Malicious PDF — malware analysis report

Static analysis result for SHA-256 bf8a3c84cfa6572a…

MALICIOUS

PDF

34.3 KB Created: 2021-06-29 13:43:51 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: 452647a0dfab3a1d93fbe357406a2909 SHA-1: 9202febdb00b233d4a618663d4fbbd1263f773ff SHA-256: bf8a3c84cfa6572a97d81457fa484ab9a4bdd96ee7310b0c38c5483cc64fde94
102 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1203 Exploitation for Client Execution

The PDF document contains numerous embedded URLs and a document body that promotes free in-game items and hacks for popular games, indicating a phishing or scam lure. The ML classifier and PDF SEO link farm heuristic strongly suggest malicious intent, likely to redirect users to malicious sites or download further malware. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9980

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://netcdn.co/app/431946152/roblox-promo-card-hack-game-hack
    • http://digilibfisip.unla.ac.id/repository/i-want-free-robux_GM431946152.pdf
    • http://digilibfisip.unla.ac.id/repository/minecraft-java-edition-free-code_GM479516143.pdf
    • http://digilibfisip.unla.ac.id/repository/free-robux-human-verification_GM431946152.pdf
    • http://digilibfisip.unla.ac.id/repository/how-to-hack-any-roblox-account_GM431946152.pdf
    • http://digilibfisip.unla.ac.id/repository/how-to-get-minecoins-in-minecraft-for-free_GM479516143.pdf
    • http://digilibfisip.unla.ac.id/repository/how-to-get-free-robux-without-email_GM431946152.pdf
    • http://digilibfisip.unla.ac.id/repository/free-roblox-injector_GM431946152.pdf
    • http://digilibfisip.unla.ac.id/repository/coin-master-free-spins-and-coins-daily_GM406889139.pdf
    • http://digilibfisip.unla.ac.id/repository/free-spin-coin-master-link-2021_GM406889139.pdf
    • http://digilibfisip.unla.ac.id/repository/how-to-get-free-robux-gift-cards_GM431946152.pdf
    • http://digilibfisip.unla.ac.id/repository/roblox-hack-synapse_GM431946152.pdf
    • http://digilibfisip.unla.ac.id/repository/roblox-song-i-want-to-break-free_GM431946152.pdf
    • http://digilibfisip.unla.ac.id/repository/promo-code-free-robux_GM431946152.pdf
    • http://digilibfisip.unla.ac.id/repository/roblox-inappropriate-games_GM431946152.pdf
    • http://digilibfisip.unla.ac.id/repository/play-roblox-for-free-online-now_GM431946152.pdf
    • http://digilibfisip.unla.ac.id/repository/roblox-promo-codes-free-robux_GM431946152.pdf
    • http://digilibfisip.unla.ac.id/repository/free-robux-inspect-2021_GM431946152.pdf
    • http://digilibfisip.unla.ac.id/repository/free-hacks-for-coin-master_GM406889139.pdf
    • http://digilibfisip.unla.ac.id/repository/are-there-any-free-back-lanes-on-roblox_GM431946152.pdf
    • http://digilibfisip.unla.ac.id/repository/coin-master-free-spins-link-2021-today_GM406889139.pdf
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00002ed7.bin
1b78dff14c4be7539ea691de6ae93474814fd00eabdaee4c22562a92afbb1baa
pdf-font-stream PDF embedded font (sfnt) at offset 0x2ED7 22304 bytes
font_01_sfnt_off00006088.bin
2cfc087c20e532e2dabac4dfa056c80d93ab95a2d5057d98a00b031fd2761189
pdf-font-stream PDF embedded font (sfnt) at offset 0x6088 19244 bytes