Malicious PDF — malware analysis report

Static analysis result for SHA-256 7a933cafa9cd71cd…

MALICIOUS

PDF

47.0 KB Created: 2021-06-10 18:18:32 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: 26e64fed888b44d4356d4b76bea7bf23 SHA-1: 56b7464d82f62376a8987ee3518b674f86867781 SHA-256: 7a933cafa9cd71cd9c044ba9511f3b20b5d7aa60252997dcd74eb20f947edb8a
102 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains numerous links to external websites, many of which are structured as PDF files with game-related keywords, suggesting a link farm or SEO poisoning tactic. The presence of a 'download button' heuristic and the ML classifier's high confidence further indicate malicious intent. The primary goal appears to be directing users to download potentially harmful files or software from the listed URLs.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9769

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://netcdn.tw/app/431946152/tiny-tanks-roblox-money-cheat-engine-game-hack
    • http://katalog.iain-padangsidimpuan.ac.id/repository/free-script-executor-roblox_GM431946152.pdf
    • http://katalog.iain-padangsidimpuan.ac.id/repository/how-to-get-750-000-robux-for-free_GM431946152.pdf
    • http://katalog.iain-padangsidimpuan.ac.id/repository/how-do-you-earn-robux-on-roblox_GM431946152.pdf
    • http://katalog.iain-padangsidimpuan.ac.id/repository/hack-coin-master-download-ios_GM406889139.pdf
    • http://katalog.iain-padangsidimpuan.ac.id/repository/roblox-cheat-engine-hacks-download_GM431946152.pdf
    • http://katalog.iain-padangsidimpuan.ac.id/repository/free-appsfor-coin-master-daily-rewards_GM406889139.pdf
    • http://katalog.iain-padangsidimpuan.ac.id/repository/free-links-to-coin-master_GM406889139.pdf
    • http://katalog.iain-padangsidimpuan.ac.id/repository/hacks-para-ganar-robux-gratis-rapido_GM431946152.pdf
    • http://katalog.iain-padangsidimpuan.ac.id/repository/but-link-says-free-robux_GM431946152.pdf
    • http://katalog.iain-padangsidimpuan.ac.id/repository/free-minecraft-java-account_GM479516143.pdf
    • http://katalog.iain-padangsidimpuan.ac.id/repository/is-minecraft-vr-free_GM479516143.pdf
    • http://katalog.iain-padangsidimpuan.ac.id/repository/tofuu-free-robux_GM431946152.pdf
    • http://katalog.iain-padangsidimpuan.ac.id/repository/how-to-get-free-robux-on-pc_GM431946152.pdf
    • http://katalog.iain-padangsidimpuan.ac.id/repository/actual-free-robux_GM431946152.pdf
    • http://katalog.iain-padangsidimpuan.ac.id/repository/how-to-get-free-outrageous-and-robux-earrape_GM431946152.pdf
    • http://katalog.iain-padangsidimpuan.ac.id/repository/minecraft-hacked-client-download_GM479516143.pdf
    • http://katalog.iain-padangsidimpuan.ac.id/repository/free-robux-generator-without-human-verification-2021_GM431946152.pdf
    • http://katalog.iain-padangsidimpuan.ac.id/repository/free-robux-that-actually-works_GM431946152.pdf
    • http://katalog.iain-padangsidimpuan.ac.id/repository/how-to-get-free-spins-on-coin-master-2021-links_GM406889139.pdf
    • http://katalog.iain-padangsidimpuan.ac.id/repository/bad-business-roblox-hack_GM431946152.pdf
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_004_off0000513d.bin
800afbae7fc951aba4ce988365330babb65e2097bf7977dedccd60c61eef2cce
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x513D 24088 bytes
font_01_sfnt_off0000880b.bin
baad2f3f6808f4af03fa9398e38c580c8d846f7f773a947d8cc1f39b2753d31a
pdf-font-stream PDF embedded font (sfnt) at offset 0x880B 2844 bytes
font_02_sfnt_off000091cd.bin
e6dea54e5a37fca100f6b6de11ed57f5e716ab0f7cb5bcb9587f33849fd1b7d0
pdf-font-stream PDF embedded font (sfnt) at offset 0x91CD 19236 bytes