Malicious PDF — malware analysis report

Static analysis result for SHA-256 64693c0fe48cbd08…

MALICIOUS

PDF

48.8 KB Created: 2021-05-16 10:53:17 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: f666036ced7209604cb34646590c8922 SHA-1: 26844c4a2a1ac6755b625ac8a395576bf33f388f SHA-256: 64693c0fe48cbd08ab0fd663f24d343bf44db486dc0870219c67baad0a2e6cd0
102 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF document contains numerous embedded links, many of which are related to game cheats and hacks for popular games like Coin Master and Roblox. The heuristic 'PDF_SEO_LINK_FARM' indicates a large number of external links, suggesting a link farm designed to attract users. The ML classifier also flagged this PDF as malicious. The presence of these links and the overall structure strongly suggest a phishing or malware distribution attempt.

Machine Learning

  • Nyx PDF Classifier malicious score 0.8642

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://netcdn.xyz/app/406889139/coin-master-free-link-today-game-hack
    • http://e-learningmin7jakarta.com/__statics/gudangsoal/files/roblox-free-robux-generator_GM431946152.pdf
    • https://e-learningmin7jakarta.com/__statics/gudangsoal/files/coin-master-free-spins-app_GM406889139.pdf
    • https://e-learningmin7jakarta.com/__statics/gudangsoal/files/hack-coin-master-2021-pc_GM406889139.pdf
    • http://e-learningmin7jakarta.com/__statics/gudangsoal/files/free-roblox-accounts-with-builders-club_GM431946152.pdf
    • http://e-learningmin7jakarta.com/__statics/gudangsoal/files/free-2021-robux_GM431946152.pdf
    • http://e-learningmin7jakarta.com/__statics/gudangsoal/files/get-free-robux-com_GM431946152.pdf
    • http://e-learningmin7jakarta.com/__statics/gudangsoal/files/coin-master-hack-tool-without-human-verification_GM406889139.pdf
    • https://e-learningmin7jakarta.com/__statics/gudangsoal/files/offers-to-complete-and-get-free-spins-in-coin-master_GM406889139.pdf
    • https://e-learningmin7jakarta.com/__statics/gudangsoal/files/coin-master-daily-free-spins-link-2021_GM406889139.pdf
    • http://e-learningmin7jakarta.com/__statics/gudangsoal/files/promo-codes-for-free-robux_GM431946152.pdf
    • http://e-learningmin7jakarta.com/__statics/gudangsoal/files/www-roblox-com-free-robux_GM431946152.pdf
    • http://e-learningmin7jakarta.com/__statics/gudangsoal/files/free-coin-master-spin-app_GM406889139.pdf
    • https://e-learningmin7jakarta.com/__statics/gudangsoal/files/how-to-get-free-robux-without-downloading-apps-2021_GM431946152.pdf
    • http://e-learningmin7jakarta.com/__statics/gudangsoal/files/games-on-roblox-that-give-you-free-robux_GM431946152.pdf
    • http://e-learningmin7jakarta.com/__statics/gudangsoal/files/how-to-get-free-robux-com_GM431946152.pdf
    • http://e-learningmin7jakarta.com/__statics/gudangsoal/files/can-i-play-roblox-for-free_GM431946152.pdf
    • https://e-learningmin7jakarta.com/__statics/gudangsoal/files/coin-master-update-2021_GM406889139.pdf
    • https://e-learningmin7jakarta.com/__statics/gudangsoal/files/coin-master-free-spins-and-coins-hack_GM406889139.pdf
    • https://e-learningmin7jakarta.com/__statics/gudangsoal/files/coin-master-free-spins-and-coins_GM406889139.pdf
    • http://e-learningmin7jakarta.com/__statics/gudangsoal/files/how-to-get-free-robux-as-a-kid_GM431946152.pdf
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_003_off00004c19.bin
eb77301ad9d8a929db6e155d964928b36a22b1d8134d3d9f58fa8d6526474f9a
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x4C19 24768 bytes
font_01_sfnt_off0000849c.bin
a17c2a746d49ac23b23e38a371e32fddecfcd91b10cf42ff6155bff6b8a07e91
pdf-font-stream PDF embedded font (sfnt) at offset 0x849C 4028 bytes
font_02_sfnt_off0000923d.bin
6fd7c7f447d66842f81aa8cf197935b17f22157d0c7e9f95622df1b5b4ddf530
pdf-font-stream PDF embedded font (sfnt) at offset 0x923D 2788 bytes
font_03_sfnt_off00009c2d.bin
ac7637c34b6ea6a17139aeea995219f6842183aaecfc204fce9d36f337c74847
pdf-font-stream PDF embedded font (sfnt) at offset 0x9C2D 18232 bytes