Malicious PDF — malware analysis report

Static analysis result for SHA-256 86af272c681851fd…

MALICIOUS

PDF

43.1 KB Created: 2021-05-16 08:46:53 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: b0648d305360202d4435109fc3cc428c SHA-1: 7c4baee5a41c0ede629eb58b7da362109d1d664c SHA-256: 86af272c681851fd5728d2097148247f363341431da3a6feb0a2b014c12becc6
102 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF document contains numerous embedded links and a document body that promises free Robux and game hacks, indicating a social engineering lure. The heuristic 'PDF_SEO_LINK_FARM' and the presence of many external URIs suggest this document is designed to redirect users to potentially malicious sites. While no scripts were explicitly extracted, the overall structure and content point towards a phishing or malware distribution attempt.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9971

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://netcdn.xyz/app/431946152/how-to-get-free-robux-codes-2021-game-hack
    • https://elearning.manposo.sch.id/__statics/gudangsoal/files/how-do-u-hack-roblox_GM431946152.pdf
    • https://elearning.manposo.sch.id/__statics/gudangsoal/files/coin-master-rewards_GM406889139.pdf
    • https://elearning.manposo.sch.id/__statics/gudangsoal/files/minecraft-bedrock-free-download-pc_GM479516143.pdf
    • https://elearning.manposo.sch.id/__statics/gudangsoal/files/how-to-make-a-minecraft-java-server-for-free_GM479516143.pdf
    • https://elearning.manposo.sch.id/__statics/gudangsoal/files/coin-master-hack-no-verify_GM406889139.pdf
    • https://elearning.manposo.sch.id/__statics/gudangsoal/files/spin-free-coin-master_GM406889139.pdf
    • https://elearning.manposo.sch.id/__statics/gudangsoal/files/how-to-hack-a-roblox-account-easy_GM431946152.pdf
    • https://elearning.manposo.sch.id/__statics/gudangsoal/files/robux-sign_GM431946152.pdf
    • https://elearning.manposo.sch.id/__statics/gudangsoal/files/wurst_GM479516143.pdf
    • https://elearning.manposo.sch.id/__statics/gudangsoal/files/free-robux-human-verification_GM431946152.pdf
    • https://elearning.manposo.sch.id/__statics/gudangsoal/files/op-rewards-free-robux_GM431946152.pdf
    • https://elearning.manposo.sch.id/__statics/gudangsoal/files/how-to-change-your-username-in-roblox-for-free_GM431946152.pdf
    • https://elearning.manposo.sch.id/__statics/gudangsoal/files/coin-master-cards-hack_GM406889139.pdf
    • https://elearning.manposo.sch.id/__statics/gudangsoal/files/free-spins-coin-master-links_GM406889139.pdf
    • https://elearning.manposo.sch.id/__statics/gudangsoal/files/coin-master-free-spins-link-2021-download_GM406889139.pdf
    • https://elearning.manposo.sch.id/__statics/gudangsoal/files/how-to-hack-roblox-jailbreak_GM431946152.pdf
    • https://elearning.manposo.sch.id/__statics/gudangsoal/files/how-to-get-free-robux-no-verification_GM431946152.pdf
    • https://elearning.manposo.sch.id/__statics/gudangsoal/files/free-robux-apps-that-work_GM431946152.pdf
    • https://elearning.manposo.sch.id/__statics/gudangsoal/files/robux-hack-no-human-verification_GM431946152.pdf
    • https://elearning.manposo.sch.id/__statics/gudangsoal/files/today-free-spin-link-for-coin-master_GM406889139.pdf
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_003_off000048d0.bin
460eae1db276e96837e9bff48febb9ab111ee9b041c958cb808cb24e452d6779
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x48D0 25560 bytes
font_01_sfnt_off00008432.bin
204886f9a3a3d456a8ba924f34e84de86e5dda13901e78a872ce278a746af401
pdf-font-stream PDF embedded font (sfnt) at offset 0x8432 18856 bytes