Malicious PDF — malware analysis report

Static analysis result for SHA-256 7f5598dc4a1b7d27…

MALICIOUS

PDF

35.0 KB Created: 2021-07-03 18:18:14 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: e06cb4ba881b77dd0fca9c38df1f6e09 SHA-1: 068b6ca50441783fe98f14d385d1567551c3bee2 SHA-256: 7f5598dc4a1b7d27258d22522c45190ee6c47b08bdc0c9ed3829390a5131496c
102 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

This PDF document contains numerous embedded links, identified as a link farm, that direct users to websites offering game cheats and hacks for popular games like Coin Master and Roblox. The ML classifier strongly indicated maliciousness, and the presence of external URIs suggests an attempt to redirect users to potentially harmful content. The document body, though partially garbled, contains references to these game-related lures and URLs.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9980

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://netcdn.tw/app/406889139/coinmasterfreespins-game-hack
    • http://daskrimti-jabar.web.id/library/repository/how-to-get-the-mew-game-pass-for-free-roblox_GM431946152.pdf
    • http://daskrimti-jabar.web.id/library/repository/conseguir-robux-gratis-hack-inspeccionar_GM431946152.pdf
    • http://daskrimti-jabar.web.id/library/repository/minecraft-pe-hacks_GM479516143.pdf
    • http://daskrimti-jabar.web.id/library//repository/how-to-get-minecraft-for-free-on-android_GM479516143.pdf
    • http://daskrimti-jabar.web.id/library/repository/giving-free-robux-in-this-roblox-group_GM431946152.pdf
    • http://daskrimti-jabar.web.id/library/repository/free-download-coin-master_GM406889139.pdf
    • http://daskrimti-jabar.web.id/library/repository/minecraft-games-to-play-for-free_GM479516143.pdf
    • http://daskrimti-jabar.web.id/library/repository/real-ways-to-get-free-robux_GM431946152.pdf
    • http://daskrimti-jabar.web.id/library/repository/roblox-q-to-speedhack-script-hack_GM431946152.pdf
    • http://daskrimti-jabar.web.id/library//repository/coin-master-daily-rewards_GM406889139.pdf
    • http://daskrimti-jabar.web.id/library/repository/chinese-free-roblox_GM431946152.pdf
    • http://daskrimti-jabar.web.id/library//repository/coin-master-hack-version-2021-free-download_GM406889139.pdf
    • http://daskrimti-jabar.web.id/library/repository/kachifpro_GM406889139.pdf
    • http://daskrimti-jabar.web.id/library/repository/roblox-free-stuff-for-avatar_GM431946152.pdf
    • http://daskrimti-jabar.web.id/library/repository/how-to-get-free-robux-no-verification-on-ipad_GM431946152.pdf
    • http://daskrimti-jabar.web.id/library//repository/free-spin-coin-master-link-today_GM406889139.pdf
    • http://daskrimti-jabar.web.id/library//repository/coin-master-hack-activegamer_GM406889139.pdf
    • http://daskrimti-jabar.web.id/library//repository/coin-master-hack-apk-2021_GM406889139.pdf
    • http://daskrimti-jabar.web.id/library/repository/coin-master-free-spins-link-june-2021_GM406889139.pdf
    • http://daskrimti-jabar.web.id/library/repository/robux-hacks-that-work-2021_GM431946152.pdf
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_002_off00003200.bin
e203d5b9ef6585ac77782e40d8364328627ab7bbe771b59f59dc35d9f3a5f7f6
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x3200 23112 bytes
font_01_sfnt_off00006618.bin
07d1048110b648044dfdf05b80b578e3dafb2e438d2dd29495699789e7328ffb
pdf-font-stream PDF embedded font (sfnt) at offset 0x6618 18272 bytes