Malicious PDF — malware analysis report

Static analysis result for SHA-256 67c8ab128631b99b…

MALICIOUS

PDF

33.1 KB Created: 2021-06-26 02:41:47 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: 95fc2d1985b1faf893e5f34c00fbc3dc SHA-1: b56c3fe54c75971189fcdf9be03f0c035c9cd2fe SHA-256: 67c8ab128631b99b3a9f874184da35f964c8d7487dc8fab5c3fba4896628d343
102 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF document contains numerous links to external websites, many of which are hosted on library.atim.ac.id and netcdn.co, and promise free Robux or game hacks. The heuristic 'PDF_SEO_LINK_FARM' indicates a large number of such external links, suggesting a link farm designed to attract users with deceptive content. The ML classifier also flagged this PDF as malicious with high confidence. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9824

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://netcdn.co/app/431946152/how-to-get-free-robux-on-roblox-without-paying-game-hack
    • http://library.atim.ac.id/repository/roblox-hacked-version-download_GM431946152.pdf
    • http://library.atim.ac.id/repository/how-to-hack-kingdom-life-in-roblox_GM431946152.pdf
    • http://library.atim.ac.id/repository/diary-of-a-roblox-hacker_GM431946152.pdf
    • http://library.atim.ac.id/repository/hacks-for-you-free-robux_GM431946152.pdf
    • http://library.atim.ac.id/repository/roblox-free-hair-promo-codes_GM431946152.pdf
    • http://library.atim.ac.id/repository/roblox-infinite-jjump-script-hack_GM431946152.pdf
    • http://library.atim.ac.id/repository/yt-roblox-hacks-admin-commands_GM431946152.pdf
    • http://library.atim.ac.id/repository/free-robux-2021-insoect_GM431946152.pdf
    • http://library.atim.ac.id/repository/free-stuff-in-roblox-catalog-2021_GM431946152.pdf
    • http://library.atim.ac.id/repository/minecraft-book-collection_GM479516143.pdf
    • http://library.atim.ac.id/repository/daily-free-spins-coin-master_GM406889139.pdf
    • http://library.atim.ac.id/repository/free-roblox-clothes-codes_GM431946152.pdf
    • http://library.atim.ac.id/repository/actual-free-robux_GM431946152.pdf
    • http://library.atim.ac.id/repository/roblox-plane-blueprints-free_GM431946152.pdf
    • http://library.atim.ac.id/repository/free-spins-on-coin-master_GM406889139.pdf
    • http://library.atim.ac.id/repository/cheat-codes-for-coin-master_GM406889139.pdf
    • http://library.atim.ac.id/repository/how-to-get-robux-free-roblox-glitch-2021_GM431946152.pdf
    • http://library.atim.ac.id/repository/how-to-get-free-advanced-placing-in-bloxburg-roblox_GM431946152.pdf
    • http://library.atim.ac.id/repository/free-download-gui-roblox-twisted-murder_GM431946152.pdf
    • http://library.atim.ac.id/repository/does-cheat-engine-work-on-roblox_GM431946152.pdf
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00002a88.bin
b9464aedd0d023c1d14c022df879e3d283aabfd9403e3fc7b76d7f2ff6ebb14d
pdf-font-stream PDF embedded font (sfnt) at offset 0x2A88 21740 bytes
font_01_sfnt_off00005a13.bin
8f958d8313dfc82d3a3d7a079a342aafe9a0d2187f762db4851be5734162706c
pdf-font-stream PDF embedded font (sfnt) at offset 0x5A13 19876 bytes