Malicious PDF — malware analysis report

Static analysis result for SHA-256 82d7fe6482a54fc6…

MALICIOUS

PDF

48.4 KB Created: 2021-05-14 09:01:19 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7) First seen: 2021-09-15
MD5: 2a80d696fb5ddcf331de6c3b1537c977 SHA-1: 6c1ea1bee95adb663847a6db13633ed9a9487629 SHA-256: 82d7fe6482a54fc66a5ccb045e3862a6fc3b19672e29d33f582583ffa69c1a7e
102 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF document contains numerous embedded links and a "DOC BODY" excerpt that explicitly mentions "Free Robux" and "free spins," indicating a lure for users to click on potentially malicious links. The PDF_SEO_LINK_FARM heuristic firing suggests a large number of external links were generated, likely to direct traffic to scam or phishing sites. While no scripts were extracted, the presence of external URLs and the nature of the lures strongly suggest a phishing or scam campaign.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9013

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://netcdn.xyz/app/431946152/free-robux-no-human-verification-and-no-survey-game-hack PDF link annotation
    • https://elearning.mtsn1banjarnegara.sch.id/__statics/gudangsoal/files/how-to-o-get-free-coin-master-spins_GM406889139.pdfIn PDF document text
    • http://elearning.mtsn1banjarnegara.sch.id/__statics/gudangsoal/files/coin-master-hack-spins-and-coins-unlimited-free_GM406889139.pdfIn PDF document text
    • http://elearning.mtsn1banjarnegara.sch.id/__statics/gudangsoal/files/free-coins-and-spins-in-coin-master_GM406889139.pdfIn PDF document text
    • http://elearning.mtsn1banjarnegara.sch.id/__statics/gudangsoal/files/coin-master-hack-reddit_GM406889139.pdfIn PDF document text
    • http://elearning.mtsn1banjarnegara.sch.id/__statics/gudangsoal/files/is-minecraft-education-edition-free_GM479516143.pdfIn PDF document text
    • https://elearning.mtsn1banjarnegara.sch.id/__statics/gudangsoal/files/free-premium-roblox_GM431946152.pdfIn PDF document text
    • http://elearning.mtsn1banjarnegara.sch.id/__statics/gudangsoal/files/coin-master-free-spins-link-2021-haktuts_GM406889139.pdfIn PDF document text
    • http://elearning.mtsn1banjarnegara.sch.id/__statics/gudangsoal/files/coin-master-free-spins-link-blogspot-2021_GM406889139.pdfIn PDF document text
    • https://elearning.mtsn1banjarnegara.sch.id/__statics/gudangsoal/files/rbxoffers-earn-free-robux_GM431946152.pdfIn PDF document text
    • http://elearning.mtsn1banjarnegara.sch.id/__statics/gudangsoal/files/how-to-hack-into-someones-roblox-account_GM431946152.pdfIn PDF document text
    • https://elearning.mtsn1banjarnegara.sch.id/__statics/gudangsoal/files/free-robux-generator-2021-no-human-verification-or-survey_GM431946152.pdfIn PDF document text
    • http://elearning.mtsn1banjarnegara.sch.id/__statics/gudangsoal/files/minecraft-hack-client-18-9_GM479516143.pdfIn PDF document text
    • https://elearning.mtsn1banjarnegara.sch.id/__statics/gudangsoal/files/free-coins-coin-master-link_GM406889139.pdfIn PDF document text
    • http://elearning.mtsn1banjarnegara.sch.id/__statics/gudangsoal/files/free-robux-generator-2021_GM431946152.pdfIn PDF document text
    • http://elearning.mtsn1banjarnegara.sch.id/__statics/gudangsoal/files/lastrick-com-coin-master-hack_GM406889139.pdfIn PDF document text
    • http://elearning.mtsn1banjarnegara.sch.id/__statics/gudangsoal/files/collect-free-spins-coin-master_GM406889139.pdfIn PDF document text
    • http://elearning.mtsn1banjarnegara.sch.id/__statics/gudangsoal/files/free-robux-easy_GM431946152.pdfIn PDF document text
    • http://elearning.mtsn1banjarnegara.sch.id/__statics/gudangsoal/files/coin-master-free-spins-hack-2021_GM406889139.pdfIn PDF document text
    • https://elearning.mtsn1banjarnegara.sch.id/__statics/gudangsoal/files/how-to-hack-roblox-2021_GM431946152.pdfIn PDF document text
    • http://elearning.mtsn1banjarnegara.sch.id/__statics/gudangsoal/files/coin-master-hack-ios-apk_GM406889139.pdfIn PDF document text
    • http://en.wikipedia.org/wiki/MIT_LicenseIn PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_003_off0000508d.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x508D 26364 bytes
SHA-256: ca0e288304ac99b7c1fd46eb03b043c7552c772d2c476d8f70df5555306b1e64
font_01_sfnt_off00008e04.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x8E04 2888 bytes
SHA-256: dcdd98ee8e25436a83587ccb4027347dd2c3fcec95f3413942edd4086125bcca
font_02_sfnt_off000097d7.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x97D7 19328 bytes
SHA-256: d2b84e9593d62b74a5e72ac2cd252f85880eba3e829d4f4451320fa49886136c