Malicious PDF — malware analysis report

Static analysis result for SHA-256 7ac6d60d333f38cc…

MALICIOUS

PDF

47.8 KB Created: 2021-05-16 00:01:34 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: 047396a0bc93df4239535a494fdd0eef SHA-1: 83ee25fb8cbcfd0916b8f61e3482bb5ed8bbf9d0 SHA-256: 7ac6d60d333f38cc22a27d7515d2ff721912d43b2dc501aad7706198fa43ae48
102 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains numerous external links, a common tactic for SEO farms or to redirect users to malicious sites. The ML classifier also flagged this PDF as malicious. While no scripts were explicitly extracted, the presence of embedded URLs and the heuristic 'PDF_SEO_LINK_FARM' strongly suggest a malicious intent to drive traffic to potentially harmful content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9013

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://netcdn.xyz/app/431946152/free-roblox-toy-codes-not-used-game-hack
    • https://www.dc-itsolutions.com/userfiles/files/how-to-win-attack-madness-in-coin-master-hack_GM406889139.pdf
    • https://www.dc-itsolutions.com/userfiles/files/free-coins-on-coin-master_GM406889139.pdf
    • https://www.dc-itsolutions.com/userfiles/files/static-moonactive-net-free-spins_GM406889139.pdf
    • https://www.dc-itsolutions.com/userfiles/files/free-roblox-groups_GM431946152.pdf
    • https://www.dc-itsolutions.com/userfiles/files/can-you-really-hack-coin-master_GM406889139.pdf
    • https://www.dc-itsolutions.com/userfiles/files/get-me-free-robux_GM431946152.pdf
    • https://www.dc-itsolutions.com/userfiles/files/coin-master-hack-online-without-human-verification_GM406889139.pdf
    • https://www.dc-itsolutions.com/userfiles/files/is-minecraft-free-on-nintendo-switch_GM479516143.pdf
    • https://www.dc-itsolutions.com/userfiles/files/free-robux-promo-codes_GM431946152.pdf
    • https://www.dc-itsolutions.com/userfiles/files/free-coin-spin-daily-link-for-coin-master-game_GM406889139.pdf
    • https://www.dc-itsolutions.com/userfiles/files/www-bandicam-com-free-robux_GM431946152.pdf
    • https://www.dc-itsolutions.com/userfiles/files/coin-master-free-cards-link_GM406889139.pdf
    • https://www.dc-itsolutions.com/userfiles/files/play-coin-master-for-free_GM406889139.pdf
    • https://www.dc-itsolutions.com/userfiles/files/how-to-get-robux-on-roblox_GM431946152.pdf
    • https://www.dc-itsolutions.com/userfiles/files/free-spin-link-coin-master-today_GM406889139.pdf
    • https://www.dc-itsolutions.com/userfiles/files/free-spin-coin-master-link-download_GM406889139.pdf
    • https://www.dc-itsolutions.com/userfiles/files/roblox-gift-card-for-free_GM431946152.pdf
    • https://www.dc-itsolutions.com/userfiles/files/free-coin-master-spins-and-coins_GM406889139.pdf
    • https://www.dc-itsolutions.com/userfiles/files/coin-master-mod-apk-latest-version-free-download_GM406889139.pdf
    • https://www.dc-itsolutions.com/userfiles/files/roblox-lawsuit_GM431946152.pdf
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_003_off00004c73.bin
e86824b44ef67532f56f599277d39565b295ab3e7b5221fd499a347943830d43
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x4C73 27836 bytes
font_01_sfnt_off00008a79.bin
450e3ee45915afe13702bf1d587eb8b9ad88a8d2113419ac9f2fd116a828e139
pdf-font-stream PDF embedded font (sfnt) at offset 0x8A79 5696 bytes
font_02_sfnt_off0000978a.bin
81fe2106c0d5db37bee378c9af18607d256debaa267bc9b857f52da7d8a402be
pdf-font-stream PDF embedded font (sfnt) at offset 0x978A 18592 bytes