-game-hack
    • http://opac.akafarma-aceh.ac.id/repository/legitimate-coin-master-free-spins-apk_GM406889139.pdf
    • http://opac.akafarma-aceh.ac.id/repository/free-robux-2021-no-human-verification_GM431946152.pdf
    • http://opac.akafarma-aceh.ac.id/repository/minecraft-pe-hack-client-2021_GM479516143.pdf
    • http://opac.akafarma-aceh.ac.id/repository/how-to-get-free-robux-generator_GM431946152.pdf
    • http://opac.akafarma-aceh.ac.id/repository/coin-master-no-download-app-but-play-for-free_GM406889139.pdf
    • http://opac.akafarma-aceh.ac.id/repository/coin-master-hack-unlimited-spins-apk-download_GM406889139.pdf
    • http://opac.akafarma-aceh.ac.id/repository/extra-free-spins-for-coin-master_GM406889139.pdf
    • http://opac.akafarma-aceh.ac.id/repository/coin-master-fan-club_GM406889139.pdf
    • http://opac.akafarma-aceh.ac.id/repository/moonactive-coin-master-hack_GM406889139.pdf
    • http://opac.akafarma-aceh.ac.id/repository/free-robux-download_GM431946152.pdf
    • http://opac.akafarma-aceh.ac.id/repository/minecraft-texture-packs-free-download_GM479516143.pdf
    • http://opac.akafarma-aceh.ac.id/repository/how-to-get-free-minecraft-skins_GM479516143.pdf
    • http://opac.akafarma-aceh.ac.id/repository/free-robux-stream_GM431946152.pdf
    • http://opac.akafarma-aceh.ac.id/repository/coin-master-free-spin-link-today-2021_GM406889139.pdf
    • http://opac.akafarma-aceh.ac.id/repository/minecraft-free-download-no-virus_GM479516143.pdf
    • http://opac.akafarma-aceh.ac.id/repository/free-coin-master-coins_GM406889139.pdf
    • http://opac.akafarma-aceh.ac.id/repository/roblox-free-models_GM431946152.pdf
    • http://opac.akafarma-aceh.ac.id/repository/coin-master-free-spins-blogspot_GM406889139.pdf
    • http://opac.akafarma-aceh.ac.id/repository/toolbox-apk_GM479516143.pdf
    • http://opac.akafarma-aceh.ac.id/repository/free-role-in-coin-master_GM406889139.pdf
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_004_off000053a8.bin
18c5e6de45ad056463235ce7eb94bda59ae89be226962236e7815290ff911447
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x53A8 24708 bytes
font_01_sfnt_off00008c7e.bin
86c9cbabc58c05dcca32ff3967a8cba2f2ca88b13f48cfcd06e4bbeea785338f
pdf-font-stream PDF embedded font (sfnt) at offset 0x8C7E 18592 bytes