Malicious PDF — malware analysis report

Static analysis result for SHA-256 6c9597f6d4ff910c…

MALICIOUS

PDF

33.3 KB Created: 2021-07-03 15:54:36 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: 3451787ec024b0fac2666c84d66fa717 SHA-1: 78ef8b554e09c93e0a570628c0020397ef84a2d1 SHA-256: 6c9597f6d4ff910cfd420463fcd439ea62444aece76e5e530b27adbc23c243bf
102 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1203 Exploitation for Client Execution

The PDF document contains numerous links to external websites, many of which are related to game hacks and free in-game items. The heuristic 'PDF_SEO_LINK_FARM' indicates a large number of these links, suggesting a tactic to drive traffic to potentially malicious sites. The ML classifier also flagged this PDF as malicious with high confidence. The document body, though truncated, contains references to 'Tiktok Free Tiktok' and game-related terms, reinforcing the lure.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9980

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://netcdn.tw/app/835599320/tiktok-free-tiktok-game-hack
    • https://www.modestuae.com/uploaded_files/userfiles/files/how-to-hack-roblox-jailbreak-ios_GM431946152.pdf
    • https://www.modestuae.com/uploaded_files/userfiles/files/coin-master-free-chest-link_GM406889139.pdf
    • https://www.modestuae.com/uploaded_files/userfiles/files/cool-avatars-on-roblox-for-free_GM431946152.pdf
    • https://www.modestuae.com/uploaded_files/userfiles/files/coin-master-daily-free-spins-link-2021_GM406889139.pdf
    • https://www.modestuae.com/uploaded_files/userfiles/files/hack-any-roblox-account-2021_GM431946152.pdf
    • https://www.modestuae.com/uploaded_files/userfiles/files/how-to-get-free-stuff-in-the-catalog-on-roblox_GM431946152.pdf
    • https://www.modestuae.com/uploaded_files/userfiles/files/free-coin-master-spins-2021_GM406889139.pdf
    • https://www.modestuae.com/uploaded_files/userfiles/files/how-to-make-a-custom-rthro-for-free-roblox_GM431946152.pdf
    • https://www.modestuae.com/uploaded_files/userfiles/files/free-exploits-for-roblox-v3rm_GM431946152.pdf
    • https://www.modestuae.com/uploaded_files/userfiles/files/coin-master-links-that-don-t-expire_GM406889139.pdf
    • https://www.modestuae.com/uploaded_files/userfiles/files/worst-roblox-avatars_GM431946152.pdf
    • https://www.modestuae.com/uploaded_files/userfiles/files/free-account-roblox-with-robux_GM431946152.pdf
    • https://www.modestuae.com/uploaded_files/userfiles/files/hacks-for-pinata-simulator-on-roblox_GM431946152.pdf
    • https://www.modestuae.com/uploaded_files/userfiles/files/roblox-free-clothes-hack_GM431946152.pdf
    • https://www.modestuae.com/uploaded_files/userfiles/files/coin-master-game-hack-online_GM406889139.pdf
    • https://www.modestuae.com/uploaded_files/userfiles/files/roblox-hack-ipad-2021_GM431946152.pdf
    • https://www.modestuae.com/uploaded_files/userfiles/files/coin-master-hack-online-generator_GM406889139.pdf
    • https://www.modestuae.com/uploaded_files/userfiles/files/free-robux-hack-no-human-verification-pc_GM431946152.pdf
    • https://www.modestuae.com/uploaded_files/userfiles/files/coin-master-free-download_GM406889139.pdf
    • https://www.modestuae.com/uploaded_files/userfiles/files/working-free-robux-websites_GM431946152.pdf
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00002f40.bin
3276b3a396f7b305030774a0b3f312c427fd41072af360356f8614a8b7e0251b
pdf-font-stream PDF embedded font (sfnt) at offset 0x2F40 22176 bytes
font_01_sfnt_off00006034.bin
c2ea0ec047dda9dae57c7b6fccb39bb9de8bc1653c054defbe0bc43e3e19fae1
pdf-font-stream PDF embedded font (sfnt) at offset 0x6034 17972 bytes