Malicious PDF — malware analysis report

Static analysis result for SHA-256 5b9a82a4f897d365…

MALICIOUS

PDF

42.8 KB Created: 2021-05-19 14:41:01 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: ac7a0e0587c11e4aa51f543e2f7862ac SHA-1: 898dd745e72b25bf68cec17af68669ca5bbb4f8a SHA-256: 5b9a82a4f897d3656fa7c69c1f6d9741098c033f4ce59def022565d186d3a771
102 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF document contains numerous embedded links and a link farm heuristic indicates a high volume of external links, many of which point to websites offering game-related cheats and currency. The ML classifier strongly flagged this PDF as malicious, suggesting it is part of a phishing or scam campaign. While no scripts were directly extracted, the presence of embedded URIs and the link farm suggest the document's primary function is to redirect users to potentially malicious sites.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9971

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://netcdn.xyz/app/431946152/how-to-get-roebucks-on-roblox-game-hack
    • http://dana1157.com/images/coin-master-free-coins-and-spins-2021_GM406889139.pdf
    • http://dana1157.com/images/minecraft-hacked-client-download_GM479516143.pdf
    • http://dana1157.com/images/get-robux-today_GM431946152.pdf
    • http://dana1157.com/images/www-claim-gg-to-earn-free-robux_GM431946152.pdf
    • http://dana1157.com/images/free-robux-no-verification-or-survey-2021_GM431946152.pdf
    • http://dana1157.com/images/earn-free-robux_GM431946152.pdf
    • http://dana1157.com/images/free-coins-coin-master-daily_GM406889139.pdf
    • http://dana1157.com/images/haktuts-coin-master-free-spin-link_GM406889139.pdf
    • http://dana1157.com/images/free-robux-without-verification-or-survey_GM431946152.pdf
    • http://dana1157.com/images/how-to-get-free-spins-on-coin-master-android_GM406889139.pdf
    • http://dana1157.com/images/como-hackear-coin-master-sin-verificacion-humana_GM406889139.pdf
    • http://dana1157.com/images/how-to-get-free-robux-not-a-scam_GM431946152.pdf
    • http://dana1157.com/images/coin-master-free-stuff_GM406889139.pdf
    • http://dana1157.com/images/free-coins-and-spins-for-coin-master-game_GM406889139.pdf
    • http://dana1157.com/images/free-foxy-food-coin-master_GM406889139.pdf
    • http://dana1157.com/images/free-robux-generator-2021_GM431946152.pdf
    • http://dana1157.com/images/free-robux-by-watching-ads_GM431946152.pdf
    • http://dana1157.com/images/minecraft-mods-download-free_GM479516143.pdf
    • http://dana1157.com/images/earn-robux-sites_GM431946152.pdf
    • http://dana1157.com/images/free-online-spins-coin-master_GM406889139.pdf
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000048d5.bin
eea749340b18bda2619c313e1847fec73e7b0675e46e84542af877ed096c7fd6
pdf-font-stream PDF embedded font (sfnt) at offset 0x48D5 26780 bytes
font_01_sfnt_off00008453.bin
2b946b4d7a1998aebf51f19e9cbc0e13d461cd82a275ed989f3ac0cfcc0a4974
pdf-font-stream PDF embedded font (sfnt) at offset 0x8453 18364 bytes