Malicious PDF — malware analysis report

Static analysis result for SHA-256 62972e74354a650b…

MALICIOUS

PDF

44.7 KB Created: 2021-05-13 12:36:00 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: 88059764c48f86b9ac55da687028feb1 SHA-1: adc0ece585d48ad95a364d4a4a13214c4dc3d66f SHA-256: 62972e74354a650b24970dda9874ebb1531d03a3d9f81c9a267da71b0524907f
102 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1203 Exploitation for Client Execution

The PDF document contains numerous embedded links to external websites, many of which are structured as SEO link farms. These links, such as 'https://netcdn.xyz/app/431946152/rbx-com-game-hack', are designed to lure users into downloading potentially malicious files by promising game hacks or free in-game currency. The ML classifier strongly indicated maliciousness, and the presence of a download button lure further supports this. No scripts were extracted, but the document's structure and embedded URLs point to a phishing or malware distribution attempt.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9632

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://netcdn.xyz/app/431946152/rbx-com-game-hack
    • http://sbm-nn.ru/images/coin-master-free-spins-link-2021-ios_GM406889139.pdf
    • http://sbm-nn.ru/images/how-to-get-free-roblox_GM431946152.pdf
    • http://sbm-nn.ru/images/free-robux-no-verification-no-download_GM431946152.pdf
    • http://sbm-nn.ru/images/roblox-2021-hack_GM431946152.pdf
    • http://sbm-nn.ru/images/how-to-get-free-robux-without-doing-anything-2021_GM431946152.pdf
    • http://sbm-nn.ru/images/how-do-you-get-free-roblox_GM431946152.pdf
    • http://sbm-nn.ru/images/how-to-earn-free-robux_GM431946152.pdf
    • http://sbm-nn.ru/images/how-to-get-minecraft-for-free-on-android_GM479516143.pdf
    • http://sbm-nn.ru/images/coin-master-hack-no-survey_GM406889139.pdf
    • http://sbm-nn.ru/images/how-to-get-minecraft-bedrock-edition-on-pc-for-free_GM479516143.pdf
    • http://sbm-nn.ru/images/coin-master-hack-2021-apk_GM406889139.pdf
    • http://sbm-nn.ru/images/free-coin-master-links_GM406889139.pdf
    • http://sbm-nn.ru/images/appsmob-coin-master-hack_GM406889139.pdf
    • http://sbm-nn.ru/images/can-you-actually-get-free-robux_GM431946152.pdf
    • http://sbm-nn.ru/images/wurst-112_GM479516143.pdf
    • http://sbm-nn.ru/images/coin-free-spin_GM406889139.pdf
    • http://sbm-nn.ru/images/orewards-com-free-robux_GM431946152.pdf
    • http://sbm-nn.ru/images/ways-to-get-free-robux_GM431946152.pdf
    • http://sbm-nn.ru/images/apps-for-free-spins-on-coin-master_GM406889139.pdf
    • http://sbm-nn.ru/images/coin-master-hack-pc-2021_GM406889139.pdf
    • http://wolfzscripts
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_003_off000048ff.bin
89a1a98e6f7f2de83f105a479570041e286ed383d6173d2ce86d210fe6012068
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x48FF 24752 bytes
font_01_sfnt_off00008221.bin
82913002036db1b45032d4ed955a7b8d08988246d24ada53eae5870292f663db
pdf-font-stream PDF embedded font (sfnt) at offset 0x8221 3168 bytes
font_02_sfnt_off00008d0f.bin
dffe5730268319e8d6523eb3a7b4d2737e6b1bc7523d2c18f722e59dff9dcb58
pdf-font-stream PDF embedded font (sfnt) at offset 0x8D0F 17972 bytes