Malicious PDF — malware analysis report

Static analysis result for SHA-256 cb1f5f452523f0ad…

MALICIOUS

PDF

35.1 KB Created: 2021-07-04 23:07:33 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: 4d17777ddff3ce6eecaac405441453f2 SHA-1: 3b42a35c6670be13865b48336a55f617bcace847 SHA-256: cb1f5f452523f0ade05e0454b767e92c8ada9796dc2b63b521eea43646dd5846
102 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF document contains numerous links to external websites, many of which are hosted on domains suggesting the distribution of game hacks and exploits. The presence of a "PDF_SEO_LINK_FARM" heuristic firing indicates a large number of these links were generated programmatically, likely to attract users searching for cheats or unauthorized software. The ML classifier also strongly flagged this PDF as malicious, supporting the conclusion that it is designed to redirect users to potentially harmful content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9980

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://netcdn.tw/app/406889139/coin-master-hack-apk-35-8-game-hack
    • https://katalog.smkn1glagah.sch.id/repository/free-roblox-shirt-templates-2021_GM431946152.pdf
    • https://katalog.smkn1glagah.sch.id/repository/roblox-hack-2021-free-robux-generator-no-human-verification_GM431946152.pdf
    • https://katalog.smkn1glagah.sch.id/repository/hack-to-log-on-any-account-on-roblox_GM431946152.pdf
    • https://katalog.smkn1glagah.sch.id/repository/coin-master-free-spins-8-14-2021_GM406889139.pdf
    • https://katalog.smkn1glagah.sch.id/repository/how-to-download-minecraft-for-free-on-windows-10_GM479516143.pdf
    • https://katalog.smkn1glagah.sch.id/repository/hack-coin-master-with-lucky-patcher_GM406889139.pdf
    • https://katalog.smkn1glagah.sch.id//repository/link-for-free-spins-on-coin-master_GM406889139.pdf
    • https://katalog.smkn1glagah.sch.id/repository/free-spins-coin-master-links-2021_GM406889139.pdf
    • https://katalog.smkn1glagah.sch.id/repository/roblox-free-exploit-lvl-6-september-2021_GM431946152.pdf
    • https://katalog.smkn1glagah.sch.id/repository/free-coins-coin-master-2021_GM406889139.pdf
    • https://katalog.smkn1glagah.sch.id/repository/roblox-mafia-hack_GM431946152.pdf
    • https://katalog.smkn1glagah.sch.id/repository/cheat-engine-clone-tycoon-2-roblox_GM431946152.pdf
    • https://katalog.smkn1glagah.sch.id/repository/minecraft-free-ios-no-verification_GM479516143.pdf
    • https://katalog.smkn1glagah.sch.id//repository/free-robux-no-verification-no-download-2021_GM431946152.pdf
    • https://katalog.smkn1glagah.sch.id/repository/bux-free-robux_GM431946152.pdf
    • https://katalog.smkn1glagah.sch.id/repository/how-to-get-minecraft-windows-10-for-free-with-java_GM479516143.pdf
    • https://katalog.smkn1glagah.sch.id//repository/coin-master-daily-free-spin-and-coin_GM406889139.pdf
    • https://katalog.smkn1glagah.sch.id/repository/how-to-prevent-being-hacked-on-roblox_GM431946152.pdf
    • https://katalog.smkn1glagah.sch.id/repository/legitimate-coin-master-free-spins-apk_GM406889139.pdf
    • https://katalog.smkn1glagah.sch.id/repository/minecraft-windows-10-hack-client-2021_GM479516143.pdf
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_002_off00003223.bin
8ccaebb3a6553e1ead36465474e2964173f692653eee83ad9c289deefd375f5b
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x3223 22812 bytes
font_01_sfnt_off00006538.bin
69b4a3ebe7d4e13e60a257f8c137696d5b2ec2d9c23dd61936efc68b08181d97
pdf-font-stream PDF embedded font (sfnt) at offset 0x6538 18696 bytes