Malicious PDF — malware analysis report

Static analysis result for SHA-256 611444a813d24416…

MALICIOUS

PDF

34.6 KB Created: 2021-06-29 09:31:06 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: ae8ef79c0650dc1887f431df16ffd858 SHA-1: 57256b86f32c351b02c3e0e87d6132a3994a7163 SHA-256: 611444a813d24416b60879bb2523561488bf464b309f18ca663c53bbe869b04d
102 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1203 Exploitation for Client Execution

The PDF contains a large number of external links, many of which are SEO-optimized and point to game-related cheats and hacks. The ML classifier strongly indicated maliciousness, and the presence of a download button lure reinforces the deceptive nature of the document. The primary goal appears to be directing users to external sites that likely host malware or facilitate further compromise.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9980

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://netcdn.co/app/431946152/cool-aoutfits-for-free-in-roblox-game-hack
    • http://opac.kolejkrim.edu.my/repository/coin-master-daily-free-spin-and-coin_GM406889139.pdf
    • http://opac.kolejkrim.edu.my/repository/coin-master-free-spins-no-generator_GM406889139.pdf
    • http://opac.kolejkrim.edu.my/repository/minecraft-life-hacks_GM479516143.pdf
    • http://opac.kolejkrim.edu.my/repository/roblox-robux-generator-free-robux-and-tix_GM431946152.pdf
    • http://opac.kolejkrim.edu.my/repository/free-robux-daily_GM431946152.pdf
    • http://opac.kolejkrim.edu.my/repository/how-to-hack-roblox-players-acounts_GM431946152.pdf
    • http://opac.kolejkrim.edu.my/repository/noclip-hack-download-roblox_GM431946152.pdf
    • http://opac.kolejkrim.edu.my/repository/roblox-promo-codes-that-give-you-free-robux_GM431946152.pdf
    • http://opac.kolejkrim.edu.my/repository/pastebin-robux-hack-911_GM431946152.pdf
    • http://opac.kolejkrim.edu.my/repository/is-there-actually-a-way-to-get-free-robux_GM431946152.pdf
    • http://opac.kolejkrim.edu.my/repository/roblox-hack-for-android-no-survey_GM431946152.pdf
    • http://opac.kolejkrim.edu.my/repository/roblox-royale-high-diamond-hack_GM431946152.pdf
    • http://opac.kolejkrim.edu.my/repository/get-free-robux-without-human-verification_GM431946152.pdf
    • http://opac.kolejkrim.edu.my/repository/coin-master-free-spins-link-today-new_GM406889139.pdf
    • http://opac.kolejkrim.edu.my/repository/free-coins-for-coin-master_GM406889139.pdf
    • http://opac.kolejkrim.edu.my/repository/how-to-get-free-chest-in-coin-master_GM406889139.pdf
    • http://opac.kolejkrim.edu.my/repository/easy-robux-today_GM431946152.pdf
    • http://opac.kolejkrim.edu.my/repository/coin-master-free-spins-hack-ios_GM406889139.pdf
    • http://opac.kolejkrim.edu.my/repository/free-coin-master-spins-blog_GM406889139.pdf
    • http://opac.kolejkrim.edu.my/repository/hack-coin-master-free_GM406889139.pdf
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000030a7.bin
d80c99f52302d42aa121b9876875f7df061b73f945c9c8abdfff19d62fb11270
pdf-font-stream PDF embedded font (sfnt) at offset 0x30A7 22308 bytes
font_01_sfnt_off00006252.bin
98bd602a3c3eb40a0dc147dfcb8856182e43c4ce91f4148c4db1ab38e5a6b973
pdf-font-stream PDF embedded font (sfnt) at offset 0x6252 19012 bytes