Malicious PDF — malware analysis report

Static analysis result for SHA-256 ab86145b761cb964…

MALICIOUS

PDF

40.0 KB Created: 2021-05-11 20:32:10 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: f4aa08832d24deb97dfbbbca92c945b1 SHA-1: acfdac4e43cfb15481a909694c13669dffdd82f9 SHA-256: ab86145b761cb964fc8dfc7fae3e66f6621b3f685ecd7c62011575ec07d83064
102 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF document contains numerous embedded URLs and a 'Robux Hack Generator' lure, strongly suggesting a phishing or malware distribution attempt. The presence of a PDF link farm heuristic indicates a large number of external links, likely for SEO manipulation or to host malicious payloads. While no scripts were directly extracted, the PDF structure and embedded URIs are indicative of an attempt to redirect users to malicious sites.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9971

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://netcdn.xyz/app/431946152/robux-hack-generator-game-hack
    • https://www.tsdb.com.au/images/coin-master-2021_GM406889139.pdf
    • https://www.tsdb.com.au/images/how-to-get-free-robux_GM431946152.pdf
    • https://www.tsdb.com.au/images/how-to-hack-someones-roblox-account_GM431946152.pdf
    • https://www.tsdb.com.au/images/cm-spins_GM406889139.pdf
    • https://www.tsdb.com.au/images/best-way-to-hack-coin-master_GM406889139.pdf
    • https://www.tsdb.com.au/images/how-to-hack-coin-master-spin-in-hindi_GM406889139.pdf
    • https://www.tsdb.com.au/images/robux-gift-card-free_GM431946152.pdf
    • https://www.tsdb.com.au/images/free-robux-without-verification-or-survey_GM431946152.pdf
    • https://www.tsdb.com.au/images/robux-link_GM431946152.pdf
    • https://www.tsdb.com.au/images/free-spin-coin-master-iphone_GM406889139.pdf
    • https://www.tsdb.com.au/images/coin-master-free-spins-link-download_GM406889139.pdf
    • https://www.tsdb.com.au/images/how-to-get-minecraft-bedrock-edition-on-pc-for-free_GM479516143.pdf
    • https://www.tsdb.com.au/images/coin-master-cheat-codes-free_GM406889139.pdf
    • https://www.tsdb.com.au/images/roblox-money-hack_GM431946152.pdf
    • https://www.tsdb.com.au/images/free-robux-no-human-verify_GM431946152.pdf
    • https://www.tsdb.com.au/images/minecraft-pe-apk-free-download_GM479516143.pdf
    • https://www.tsdb.com.au/images/free-coin-master-spins-and-coins-for-daily_GM406889139.pdf
    • https://www.tsdb.com.au/images/coinmaster-gps-user-review-coinmaster-coin-master-hack-pagedemo-index_GM406889139.pdf
    • https://www.tsdb.com.au/images/install-free-game-coin-master_GM406889139.pdf
    • https://www.tsdb.com.au/images/free-minecraft-alt-generator_GM479516143.pdf
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00004471.bin
9255aa2fe46e16781ed49eeb8359ee26bb97f0deb90b02708e0c54298fb9515f
pdf-font-stream PDF embedded font (sfnt) at offset 0x4471 23860 bytes
font_01_sfnt_off00007996.bin
f5433ce3dc9930d213a8e7315569ee207b9df6dd56817c97a1fb358bc14a6a3b
pdf-font-stream PDF embedded font (sfnt) at offset 0x7996 18352 bytes