Malicious PDF — malware analysis report

Static analysis result for SHA-256 706f0356b6496073…

MALICIOUS

PDF

35.9 KB Created: 2021-07-05 06:03:00 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: abc0ed258205fb28863f0dbdb24e9dda SHA-1: c7c397c36dd635fa4dfe7a67292c7c4873513f89 SHA-256: 706f0356b64960736dc4b0ceec46de373d3f782946c88f44d2c08ea09a253c81
102 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF document contains numerous embedded links to external websites, many of which are structured as SEO-optimized links for game-related hacks and freebies. The ML classifier and PDF link farm heuristics strongly indicate malicious intent, likely to direct users to scam or phishing pages. No scripts were extracted, but the extensive link farm suggests a phishing or scam campaign.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9980

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://netcdn.tw/app/406889139/coin-master-free-spins-daily-game-hack
    • http://perpustakaan.bkkbnkaltim.id/repository/minecraft-free-minecoins_GM479516143.pdf
    • http://perpustakaan.bkkbnkaltim.id/repository/spero-roblox-hack_GM431946152.pdf
    • http://perpustakaan.bkkbnkaltim.id/repository/how-to-get-more-free-coins-on-coin-master_GM406889139.pdf
    • http://perpustakaan.bkkbnkaltim.id/repository/dbzfs-roblox-hack_GM431946152.pdf
    • http://perpustakaan.bkkbnkaltim.id/repository/how-much-tiktok-free-account_GM835599320.pdf
    • http://perpustakaan.bkkbnkaltim.id/repository/roblox-hack-apk-para-pc_GM431946152.pdf
    • http://perpustakaan.bkkbnkaltim.id/repository/coin-master-hack-pro-gamers_GM406889139.pdf
    • http://perpustakaan.bkkbnkaltim.id/repository/how-to-get-1-million-robux-free-birth_GM431946152.pdf
    • http://perpustakaan.bkkbnkaltim.id/repository/coin-master-free-spins-2021_GM406889139.pdf
    • http://perpustakaan.bkkbnkaltim.id/repository/get-free-spins-coin-master-2021_GM406889139.pdf
    • http://perpustakaan.bkkbnkaltim.id/repository/robux-download_GM431946152.pdf
    • http://perpustakaan.bkkbnkaltim.id/repository/cheat-codes-for-building-simulator-roblox_GM431946152.pdf
    • http://perpustakaan.bkkbnkaltim.id/repository/free-400-spins-coin-master_GM406889139.pdf
    • http://perpustakaan.bkkbnkaltim.id/repository/hack-strucid-stop-start-roblox_GM431946152.pdf
    • http://perpustakaan.bkkbnkaltim.id/repository/how-to-get-free-premium-roblox_GM431946152.pdf
    • http://perpustakaan.bkkbnkaltim.id/repository/how-to-hack-to-get-robux_GM431946152.pdf
    • http://perpustakaan.bkkbnkaltim.id/repository/buy-for-free-roblox-builders-club-classic_GM431946152.pdf
    • http://perpustakaan.bkkbnkaltim.id/repository/free-coin-master-coins_GM406889139.pdf
    • http://perpustakaan.bkkbnkaltim.id/repository/how-to-earn-free-spins-coin-master_GM406889139.pdf
    • http://perpustakaan.bkkbnkaltim.id/repository/coin-master-mod-apk-latest-hack-with-unlimited-free-spins_GM406889139.pdf
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_002_off000034b1.bin
6f50d423bf49e4b87c0fb893d086260ad7c18e2ac0b7a1ac9386d6a54ef50f3b
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x34B1 23172 bytes
font_01_sfnt_off000068cd.bin
9b8358e598e07f7d28a63a566b047adfcbccaa59c97f3816d59e3cdcc62e8d14
pdf-font-stream PDF embedded font (sfnt) at offset 0x68CD 18596 bytes