Malicious PDF — malware analysis report

Static analysis result for SHA-256 8e71990d006977dd…

MALICIOUS

PDF

41.5 KB Created: 2021-05-14 11:01:01 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: 6a1bdb31a0393af8310b21a0bbe15553 SHA-1: 8bfb4b43167885565fd8deeffd0596fd332284ec SHA-256: 8e71990d006977ddc3ad011f26415d3a459e62120f03853e4728ce9ac7f9253f
102 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains numerous embedded links, many of which are SEO-optimized and point to other PDF files, suggesting a link farm or content-scraping operation. The presence of a 'download button' heuristic and an external URI related to a 'game hack' further indicates a malicious intent to trick users into downloading potentially harmful content. The ML classifier also strongly flagged this PDF as malicious.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9971

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://netcdn.xyz/app/479516143/minecraft-iphone-free-game-hack
    • http://www.teapotjewelry.com/images/free-robux-no-human-verification-and-no-survey_GM431946152.pdf
    • http://www.teapotjewelry.com/images/how-to-get-free-robux-without-offers_GM431946152.pdf
    • http://www.teapotjewelry.com/images/play-full-version-of-minecraft-for-free-no-download_GM479516143.pdf
    • http://www.teapotjewelry.com/images/coin-master-free-spins-hack_GM406889139.pdf
    • http://www.teapotjewelry.com/images/coin-master-daily-free-spins-blogspot_GM406889139.pdf
    • http://www.teapotjewelry.com/images/coin-master-free-spins_GM406889139.pdf
    • http://www.teapotjewelry.com/images/free-coin-master-coins_GM406889139.pdf
    • http://www.teapotjewelry.com/images/coin-master-hacks-free-spins_GM406889139.pdf
    • http://www.teapotjewelry.com/images/free-robux-for-kids_GM431946152.pdf
    • http://www.teapotjewelry.com/images/coin-master-hack-game-download_GM406889139.pdf
    • http://www.teapotjewelry.com/images/coin-master-hack-online-android_GM406889139.pdf
    • http://www.teapotjewelry.com/images/free-attacks-on-coin-master_GM406889139.pdf
    • http://www.teapotjewelry.com/images/minecraft-hacks-list_GM479516143.pdf
    • http://www.teapotjewelry.com/images/coin-master-free-spins-link-2021-today_GM406889139.pdf
    • http://www.teapotjewelry.com/images/roblox-com-redeem_GM431946152.pdf
    • http://www.teapotjewelry.com/images/is-there-a-way-to-get-free-robux_GM431946152.pdf
    • http://www.teapotjewelry.com/images/is-it-possible-to-get-free-robux_GM431946152.pdf
    • http://www.teapotjewelry.com/images/how-do-you-hack-minecraft_GM479516143.pdf
    • http://www.teapotjewelry.com/images/free-spin-coin-master-game_GM406889139.pdf
    • http://www.teapotjewelry.com/images/how-do-i-get-free-robux_GM431946152.pdf
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_003_off0000498b.bin
abec6f23d416cf7e072b486b0e3eb45996df7478210b83d79239a3d84b6eba16
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x498B 24300 bytes
font_01_sfnt_off000080d8.bin
d64526d0e07d457868d5eac688c0bc3e5c9817b8b07646f1be3e20c76e1ff486
pdf-font-stream PDF embedded font (sfnt) at offset 0x80D8 18052 bytes