Malicious PDF — malware analysis report

Static analysis result for SHA-256 a234f267265cf31a…

MALICIOUS

PDF

35.8 KB Created: 2021-06-27 20:10:55 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: af498cbe85e1424e0bc7f41a848ad85e SHA-1: 978b31cffc8c95993c586820aa31ab284968c374 SHA-256: a234f267265cf31aa004dd20b4837e508fd9408f5676f5d24575d68c9bddde98
102 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF document contains a large number of external links, many of which are SEO-optimized and point to sites offering game-related cheats or free items. The heuristic 'PDF_SEO_LINK_FARM' indicates a mass of external links, and the ML classifier strongly flags this PDF as malicious. The document body itself contains URLs that likely serve as lures to download malicious content or redirect to phishing sites.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9980

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://netcdn.co/app/431946152/free-things-february-2021-roblox-game-hack
    • http://pustaka.manajemen.fekon.unand.ac.id/repository/how-to-get-free-robux-without-doing-anything_GM431946152.pdf
    • http://pustaka.manajemen.fekon.unand.ac.id/repository/free-unused-roblox-card-codes-2021_GM431946152.pdf
    • http://pustaka.manajemen.fekon.unand.ac.id/repository/how-to-download-minecraft-windows-10-edition-for-free_GM479516143.pdf
    • http://pustaka.manajemen.fekon.unand.ac.id/repository/roblox-kinetic-code-prealpha-free-download_GM431946152.pdf
    • http://pustaka.manajemen.fekon.unand.ac.id/repository/how-to-cheat-in-rotom-on-prokect-pokemon-roblox_GM431946152.pdf
    • http://pustaka.manajemen.fekon.unand.ac.id/repository/how-to-bypass-the-roblox-cheat-engine-bypass_GM431946152.pdf
    • http://pustaka.manajemen.fekon.unand.ac.id/repository/free-btools-for-roblox_GM431946152.pdf
    • http://pustaka.manajemen.fekon.unand.ac.id/repository/how-to-setup-a-minecraft-server-for-free_GM479516143.pdf
    • http://pustaka.manajemen.fekon.unand.ac.id/repository/roblox-editable-invitation-template-free_GM431946152.pdf
    • http://pustaka.manajemen.fekon.unand.ac.id/repository/free-online-games-like-minecraft_GM479516143.pdf
    • http://pustaka.manajemen.fekon.unand.ac.id/repository/how-to-get-free-robux-without-verifying-2021_GM431946152.pdf
    • http://pustaka.manajemen.fekon.unand.ac.id/repository/coin-master-15-free-spin-link-of-last-5-days_GM406889139.pdf
    • http://pustaka.manajemen.fekon.unand.ac.id/repository/how-to-get-free-robux-on-roblox_GM431946152.pdf
    • http://pustaka.manajemen.fekon.unand.ac.id/repository/easy-free-robux-no-human-verification_GM431946152.pdf
    • http://pustaka.manajemen.fekon.unand.ac.id/repository/game-guardian-hack-roblox_GM431946152.pdf
    • http://pustaka.manajemen.fekon.unand.ac.id/repository/robux-hack-2021-pc_GM431946152.pdf
    • http://pustaka.manajemen.fekon.unand.ac.id/repository/how-to-get-free-robux-no-human-verification-2021_GM431946152.pdf
    • http://pustaka.manajemen.fekon.unand.ac.id/repository/free-robux-giveaway-no-human-verification_GM431946152.pdf
    • http://pustaka.manajemen.fekon.unand.ac.id/repository/greasy-fork-roblox-hack_GM431946152.pdf
    • http://pustaka.manajemen.fekon.unand.ac.id/repository/can-i-get-free-money-on-roblox-adopt-me-2021_GM431946152.pdf
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000033b1.bin
f6e2c2dc6cad3bedcfb6cf64c313cb41777558fd9bc726fd97da57341e2e4e71
pdf-font-stream PDF embedded font (sfnt) at offset 0x33B1 22372 bytes
font_01_sfnt_off0000653a.bin
516de84b60e667ff92d40af0eb75e8fedd019f0a32acc1a3beb16965974ec803
pdf-font-stream PDF embedded font (sfnt) at offset 0x653A 19656 bytes