Malicious PDF — malware analysis report

Static analysis result for SHA-256 be1657485175096a…

MALICIOUS

PDF

34.8 KB Created: 2021-07-05 09:49:04 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: 3b9362c3af198c1d27f0a15e16e7c1cb SHA-1: 3a5cfe0d7a275a29e740de698630ae1aae8768d6 SHA-256: be1657485175096a0e4c5b3210c78608c77073d9ed9336951fddfc7a08f82633
122 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF document contains numerous links to external websites and other PDFs, many of which are hosted on an IP address and promise hacks for popular games. The heuristic 'PDF_SEO_LINK_FARM' indicates a large number of these links, suggesting a malicious intent to redirect users to potentially harmful content or downloads. The ML classifier also strongly flagged this PDF as malicious.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9980

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Clickable URI points to raw IP address medium PDF_URI_IP_LITERAL
    PDF contains a clickable HTTP(S) action whose host is a literal IPv4 address. Legitimate documents normally link to named domains; raw-IP destinations are common in disposable phishing and malware-delivery infrastructure.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://netcdn.tw/app/406889139/hack-to-get-free-spins-on-coin-master-game-hack
    • http://36.94.36.7/elib//repository/coin-master-hack-apk-ios_GM406889139.pdf
    • http://36.94.36.7/elib/repository/coin-master-hack-without-verification_GM406889139.pdf
    • http://36.94.36.7/elib//repository/how-to-get-free-robux-for-real_GM431946152.pdf
    • http://36.94.36.7/elib/repository/how-to-get-free-robux-2021_GM431946152.pdf
    • http://36.94.36.7/elib/repository/roblox-hack-unlimited-robux_GM431946152.pdf
    • http://36.94.36.7/elib/repository/is-hacking-roblox-a-crome_GM431946152.pdf
    • http://36.94.36.7/elib/repository/free-robux-without-human-verification-real_GM431946152.pdf
    • http://36.94.36.7/elib/repository/how-to-get-free-minecoins-in-minecraft_GM479516143.pdf
    • http://36.94.36.7/elib//repository/how-to-hack-roblox-accounts-2021-easy_GM431946152.pdf
    • http://36.94.36.7/elib/repository/roblox-games-for-free-no-download_GM431946152.pdf
    • http://36.94.36.7/elib/repository/blogger-free-spins-and-coins_GM406889139.pdf
    • http://36.94.36.7/elib/repository/free-robux-on-phone-no-verification_GM431946152.pdf
    • http://36.94.36.7/elib/repository/e-free-roblox_GM431946152.pdf
    • http://36.94.36.7/elib/repository/vdeos-de-los-mejores-hackers-que-hackean-cuentas-en-roblox_GM431946152.pdf
    • http://36.94.36.7/elib/repository/coin-master-free-spins-hack-iphone_GM406889139.pdf
    • http://36.94.36.7/elib/repository/snapes-free-download-roblox_GM431946152.pdf
    • http://36.94.36.7/elib//repository/coin-master-free-spins-deutsch-download-ios-link_GM406889139.pdf
    • http://36.94.36.7/elib//repository/free-roblox-girl-hair-not-a-model_GM431946152.pdf
    • http://36.94.36.7/elib//repository/free-games-like-coin-master_GM406889139.pdf
    • http://36.94.36.7/elib/repository/roblox-person_GM431946152.pdf
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000327c.bin
2636e0cfb72809e60b9b9368d69491b35cde94d5b048116b412782d315b84d20
pdf-font-stream PDF embedded font (sfnt) at offset 0x327C 22728 bytes
font_01_sfnt_off0000654d.bin
49656a9ce1f79f371d4147e6373d1b345a80f0cbc55be9fbc1109b8dbb6a841c
pdf-font-stream PDF embedded font (sfnt) at offset 0x654D 18344 bytes