Malicious PDF — malware analysis report

Static analysis result for SHA-256 906b669127bfe942…

MALICIOUS

PDF

44.8 KB Created: 2021-06-11 10:22:46 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: 5b2e8b23d8e48d495004c2f009556950 SHA-1: ea3ea12f91b9b6627ba2e3ed7cc0947a24f26286 SHA-256: 906b669127bfe9425358f4a8918b1bda315d6dafa5bbd3d50e2ddc3fbf43b060
102 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

This PDF document exhibits characteristics of a malicious lure, specifically a link farm designed to redirect users to potentially harmful websites. The presence of numerous external links, many with 'robux' or 'coin master' in their titles, suggests an attempt to trick users into visiting scam or malware-distributing sites. The ML classifier also strongly flagged this PDF as malicious, reinforcing the suspicious nature of its content and structure.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9865

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://netcdn.tw/app/431946152/resourcly-cf-free-robux-game-hack
    • http://digilibfisip.unla.ac.id/repository/face-added-by-hacker-roblox_GM431946152.pdf
    • http://digilibfisip.unla.ac.id/repository/coin-master-free-cards-link_GM406889139.pdf
    • http://digilibfisip.unla.ac.id/repository/google-coin-master-free-spins_GM406889139.pdf
    • http://digilibfisip.unla.ac.id/repository/free-robux-websites-that-actually-work_GM431946152.pdf
    • http://digilibfisip.unla.ac.id/repository/2021-coin-master-hack-without-verification_GM406889139.pdf
    • http://digilibfisip.unla.ac.id/repository/how-to-get-free-stuff-on-roblox_GM431946152.pdf
    • http://digilibfisip.unla.ac.id/repository/rbx-roblox_GM431946152.pdf
    • http://digilibfisip.unla.ac.id/repository/working-coin-master-hack_GM406889139.pdf
    • http://digilibfisip.unla.ac.id/repository/free-roblox-followers_GM431946152.pdf
    • http://digilibfisip.unla.ac.id/repository/free-spin-coin-master-hacktoman_GM406889139.pdf
    • http://digilibfisip.unla.ac.id/repository/coin-master-real-free-spins_GM406889139.pdf
    • http://digilibfisip.unla.ac.id/repository/how-to-get-free-food-for-foxy-in-coin-master_GM406889139.pdf
    • http://digilibfisip.unla.ac.id/repository/get-free-spins-on-coin-master_GM406889139.pdf
    • http://digilibfisip.unla.ac.id/repository/free-spins-coin-master-2021_GM406889139.pdf
    • http://digilibfisip.unla.ac.id/repository/hacks-to-get-free-robux_GM431946152.pdf
    • http://digilibfisip.unla.ac.id/repository/coin-master-free-spin-and-coin-links_GM406889139.pdf
    • http://digilibfisip.unla.ac.id/repository/free-robux-on-iphone_GM431946152.pdf
    • http://digilibfisip.unla.ac.id/repository/20210-free-spin-links-for-coin-master_GM406889139.pdf
    • http://digilibfisip.unla.ac.id/repository/overhaul-roblox-free-shop_GM431946152.pdf
    • http://digilibfisip.unla.ac.id/repository/free-robux-hack-no-download-apps_GM431946152.pdf
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_004_off000051ea.bin
71c8063839de2d5d2bb17ca945152d98540fa52ff9a68255a8426ee871d35802
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x51EA 25440 bytes
font_01_sfnt_off00008c95.bin
4563367820d4a045425c4c822873aff51b34bae849797131606a74a41c7c5199
pdf-font-stream PDF embedded font (sfnt) at offset 0x8C95 18268 bytes