Malicious PDF — malware analysis report

Static analysis result for SHA-256 a36cdfc57ade4baa…

MALICIOUS

PDF

45.4 KB Created: 2021-06-10 14:23:32 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: c9b54c1f736a4b128891a8291e4fda66 SHA-1: 51f1821358adfc624574f403997bd92eea6a2459 SHA-256: a36cdfc57ade4baa6985cda42c2f373b44fc2dc9fc6a4b034d342cdcac24e405
102 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1203 Exploitation for Client Execution

This PDF file contains numerous embedded URLs, many of which are structured as SEO link farms, suggesting an attempt to distribute malicious content. The document body, though partially corrupted, contains references to 'Roblox Backpacking Hack Script' and a URL pointing to a 'roblox-backpacking-hack-script-game-hack', indicating a lure for potentially harmful downloads. The ML classifier also flagged this PDF as malicious with high confidence.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9864

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://netcdn.tw/app/431946152/roblox-backpacking-hack-script-game-hack
    • https://lib.unitri.ac.id/repository/free-robux-no-verification-required_GM431946152.pdf
    • https://lib.unitri.ac.id/repository/is-minecraft-bedrock-edition-free_GM479516143.pdf
    • https://lib.unitri.ac.id/repository/free-tiktok-followers-generator_GM835599320.pdf
    • https://lib.unitri.ac.id//repository/coin-master-heaven-free-spins_GM406889139.pdf
    • https://lib.unitri.ac.id/repository/why-isnt-robux-for-free_GM431946152.pdf
    • https://lib.unitri.ac.id/repository/free-ice-cream-shirt-roblox_GM431946152.pdf
    • https://lib.unitri.ac.id//repository/coin-master-hack-uk_GM406889139.pdf
    • https://lib.unitri.ac.id/repository/free-robux-generator-2021-no-human-verification-or-survey_GM431946152.pdf
    • https://lib.unitri.ac.id//repository/free-minecraft-capes-no-mods_GM479516143.pdf
    • https://lib.unitri.ac.id//repository/coin-master-free-spins-hack-2021_GM406889139.pdf
    • https://lib.unitri.ac.id//repository/como-hackear-el-juego-coin-master_GM406889139.pdf
    • https://lib.unitri.ac.id//repository/how-do-you-get-free-pet-food-in-coin-master_GM406889139.pdf
    • https://lib.unitri.ac.id/repository/minecraft-tower-defense-2-hacked_GM479516143.pdf
    • https://lib.unitri.ac.id/repository/roblox-free-exploits_GM431946152.pdf
    • https://lib.unitri.ac.id/repository/how-can-i-get-minecraft-for-free_GM479516143.pdf
    • https://lib.unitri.ac.id/repository/robux-hack-joining-groups_GM431946152.pdf
    • https://lib.unitri.ac.id//repository/pokemon-go-free-coins-apk_GM1094591345.pdf
    • https://lib.unitri.ac.id/repository/coin-master-spin-hack_GM406889139.pdf
    • https://lib.unitri.ac.id//repository/free-spins-coin-master_GM406889139.pdf
    • https://lib.unitri.ac.id/repository/coin-master-fan-page-giveaway_GM406889139.pdf
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_004_off00005349.bin
a1d5cbb9b18b2a4f965082d1bb78649874103e9aa6d43a9f83ef345d81e73418
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x5349 25528 bytes
font_01_sfnt_off00008d0a.bin
980b190bf26052fc8a4a2547045ad1dd043861e9762ae1d7f0ea4ccb58c02f05
pdf-font-stream PDF embedded font (sfnt) at offset 0x8D0A 18872 bytes