Malicious PDF — malware analysis report

Static analysis result for SHA-256 7442bb24de49cc26…

MALICIOUS

PDF

34.1 KB Created: 2021-07-06 12:43:48 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: a82a911c0b1965f8bff12472d8a78e0f SHA-1: 1bd5bf33c86dd7daffc0161132cff614744e4dc8 SHA-256: 7442bb24de49cc26f05640d844b46097baf5c4989c0ce8ab22b909ff4c72c75d
102 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF document contains numerous links to external websites, many of which are SEO-optimized to appear as legitimate repositories for game-related cheats and hacks, such as 'free Robux'. The ML classifier strongly indicates maliciousness, and the presence of embedded URLs suggests an attempt to redirect users to malicious download sites. The document body itself contains a lure related to 'Free Robux' and includes many of the extracted URLs.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9980

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://netcdn.tw/app/431946152/is-free-robux-real-game-hack
    • http://pustaka1.unindra.id/repository/roblox-free-robux-no-human-verification_GM431946152.pdf
    • http://pustaka1.unindra.id/repository/free-robux-computer-2021_GM431946152.pdf
    • http://pustaka1.unindra.id/repository/free-coins-on-coin-master_GM406889139.pdf
    • http://pustaka1.unindra.id/repository/instante-break-block-roblox-script-hack_GM431946152.pdf
    • http://pustaka1.unindra.id/repository/scaffold-minecraft-hack_GM479516143.pdf
    • http://pustaka1.unindra.id/repository/minecraft_GM479516143.pdf
    • http://pustaka1.unindra.id/repository/get-free-spins-for-coin-master_GM406889139.pdf
    • http://pustaka1.unindra.id/repository/hacks-to-get-free-robux_GM431946152.pdf
    • http://pustaka1.unindra.id/repository/i-want-to-play-roblox-play-free-online_GM431946152.pdf
    • http://pustaka1.unindra.id/repository/minecraft-for-free-on-phone_GM479516143.pdf
    • http://pustaka1.unindra.id/repository/coin-master-free-coins-and-spins-link-2021_GM406889139.pdf
    • http://pustaka1.unindra.id/repository/how-to-earn-free-stars-on-coin-master_GM406889139.pdf
    • http://pustaka1.unindra.id/repository/how-do-you-get-free-robux-without-doing-anything_GM431946152.pdf
    • http://pustaka1.unindra.id/repository/krnl-roblox_GM431946152.pdf
    • http://pustaka1.unindra.id/repository/coin-master-hack-mod_GM406889139.pdf
    • http://pustaka1.unindra.id/repository/coin-master-free-spin-link-today-16-11-2021_GM406889139.pdf
    • http://pustaka1.unindra.id/repository/minecraft-java-for-free_GM479516143.pdf
    • http://pustaka1.unindra.id/repository/free-robux-kid-friendly-no-human-verification_GM431946152.pdf
    • http://pustaka1.unindra.id/repository/coin-master_GM406889139.pdf
    • http://pustaka1.unindra.id/repository/coin-master-free-2021-spin-link_GM406889139.pdf
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00002ea6.bin
53433fd43e53505648cd15f3e02fb20ac0cb910d86b31d8f60985b57822739f9
pdf-font-stream PDF embedded font (sfnt) at offset 0x2EA6 22584 bytes
font_01_sfnt_off0000611a.bin
8d89a61ec1c53a2ba5e83d2650bf3a22bf45cbf3832a400ed197163bd01e5d03
pdf-font-stream PDF embedded font (sfnt) at offset 0x611A 18788 bytes