Malicious PDF — malware analysis report

Static analysis result for SHA-256 64821060fa6a7fc2…

MALICIOUS

PDF

35.0 KB Created: 2021-07-05 03:45:47 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: fbe688a5cdf182f99fcc0eee6d2cabf1 SHA-1: ab44b940462b9078383c3f4a4766a8264dd45a9d SHA-256: 64821060fa6a7fc2772a08b1d5e0d09b1cc44a59d41cb9336c66056d52c9b4b2
102 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF document contains numerous embedded URLs and a "download button" lure, strongly suggesting a phishing or scam attempt. The ML classifier and PDF link farm heuristics confirm the malicious nature of the document. The primary intent appears to be directing users to download files or access services related to popular games, likely as a pretext for malware distribution or credential harvesting.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9980

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://netcdn.tw/app/431946152/free-roblox-accounts-game-hack
    • http://lib3tell.stptrisakti.net/repository/free-roblox-account-gen_GM431946152.pdf
    • http://lib3tell.stptrisakti.net/repository/minecraft-apk-download-v1-144-2-free_GM479516143.pdf
    • http://lib3tell.stptrisakti.net//repository/coin-master-spin-link-today_GM406889139.pdf
    • http://lib3tell.stptrisakti.net//repository/coin-master-hack-ios-2021_GM406889139.pdf
    • http://lib3tell.stptrisakti.net/repository/how-to-get-girl-hair-on-roblox-for-free_GM431946152.pdf
    • http://lib3tell.stptrisakti.net//repository/how-to-get-free-gamepasses-on-roblox_GM431946152.pdf
    • http://lib3tell.stptrisakti.net/repository/free-robux-codes-no-download_GM431946152.pdf
    • http://lib3tell.stptrisakti.net/repository/coin-master-free-spins-app-android_GM406889139.pdf
    • http://lib3tell.stptrisakti.net//repository/free-minecraft-bedrock_GM479516143.pdf
    • http://lib3tell.stptrisakti.net/repository/free-robux-app_GM431946152.pdf
    • http://lib3tell.stptrisakti.net/repository/wizard-hacks_GM479516143.pdf
    • http://lib3tell.stptrisakti.net/repository/can-i-get-free-robux_GM431946152.pdf
    • http://lib3tell.stptrisakti.net//repository/coin-master-heaven-free-spins-link-2021_GM406889139.pdf
    • http://lib3tell.stptrisakti.net/repository/www-coin-master-hack-tk_GM406889139.pdf
    • http://lib3tell.stptrisakti.net/repository/best-free-coin-master-spins_GM406889139.pdf
    • http://lib3tell.stptrisakti.net/repository/how-to-get-free-robux-no-scam_GM431946152.pdf
    • http://lib3tell.stptrisakti.net/repository/coin-master-free-spins-link-2021_GM406889139.pdf
    • http://lib3tell.stptrisakti.net/repository/minecraft-handbook_GM479516143.pdf
    • http://lib3tell.stptrisakti.net//repository/how-to-get-minecoins-in-minecraft-for-free_GM479516143.pdf
    • http://lib3tell.stptrisakti.net//repository/online-coin-master-free-spin-app_GM406889139.pdf
    • https://www.roblox.com/.I
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000305f.bin
dfdb5b38b231f3034686fa7d764150de2467b850146cf6b8cd93b8506061d3ca
pdf-font-stream PDF embedded font (sfnt) at offset 0x305F 23000 bytes
font_01_sfnt_off0000640a.bin
dca2f27ecdd8c5a39a81753fb954dd30ae74f07dc947ace6cc80d7c98cb68ba8
pdf-font-stream PDF embedded font (sfnt) at offset 0x640A 18896 bytes