Malicious PDF — malware analysis report

Static analysis result for SHA-256 a029b32470362f9b…

MALICIOUS

PDF

34.5 KB Created: 2021-06-29 22:04:14 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: 89e9b93bad4359476056c396bb13653d SHA-1: 6ff4c6bacbeac01173b81f6a781c59e61bf7f80d SHA-256: a029b32470362f9b1f43b6ed0c97b8b8a26e1885cb17a59f5075e2b0b29b3dc5
102 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

This PDF document exhibits characteristics of a malicious lure, employing a link farm strategy to direct users to external sites offering game cheats and hacks. The presence of numerous URLs, including one pointing to 'netcdn.co', suggests an attempt to distribute potentially unwanted or malicious software. The ML classifier's high confidence score further supports the malicious nature of this file.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9980

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://netcdn.co/app/431946152/free-andrbirds-head-roblox-game-hack
    • https://library.uigm.ac.id/repository/how-do-you-get-free-roblox_GM431946152.pdf
    • https://library.uigm.ac.id/repository/get-your-free-tvs-roblox_GM431946152.pdf
    • https://library.uigm.ac.id/repository/heist-2-roblox-hack_GM431946152.pdf
    • https://library.uigm.ac.id/repository/thebuxian-you-have-robux-try-hack-today_GM431946152.pdf
    • https://library.uigm.ac.id/repository/how-to-get-free-legit-robux_GM431946152.pdf
    • https://library.uigm.ac.id/repository/free-candy-20-roblox_GM431946152.pdf
    • https://library.uigm.ac.id/repository/roblox-free-clothes-girl_GM431946152.pdf
    • https://library.uigm.ac.id/repository/how-to-get-hacks-on-minecraft_GM479516143.pdf
    • https://library.uigm.ac.id/repository/free-robux-generator-no-human-verification-or-surveys_GM431946152.pdf
    • https://library.uigm.ac.id/repository/cheat-codes-for-roblox-adopt-me_GM431946152.pdf
    • https://library.uigm.ac.id/repository/getrobux-come_GM431946152.pdf
    • https://library.uigm.ac.id/repository/free-roblox-accounts-2021-with-robux_GM431946152.pdf
    • https://library.uigm.ac.id/repository/easy-ways-to-get-free-robux_GM431946152.pdf
    • https://library.uigm.ac.id/repository/how-to-block-someone-on-coin-master_GM406889139.pdf
    • https://library.uigm.ac.id/repository/coin-master-hack-apk_GM406889139.pdf
    • https://library.uigm.ac.id/repository/roblox-free-candy-script-pastebin_GM431946152.pdf
    • https://library.uigm.ac.id/repository/tutorial-avanzado-de-cheat-engine-para-dragon-ball-range-roblox_GM431946152.pdf
    • https://library.uigm.ac.id/repository/coin-master-ad_GM406889139.pdf
    • https://library.uigm.ac.id/repository/links-to-get-free-spins-on-coin-master_GM406889139.pdf
    • https://library.uigm.ac.id/repository/hacks-in-roblox-prison-life_GM431946152.pdf
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00002fe4.bin
11af9f240579831703613be5429a68706390f0437d8f4bb6cb272e9375cfa421
pdf-font-stream PDF embedded font (sfnt) at offset 0x2FE4 22420 bytes
font_01_sfnt_off000061f5.bin
53a37ed702d1644caad71e030ffdc5e92daae9060fa0927eb973026e987afb99
pdf-font-stream PDF embedded font (sfnt) at offset 0x61F5 18944 bytes