Malicious PDF — malware analysis report

Static analysis result for SHA-256 b7e6ebfa3b0269e6…

MALICIOUS

PDF

45.5 KB Created: 2021-06-09 11:05:41 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: ce3468ac0e84e898dbbc30cd4e26b251 SHA-1: fc1b1ffac906fcb09f8663dbe49d44bb2a766750 SHA-256: b7e6ebfa3b0269e6c482dd7f8a89db8dfc3dd987e9986c4e751d6dd6d0f9d16e
102 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF document contains numerous embedded links and a primary URL advertising free Robux and game hacks, indicating a social engineering lure. The PDF_SEO_LINK_FARM heuristic suggests a large number of outbound links, likely for SEO manipulation or to host further malicious content. While no scripts were directly extracted, the presence of embedded URIs and the ML classifier's high confidence score point towards malicious intent, likely to drive users to download or click on further malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9797

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://netcdn.tw/app/431946152/secret-free-robux-game-hack
    • http://internetdeputy.com/images/tiktok-free-videos_GM835599320.pdf
    • http://internetdeputy.com/images/how-to-get-free-robux-games_GM431946152.pdf
    • http://internetdeputy.com/images/how-can-i-get-free-robux_GM431946152.pdf
    • http://internetdeputy.com/images/roblox-free-robux-hack_GM431946152.pdf
    • http://internetdeputy.com/images/free-spins-for-coin-master-2021_GM406889139.pdf
    • http://internetdeputy.com/images/how-to-hack-peoples-roblox-accounts-2021_GM431946152.pdf
    • http://internetdeputy.com/images/admin-commands-script-roblox-hack_GM431946152.pdf
    • http://internetdeputy.com/images/coin-master-free-daily-spins-2021_GM406889139.pdf
    • http://internetdeputy.com/images/roblox-hack-ios_GM431946152.pdf
    • http://internetdeputy.com/images/coin-master-free-spins-hack-apk-download_GM406889139.pdf
    • http://internetdeputy.com/images/roblox-free-hair-codes_GM431946152.pdf
    • http://internetdeputy.com/images/how-to-play-coin-master_GM406889139.pdf
    • http://internetdeputy.com/images/microsoft-bing-robux_GM431946152.pdf
    • http://internetdeputy.com/images/coin-master-free-spins-link_GM406889139.pdf
    • http://internetdeputy.com/images/coin-master-hack-online-no-human-verification_GM406889139.pdf
    • http://internetdeputy.com/images/coin-master-hack-to-get-free-spins_GM406889139.pdf
    • http://internetdeputy.com/images/legit-coin-master-hack-without-verification_GM406889139.pdf
    • http://internetdeputy.com/images/free-spins-for-coin-master-on-1-19-19_GM406889139.pdf
    • http://internetdeputy.com/images/bloxawards-com-earn-free-robux_GM431946152.pdf
    • http://internetdeputy.com/images/coin-master-free-spins-link-whatsapp-group_GM406889139.pdf
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_004_off00004df3.bin
b9bf2ba4cb0c1fcc5b3a0f8205cbd8de785439512ca46be25e03195c434d943a
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x4DF3 24484 bytes
font_01_sfnt_off000085cc.bin
fd98c8f6e7c2e74bbd5822409159a93ac5c94da083ae4c2eb269d4284375f9e8
pdf-font-stream PDF embedded font (sfnt) at offset 0x85CC 2836 bytes
font_02_sfnt_off00008f71.bin
c95e2218740038a527dcee8a7a0acae0192802f3236c9c5d3ca2d28bc3df4fbe
pdf-font-stream PDF embedded font (sfnt) at offset 0x8F71 18120 bytes