Malicious PDF — malware analysis report

Static analysis result for SHA-256 6bd2fb46694fe1bd…

MALICIOUS

PDF

43.6 KB Created: 2021-05-15 14:27:43 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: 4872d98dd58e62c706154c7b0c9fe32e SHA-1: ebb6e87fff6f2669a6c88a4f465d1912d7be18fd SHA-256: 6bd2fb46694fe1bd8b377eaecd1191448b6552652d148f003660290646101e87
102 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains numerous embedded links to external websites, many of which are structured as SEO-optimized links for game-related downloads and cheats. The presence of a 'download button' heuristic and the ML classifier's high confidence score indicate malicious intent. The primary attack pattern involves luring users to download potentially harmful files from these external URLs.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9969

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://netcdn.xyz/app/479516143/minecraft-1.14-4-download-game-hack
    • http://jdih.ptun-denpasar.go.id/assets/CKImages/files/how-to-get-free-coins-on-coin-master-hack_GM406889139.pdf
    • http://jdih.ptun-denpasar.go.id/assets/CKImages/files/roblox-18_GM431946152.pdf
    • http://jdih.ptun-denpasar.go.id/assets/CKImages/files/how-to-get-free-coins-for-coin-master_GM406889139.pdf
    • http://jdih.ptun-denpasar.go.id/assets/CKImages/files/websites-to-get-free-robux_GM431946152.pdf
    • http://jdih.ptun-denpasar.go.id/assets/CKImages/files/free-spin-link-coin-master_GM406889139.pdf
    • http://jdih.ptun-denpasar.go.id/assets/CKImages/files/free-robux-games-that-actually-work-2021_GM431946152.pdf
    • http://jdih.ptun-denpasar.go.id/assets/CKImages/files/how-to-get-free-robux-easy-2021_GM431946152.pdf
    • http://jdih.ptun-denpasar.go.id/assets/CKImages/files/roblox-character-free_GM431946152.pdf
    • http://jdih.ptun-denpasar.go.id/assets/CKImages/files/free-money-and-spins-coin-master_GM406889139.pdf
    • http://jdih.ptun-denpasar.go.id/assets/CKImages/files/how-to-hack-roblox-accounts-2021-easy_GM431946152.pdf
    • http://jdih.ptun-denpasar.go.id/assets/CKImages/files/roblox-no-download-hack_GM431946152.pdf
    • http://jdih.ptun-denpasar.go.id/assets/CKImages/files/free-minecraft-survival-server_GM479516143.pdf
    • http://jdih.ptun-denpasar.go.id/assets/CKImages/files/free-coin-master-spins-for-today_GM406889139.pdf
    • http://jdih.ptun-denpasar.go.id/assets/CKImages/files/how-can-u-get-free-robux_GM431946152.pdf
    • http://jdih.ptun-denpasar.go.id/assets/CKImages/files/coin-master-card-collection-hack_GM406889139.pdf
    • http://jdih.ptun-denpasar.go.id/assets/CKImages/files/roblox-robux-hack-generator_GM431946152.pdf
    • http://jdih.ptun-denpasar.go.id/assets/CKImages/files/coin-master-hack-without-verification-code_GM406889139.pdf
    • http://jdih.ptun-denpasar.go.id/assets/CKImages/files/earn-rbx_GM431946152.pdf
    • http://jdih.ptun-denpasar.go.id/assets/CKImages/files/get-free-spins-coin-master-2021_GM406889139.pdf
    • http://jdih.ptun-denpasar.go.id/assets/CKImages/files/daily-free-spin-link-in-coin-master_GM406889139.pdf
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_003_off00004cde.bin
78f010c645793e868563056784bb3744c1d8c934571ced4e315616e95a9848c5
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x4CDE 25548 bytes
font_01_sfnt_off0000878e.bin
6d95bb5e0251b920a9764ccc918690a910b4901eebdf6c0878bf0d7e0e2360a0
pdf-font-stream PDF embedded font (sfnt) at offset 0x878E 18524 bytes