Malicious PDF — malware analysis report

Static analysis result for SHA-256 5c5523ba7b2f7f21…

MALICIOUS

PDF

33.5 KB Created: 2021-07-03 12:18:05 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: 9aff1c3306461d6691f818ddc85c92c0 SHA-1: 76a22535633930b8df66c7c8ed88a78ee381940d SHA-256: 5c5523ba7b2f7f21945bd396091bba734809d9541bb3c6d693242a8c426106b7
102 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1203 Exploitation for Client Execution

The PDF document contains numerous embedded URLs that link to external resources, many of which are related to game hacks and cheats. The ML classifier strongly indicated maliciousness, and the presence of a large number of external links suggests a link farm or a distribution point for further malicious content. The document body, though partially corrupted, contains references to game hacks and the primary malicious URL.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9980

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://netcdn.tw/app/431946152/robux-sign-game-hack
    • http://library.fikes.upnvj.ac.id/repository/hack-minecraft_GM479516143.pdf
    • http://library.fikes.upnvj.ac.id/repository/archery-master-3d-apk-and-mod-free-download-unlimited-coins_GM406889139.pdf
    • http://library.fikes.upnvj.ac.id/repository/coin-master-hack-spins-download_GM406889139.pdf
    • http://library.fikes.upnvj.ac.id/repository/roblox-zone-free-robux_GM431946152.pdf
    • http://library.fikes.upnvj.ac.id/repository/how-to-hack-and-get-free-robux-2021-fast_GM431946152.pdf
    • http://library.fikes.upnvj.ac.id/repository/is-the-free-robux-video-real-from-vixter_GM431946152.pdf
    • http://library.fikes.upnvj.ac.id/repository/roblox-robux-hack-com_GM431946152.pdf
    • http://library.fikes.upnvj.ac.id/repository/coin-master-firebird-card-free_GM406889139.pdf
    • http://library.fikes.upnvj.ac.id/repository/free-robux-2021-no-human-verification_GM431946152.pdf
    • http://library.fikes.upnvj.ac.id/repository/free-codes-to-roblox-redeem-cards-2021_GM431946152.pdf
    • http://library.fikes.upnvj.ac.id/repository/coin-master-hack-spin-generator_GM406889139.pdf
    • http://library.fikes.upnvj.ac.id/repository/www-free-robux-com_GM431946152.pdf
    • http://library.fikes.upnvj.ac.id/repository/get-free-spins-coin-master-2021_GM406889139.pdf
    • http://library.fikes.upnvj.ac.id/repository/roblox-fun-com-free-robux_GM431946152.pdf
    • http://library.fikes.upnvj.ac.id/repository/free-robux-no-human-verification-2021_GM431946152.pdf
    • http://library.fikes.upnvj.ac.id/repository/how-to-get-free-robux-and-tix-no-download_GM431946152.pdf
    • http://library.fikes.upnvj.ac.id/repository/free-roblox-gift-card_GM431946152.pdf
    • http://library.fikes.upnvj.ac.id/repository/free-coin-master-androd-cheats-2021_GM406889139.pdf
    • http://library.fikes.upnvj.ac.id/repository/how-to-use-cheat-engine-to-hack-roblox-2021_GM431946152.pdf
    • http://library.fikes.upnvj.ac.id/repository/free-robux-com-roblox_GM431946152.pdf
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00002daa.bin
bff317686ef5195f3a3c287041274e1a1af243290a728c6ac7142f8c0e72a87a
pdf-font-stream PDF embedded font (sfnt) at offset 0x2DAA 22140 bytes
font_01_sfnt_off00005ee1.bin
b08045f0ef1d16ee57e5480d01b9e5b14967ade0d8d990bfafc75919adf3db5b
pdf-font-stream PDF embedded font (sfnt) at offset 0x5EE1 18672 bytes