Malicious PDF — malware analysis report

Static analysis result for SHA-256 a62f13d37c2a062c…

MALICIOUS

PDF

35.4 KB Created: 2021-06-27 14:11:43 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: 54048772e09c18ad8e878454ac1fab3c SHA-1: 9db95363e24c9b81a1296af5967d2c68e536c166 SHA-256: a62f13d37c2a062c0775c1408e1925985f153c0df17ed572bcc05885056b8f13
102 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1203 Exploitation for Client Execution

This PDF document contains numerous embedded URLs, many of which are structured as SEO-optimized links pointing to purported game hacks. The ML classifier strongly indicates maliciousness, and the presence of a download button lure reinforces the deceptive nature of the document. The primary goal appears to be directing users to external sites that likely host malware or facilitate further compromise.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9980

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://netcdn.co/app/431946152/hack-roblox-money-2021-game-hack
    • http://lib.fekon.untad.ac.id/repository/roblox-comment-mettre-un-script-cheat_GM431946152.pdf
    • http://lib.fekon.untad.ac.id/repository/greenlegocats123-free-robux_GM431946152.pdf
    • http://lib.fekon.untad.ac.id/repository/how-do-you-get-free-stuff-in-roblox-2021_GM431946152.pdf
    • http://lib.fekon.untad.ac.id/repository/roblox-group-free-robux_GM431946152.pdf
    • http://lib.fekon.untad.ac.id/repository/how-do-you-get-free-roblox-money_GM431946152.pdf
    • http://lib.fekon.untad.ac.id/repository/coin-master-unlimited-spin-hack-apk_GM406889139.pdf
    • http://lib.fekon.untad.ac.id/repository/free-ways-to-get-robux-2021_GM431946152.pdf
    • http://lib.fekon.untad.ac.id/repository/how-to-get-free-clothes-on-roblox-2021_GM431946152.pdf
    • http://lib.fekon.untad.ac.id/repository/free-minecraft-gift-card_GM479516143.pdf
    • http://lib.fekon.untad.ac.id/repository/best-minecraft-hacks_GM479516143.pdf
    • http://lib.fekon.untad.ac.id/repository/how-to-hack-in-games-roblox_GM431946152.pdf
    • http://lib.fekon.untad.ac.id/repository/how-to-get-free-r-in-roblox_GM431946152.pdf
    • http://lib.fekon.untad.ac.id/repository/hack-version-of-coin-master_GM406889139.pdf
    • http://lib.fekon.untad.ac.id/repository/hack-roblox-tener-robux-gratis-2021-diciembre_GM431946152.pdf
    • http://lib.fekon.untad.ac.id/repository/roblox-star-wars-first-order-cheat-engine_GM431946152.pdf
    • http://lib.fekon.untad.ac.id/repository/roblox-flood-escape-to-how-to-get-fly-hacks_GM431946152.pdf
    • http://lib.fekon.untad.ac.id/repository/roblox-royale-high-outfit-hacks_GM431946152.pdf
    • http://lib.fekon.untad.ac.id/repository/how-to-get-free-robux-by-playing-games_GM431946152.pdf
    • http://lib.fekon.untad.ac.id/repository/hack-for-robux-script_GM431946152.pdf
    • http://lib.fekon.untad.ac.id/repository/coin-master-hacks-free-spins_GM406889139.pdf
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000318b.bin
87f32a01a2fbd34bd389def93b80afc2d7b0e119f031dd1d69db85de7b2e35a6
pdf-font-stream PDF embedded font (sfnt) at offset 0x318B 22976 bytes
font_01_sfnt_off000063eb.bin
dc9e44ba82a6316c86e1634460083108206c68842e6339b8a5a86b64cadc6b68
pdf-font-stream PDF embedded font (sfnt) at offset 0x63EB 19432 bytes