Malicious PDF — malware analysis report

Static analysis result for SHA-256 ba8a5d591a4516cf…

MALICIOUS

PDF

34.3 KB Created: 2021-06-26 11:33:57 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: ab8bf0c6a8600e5a14f53e98e4244efb SHA-1: 3afdab516a55941080e580e33f55ffabb92a4223 SHA-256: ba8a5d591a4516cf34a3835dc3c3ee8574f46ebad2d9d422b5355a06169784c4
102 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF document contains numerous links to external websites, many of which are SEO-optimized and appear to be part of a link farm designed to attract users searching for game cheats and free in-game currency. The ML classifier strongly indicates maliciousness, and the presence of embedded URLs suggests an attempt to redirect users to malicious content or download further payloads. The document body itself contains references to game hacks and URLs, reinforcing the lure.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9980

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://netcdn.co/app/431946152/sentinel-hack-roblox-game-hack
    • https://privatearrangements.co.nz/public/files/coin-master-free-spins-link-blogspot-2021_GM406889139.pdf
    • https://privatearrangements.co.nz/public/files/best-free-minecraft-hacked-client_GM479516143.pdf
    • https://privatearrangements.co.nz/public/files/balloon-roblox-free_GM431946152.pdf
    • https://privatearrangements.co.nz/public/files/minecraft-build-hacks_GM479516143.pdf
    • https://privatearrangements.co.nz/public/files/jailbreak-roblox-safes-hack_GM431946152.pdf
    • https://privatearrangements.co.nz/public/files/free-roblox-promo-codes-for-robux_GM431946152.pdf
    • https://privatearrangements.co.nz/public/files/how-to-hack-roblox-accounts-2021-easy_GM431946152.pdf
    • https://privatearrangements.co.nz/public/files/free-robux-that-does-not-scame-you_GM431946152.pdf
    • https://privatearrangements.co.nz/public/files/free-robux-app-code_GM431946152.pdf
    • https://privatearrangements.co.nz/public/files/free-anime-t-shirt-roblox_GM431946152.pdf
    • https://privatearrangements.co.nz/public/files/how-do-you-get-roblox-money_GM431946152.pdf
    • https://privatearrangements.co.nz/public/files/free-spins-and-coins-coin-master-link-2021_GM406889139.pdf
    • https://privatearrangements.co.nz/public/files/minecraft-windows-10-free-with-java_GM479516143.pdf
    • https://privatearrangements.co.nz/public/files/master-hack-coin_GM406889139.pdf
    • https://privatearrangements.co.nz/public/files/how-to-hack-any-magic-in-fairy-tale-revalations-roblox_GM431946152.pdf
    • https://privatearrangements.co.nz/public/files/how-can-u-get-free-robux_GM431946152.pdf
    • https://privatearrangements.co.nz/public/files/coin-master-free-spins-and-coins-daily_GM406889139.pdf
    • https://privatearrangements.co.nz/public/files/how-to-hack-people-on-roblox_GM431946152.pdf
    • https://privatearrangements.co.nz/public/files/how-to-get-free-dominus-in-roblox_GM431946152.pdf
    • https://privatearrangements.co.nz/public/files/descargar-hack-de-jailbreak-roblox_GM431946152.pdf
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00002fad.bin
90adce57e350e34183b359d801a9adacf4f645797d8e00bdbf3f1e4802cc633e
pdf-font-stream PDF embedded font (sfnt) at offset 0x2FAD 22304 bytes
font_01_sfnt_off0000613d.bin
3f1b0d0e937a0f187ccecfd33e95a49472a1f236def32c5ee7eba81c3814dbf5
pdf-font-stream PDF embedded font (sfnt) at offset 0x613D 18880 bytes