Malicious PDF — malware analysis report

Static analysis result for SHA-256 61d36703e8547a13…

MALICIOUS

PDF

46.9 KB Created: 2021-06-11 06:22:05 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: 7cdf572ccb94ac14b0fc1f3f7d97c5b0 SHA-1: 712669758b245b540518f70c58bc37e12c768072 SHA-256: 61d36703e8547a13b6b06998b47c3421078016df56c52068a8803e6bf9b9cea1
102 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains numerous embedded URLs and a document body that explicitly promotes 'Free Robux' and game hacks, indicating a phishing or scam lure. The heuristic firings confirm the presence of many external links, including a link farm, and a machine learning classifier flagged the PDF as malicious. While no scripts were directly extracted, the document's structure and content strongly suggest it's designed to redirect users to malicious websites.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9832

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://netcdn.tw/app/431946152/claim-free-robux-without-human-verification-game-hack
    • https://cogp.greentrade.org.tw/image/data/files/how-to-get-free-robux-website_GM431946152.pdf
    • https://cogp.greentrade.org.tw/image/data/files/coin-master-hack-mod-apk-35-8_GM406889139.pdf
    • https://cogp.greentrade.org.tw/image/data/files/get-me-robux-for-free_GM431946152.pdf
    • https://cogp.greentrade.org.tw/image/data/files/coin-master-freebies_GM406889139.pdf
    • https://cogp.greentrade.org.tw/image/data/files/free-robux-no-human-verification-or-survey-2021_GM431946152.pdf
    • https://cogp.greentrade.org.tw/image/data/files/rbxdemon_GM431946152.pdf
    • https://cogp.greentrade.org.tw/image/data/files/roblox-exploit-razzberry-and-tools-hack_GM431946152.pdf
    • https://cogp.greentrade.org.tw/image/data/files/how-to-change-your-username-on-roblox-for-free_GM431946152.pdf
    • https://cogp.greentrade.org.tw/image/data/files/roblox-free-robux-website_GM431946152.pdf
    • https://cogp.greentrade.org.tw/image/data/files/rbx-roblox-free_GM431946152.pdf
    • https://cogp.greentrade.org.tw/image/data/files/free-robux-websites-not-clickbait_GM431946152.pdf
    • https://cogp.greentrade.org.tw/image/data/files/robux-match_GM431946152.pdf
    • https://cogp.greentrade.org.tw/image/data/files/coin-master-daily-free-cards_GM406889139.pdf
    • https://cogp.greentrade.org.tw/image/data/files/coin-master-free-spins-links-2021_GM406889139.pdf
    • https://cogp.greentrade.org.tw/image/data/files/free-spins-coin-master-facebook_GM406889139.pdf
    • https://cogp.greentrade.org.tw/image/data/files/minecraft-maps-pe-free-download_GM479516143.pdf
    • https://cogp.greentrade.org.tw/image/data/files/free-spin-coin-master-2021-link_GM406889139.pdf
    • https://cogp.greentrade.org.tw/image/data/files/free-whatsapp-tik-tok-status-download_GM835599320.pdf
    • https://cogp.greentrade.org.tw/image/data/files/hack-version-of-coin-master-apk-download_GM406889139.pdf
    • https://cogp.greentrade.org.tw/image/data/files/coin-master-spin-ml_GM406889139.pdf
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_004_off0000511c.bin
125d4385245f740f561d773b35815fe00ab01a7431d4a3be724a8782561d9f01
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x511C 28720 bytes
font_01_sfnt_off00009203.bin
e24699b499c4918051a88b4a7df27f2785cff25e19cd1876b240eab16d4aecd0
pdf-font-stream PDF embedded font (sfnt) at offset 0x9203 19296 bytes