Malicious PDF — malware analysis report

Static analysis result for SHA-256 95adcd1bcb7a6137…

MALICIOUS

PDF

46.7 KB Created: 2021-06-11 03:05:11 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: bd1fffd9278f7be65b8c435e8d451da6 SHA-1: 6bafaf00ff369074c8ee2eeb8335df7227e2ef09 SHA-256: 95adcd1bcb7a613704241969f612f83961ed236822f53667cc29288e6415fe6b
102 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains numerous links to external websites, many of which are SEO-optimized to appear as legitimate download pages for game-related cheats or virtual currency. The document body and extracted URLs strongly suggest a lure for users seeking free Robux, likely leading to a malware download. The presence of a 'download button' heuristic further supports this malicious intent.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9832

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://netcdn.tw/app/431946152/free-robux-master-game-hack
    • http://sistem.amikomsolo.ac.id/perpus/repository/how-to-get-free-robux-without-download-apps-or-survey_GM431946152.pdf
    • http://sistem.amikomsolo.ac.id/perpus/repository/synapse-x-roblox-free-download-2021_GM431946152.pdf
    • http://sistem.amikomsolo.ac.id/perpus/repository/roebucks-on-roblox_GM431946152.pdf
    • http://sistem.amikomsolo.ac.id/perpus/repository/spins-gratis-coin-master-hoy_GM406889139.pdf
    • http://sistem.amikomsolo.ac.id/perpus/repository/free-robux-com-real_GM431946152.pdf
    • http://sistem.amikomsolo.ac.id/perpus/repository/robux-generator-no-verification-needed_GM431946152.pdf
    • http://sistem.amikomsolo.ac.id/perpus/repository/roblox-hacked-version_GM431946152.pdf
    • http://sistem.amikomsolo.ac.id/perpus/repository/free-minecraft-printables-food-labels_GM479516143.pdf
    • http://sistem.amikomsolo.ac.id/perpus/repository/minecraft-java-free_GM479516143.pdf
    • http://sistem.amikomsolo.ac.id/perpus/repository/free-roblox-gift-cards-discord_GM431946152.pdf
    • http://sistem.amikomsolo.ac.id/perpus/repository/coin-master-hacks-for-pet-food_GM406889139.pdf
    • http://sistem.amikomsolo.ac.id/perpus/repository/easy-ways-to-get-free-robux_GM431946152.pdf
    • http://sistem.amikomsolo.ac.id/perpus/repository/how-to-get-free-robux-fast-and-easy_GM431946152.pdf
    • http://sistem.amikomsolo.ac.id/perpus/repository/how-to-get-free-robux-without-paying_GM431946152.pdf
    • http://sistem.amikomsolo.ac.id/perpus/repository/how-to-get-free-robux-inspect-element-no-wait_GM431946152.pdf
    • http://sistem.amikomsolo.ac.id/perpus/repository/roblox-jailbreak-hack-download_GM431946152.pdf
    • http://sistem.amikomsolo.ac.id/perpus/repository/www-bloxyworld-com-free-robux_GM431946152.pdf
    • http://sistem.amikomsolo.ac.id/perpus/repository/no-censor-hack-roblox_GM431946152.pdf
    • http://sistem.amikomsolo.ac.id/perpus/repository/earn-robux-by-watching-ads_GM431946152.pdf
    • http://sistem.amikomsolo.ac.id/perpus/repository/how-to-get-free-minecraft-alts_GM479516143.pdf
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_004_off00005575.bin
9634093e2a66a782e8eb0df3dd627fe01da729831d87ced36dd32ad330d5ea19
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x5575 27112 bytes
font_01_sfnt_off0000933b.bin
5f92163030842751a82ce86b738a68b4d97fee0a57e838fb4c20f827a47ffbab
pdf-font-stream PDF embedded font (sfnt) at offset 0x933B 18544 bytes