Malicious PDF — malware analysis report

Static analysis result for SHA-256 75dac863736296b4…

MALICIOUS

PDF

30.3 KB Created: 2021-07-05 02:43:19 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: 5dbec0f46a5a29c56c5e7be231c3ed38 SHA-1: fc951c94d3f641834a8a4f04cf1a551d41efb964 SHA-256: 75dac863736296b431d1a2cb855977d89b0dde77a4693bbf8447f4eedc27dd14
94 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

This PDF document contains numerous embedded links, many of which point to pages offering free Robux or game hacks, indicating a phishing or scam attempt. The ML classifier strongly flagged this PDF as malicious, and the presence of multiple external links suggests it's designed to redirect users to potentially harmful sites. No scripts were extracted, but the document's structure and content strongly suggest a social engineering lure.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9988

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://netcdn.tw/app/479516143/minecraft-hack-2021-game-hack
    • http://perpustakaan.sman2bondowoso.sch.id/repository/how-do-you-get-free-robux-on-roblox_GM431946152.pdf
    • http://perpustakaan.sman2bondowoso.sch.id/repository/free-roblox-accounts-2021_GM431946152.pdf
    • http://perpustakaan.sman2bondowoso.sch.id/repository/free-links-for-coin-master-2021_GM406889139.pdf
    • http://perpustakaan.sman2bondowoso.sch.id/repository/rbxoffers-earn-free-robux_GM431946152.pdf
    • http://perpustakaan.sman2bondowoso.sch.id/repository/free-robux-games-that-actually-work-2021_GM431946152.pdf
    • http://perpustakaan.sman2bondowoso.sch.id/repository/coin-master-hack-version_GM406889139.pdf
    • http://perpustakaan.sman2bondowoso.sch.id/repository/cheats-for-bird-simulator-roblox_GM431946152.pdf
    • http://perpustakaan.sman2bondowoso.sch.id/repository/get-me-robux-for-free_GM431946152.pdf
    • http://perpustakaan.sman2bondowoso.sch.id/repository/robux-withdraw_GM431946152.pdf
    • http://perpustakaan.sman2bondowoso.sch.id/repository/how-to-hack-coin-master-spin-in-hindi_GM406889139.pdf
    • http://perpustakaan.sman2bondowoso.sch.id/repository/free-coins-and-spins-in-coin-master_GM406889139.pdf
    • http://perpustakaan.sman2bondowoso.sch.id/repository/roblox-free-body_GM431946152.pdf
    • http://perpustakaan.sman2bondowoso.sch.id/repository/how-to-get-free-robux-in-roblox-2021-easy_GM431946152.pdf
    • http://perpustakaan.sman2bondowoso.sch.id/repository/coin-master-game-hack-kaise-kare_GM406889139.pdf
    • http://perpustakaan.sman2bondowoso.sch.id/repository/get-me-free-roblox_GM431946152.pdf
    • http://perpustakaan.sman2bondowoso.sch.id/repository/coin-master-links-for-free-spins_GM406889139.pdf
    • http://perpustakaan.sman2bondowoso.sch.id/repository/free-minecraft-java-edition-codes_GM479516143.pdf
    • http://perpustakaan.sman2bondowoso.sch.id/repository/how-to-get-1-million-robux-hack_GM431946152.pdf
    • http://perpustakaan.sman2bondowoso.sch.id/repository/coin-master-free-spins-and-coins-daily_GM406889139.pdf
    • http://perpustakaan.sman2bondowoso.sch.id/repository/roblox-digimon-aurity-level-hack_GM431946152.pdf
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000309f.bin
32115245a7ae58a4975c6c4ae270bf95935dbe6c416512a51a25a4f50d59d700
pdf-font-stream PDF embedded font (sfnt) at offset 0x309F 22800 bytes