Malicious PDF — malware analysis report

Static analysis result for SHA-256 665b9654a15dbde9…

MALICIOUS

PDF

35.1 KB Created: 2021-06-20 03:43:25 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: 902b9ab73d8f064e506f9ed4ce8066d9 SHA-1: 82e87a37a18857f73cf2ac2f205c3a4c432ae1ba SHA-256: 665b9654a15dbde9f925d6e424cd23122c2767553f1629c21ce4115e5199895f
102 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

This PDF document contains a large number of external links, many of which are SEO-optimized and point to pages related to game cheats and hacks. The document body itself contains a URL that appears to be a direct link to a potential exploit or malware download. The ML classifier also flagged this PDF as malicious with high confidence. The primary attack pattern involves luring users to click these links, likely to download malicious payloads or engage in phishing.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9980

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://netcdn.co/app/431946152/is-roblox-100-cheat-ingine-patched-game-hack
    • https://perpus.uwhs.ac.id/repository/roblox-games-that-give-you-free-robux_GM431946152.pdf
    • https://perpus.uwhs.ac.id/repository/coin-master-mod-apk-unlimited-spin-download-free-full-version_GM406889139.pdf
    • https://perpus.uwhs.ac.id/repository/get-coin-master-hack_GM406889139.pdf
    • https://perpus.uwhs.ac.id/repository/roblox-hack-com_GM431946152.pdf
    • https://perpus.uwhs.ac.id/repository/how-to-get-back-your-hacked-roblox-account_GM431946152.pdf
    • https://perpus.uwhs.ac.id/repository/coin-master-hack-tool-v1-9-download_GM406889139.pdf
    • https://perpus.uwhs.ac.id/repository/how-to-get-free-robux-without-downloading-any-apps_GM431946152.pdf
    • https://perpus.uwhs.ac.id/repository/robux-hack-script-pastebin_GM431946152.pdf
    • https://perpus.uwhs.ac.id/repository/free-robux-without-human-verification-and-no-survey_GM431946152.pdf
    • https://perpus.uwhs.ac.id/repository/free-spins-coin-master-app_GM406889139.pdf
    • https://perpus.uwhs.ac.id/repository/coin-master-free-spins-link-2021_GM406889139.pdf
    • https://perpus.uwhs.ac.id/repository/coin-master-hack-free-spins_GM406889139.pdf
    • https://perpus.uwhs.ac.id/repository/free-robux-code-no-verification_GM431946152.pdf
    • https://perpus.uwhs.ac.id/repository/ash-greninja-free-shopping-in-roblox-on-robloxshopping_GM431946152.pdf
    • https://perpus.uwhs.ac.id/repository/free-robux-games-on-roblox_GM431946152.pdf
    • https://perpus.uwhs.ac.id/repository/free-coin-coin-master_GM406889139.pdf
    • https://perpus.uwhs.ac.id/repository/roblox-rules_GM431946152.pdf
    • https://perpus.uwhs.ac.id/repository/free-spin-coin-master-2021-link_GM406889139.pdf
    • https://perpus.uwhs.ac.id/repository/roblox-fly-hack_GM431946152.pdf
    • https://perpus.uwhs.ac.id/repository/codes-how-to-get-free-robux_GM431946152.pdf
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00003098.bin
c77392fbd3e924665d1941a372b4c9f3d44588e6f6ff546e775b7455af6b0aa9
pdf-font-stream PDF embedded font (sfnt) at offset 0x3098 22432 bytes
font_01_sfnt_off000062ad.bin
193083524d3e04296ab3a1047cff6c1a989ecb3ba46bdbe3f31434ebc9fc9105
pdf-font-stream PDF embedded font (sfnt) at offset 0x62AD 19484 bytes