Malicious PDF — malware analysis report

Static analysis result for SHA-256 9dd9b57cb2a80e09…

MALICIOUS

PDF

34.4 KB Created: 2021-07-01 07:23:41 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: bbba739d6bb7435b641818ce50b970e3 SHA-1: 4d793b37055ce3d36350091dfe6829e369cb41d9 SHA-256: 9dd9b57cb2a80e09b6cfd79c47eff5cb63428e280d31b97c229a6f5ed417e06c
102 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

This PDF document contains numerous links disguised as download opportunities for games and hacks, aiming to trick users into clicking them. The ML classifier strongly indicated maliciousness, and the presence of a large number of external links, many with SEO-like slugs, suggests a link farm or phishing attempt. The document's content and structure are consistent with a lure to download potentially unwanted or malicious software.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9980

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://netcdn.co/app/479516143/minecraft-dungeons-free-download-game-hack
    • http://digilib.pustaka.unand.ac.id/repository/free-roblox-customization_GM431946152.pdf
    • http://digilib.pustaka.unand.ac.id/repository/hex-code-hacks-not-working-roblox_GM431946152.pdf
    • http://digilib.pustaka.unand.ac.id/repository/hire-someone-to-hack-a-roblox-account_GM431946152.pdf
    • http://digilib.pustaka.unand.ac.id/repository/how-to-hack-someones-roblox-account_GM431946152.pdf
    • http://digilib.pustaka.unand.ac.id/repository/free-roblox-linkmon-website_GM431946152.pdf
    • http://digilib.pustaka.unand.ac.id/repository/i-want-to-play-roblox-play-free-online_GM431946152.pdf
    • http://digilib.pustaka.unand.ac.id/repository/free-robux-codes-never-used_GM431946152.pdf
    • http://digilib.pustaka.unand.ac.id/repository/roblox-hack-march-18_GM431946152.pdf
    • http://digilib.pustaka.unand.ac.id/repository/how-to-do-speed-hack-on-roblox-mad-paintball_GM431946152.pdf
    • http://digilib.pustaka.unand.ac.id/repository/how-to-put-cheat-codes-roblox-bubble-gum_GM431946152.pdf
    • http://digilib.pustaka.unand.ac.id/repository/cheat-codes-for-roblox-murder-mystery-2_GM431946152.pdf
    • http://digilib.pustaka.unand.ac.id/repository/hacks-for-work-at-a-pizza-place-roblox_GM431946152.pdf
    • http://digilib.pustaka.unand.ac.id/repository/free-robux-giveaway-live_GM431946152.pdf
    • http://digilib.pustaka.unand.ac.id/repository/money-cheats-for-rocitizens-in-roblox_GM431946152.pdf
    • http://digilib.pustaka.unand.ac.id/repository/how-yammy-hacks-people-on-roblox_GM431946152.pdf
    • http://digilib.pustaka.unand.ac.id/repository/hack-vampire-hunters-2-roblox_GM431946152.pdf
    • http://digilib.pustaka.unand.ac.id/repository/roblox-wikia-free-robux_GM431946152.pdf
    • http://digilib.pustaka.unand.ac.id/repository/free-robux-promo-code-site-youtubecom_GM431946152.pdf
    • http://digilib.pustaka.unand.ac.id/repository/free-roblox-accounts-with-robux-that-work-2021_GM431946152.pdf
    • http://digilib.pustaka.unand.ac.id/repository/link-for-free-spins-on-coin-master_GM406889139.pdf
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000315e.bin
da3848e097e3ddc8fc02f6d77993d6aa299fac4e097e6a109b6d4b10564af2ab
pdf-font-stream PDF embedded font (sfnt) at offset 0x315E 22116 bytes
font_01_sfnt_off0000625d.bin
9131f8ae0af3742f2152d673706180936bbe7c3ea282a1fb4d0c655f83237649
pdf-font-stream PDF embedded font (sfnt) at offset 0x625D 18720 bytes