Malicious PDF — malware analysis report

Static analysis result for SHA-256 d006111dba702a55…

MALICIOUS

PDF

50.4 KB Created: 2021-06-03 22:03:50 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: 1a02f04c70625f6896c631e13dad6281 SHA-1: a190cb25d6f8ad12d03bdd599b3c65bad353e7d2 SHA-256: d006111dba702a55e0a6962d210c99badda7e1fa131bff2d842c149e63fe02d6
102 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF document contains numerous external links, many of which are SEO-optimized and point to other PDF files, suggesting a link farm or redirection scheme. The primary URL leads to a page offering free spins for a game, a common lure for phishing or malware distribution. While no scripts were explicitly extracted, the PDF structure and the ML classifier's high confidence indicate malicious intent, likely to redirect users to malicious sites or download further payloads.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9769

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://netcdn.online/app/406889139/where-can-i-get-free-spins-for-coin-master-game-hack
    • https://digilib.stkip-pgri-sumbar.ac.id/repository/get-free-spins-coin-master-link_GM406889139.pdf
    • https://digilib.stkip-pgri-sumbar.ac.id/repository/mine-minecraft-games-for-free_GM479516143.pdf
    • https://digilib.stkip-pgri-sumbar.ac.id/repository/coin-master-game-for-pc-free-download_GM406889139.pdf
    • https://digilib.stkip-pgri-sumbar.ac.id/repository/coin-master-daily-free-spins-link-2021-today_GM406889139.pdf
    • https://digilib.stkip-pgri-sumbar.ac.id/repository/how-to-get-free-cards-for-coin-master_GM406889139.pdf
    • https://digilib.stkip-pgri-sumbar.ac.id/repository/coin-master-daily-free-spin-and-coin_GM406889139.pdf
    • https://digilib.stkip-pgri-sumbar.ac.id/repository/how-to-get-free-robux-games_GM431946152.pdf
    • https://digilib.stkip-pgri-sumbar.ac.id/repository/roblox-hack-ga_GM431946152.pdf
    • https://digilib.stkip-pgri-sumbar.ac.id/repository/minecraft-toys-for-free_GM479516143.pdf
    • https://digilib.stkip-pgri-sumbar.ac.id/repository/robux-gift-card-free_GM431946152.pdf
    • https://digilib.stkip-pgri-sumbar.ac.id/repository/free-promo-codes-for-robux_GM431946152.pdf
    • https://digilib.stkip-pgri-sumbar.ac.id/repository/free-robux-discord-servers_GM431946152.pdf
    • https://digilib.stkip-pgri-sumbar.ac.id/repository/how-to-get-free-coins-on-coin-master-hack_GM406889139.pdf
    • https://digilib.stkip-pgri-sumbar.ac.id/repository/minecraft-com-free_GM479516143.pdf
    • https://digilib.stkip-pgri-sumbar.ac.id/repository/free-minecraft-account_GM479516143.pdf
    • https://digilib.stkip-pgri-sumbar.ac.id/repository/how-to-hack-roblox-to-get-free-robux_GM431946152.pdf
    • https://digilib.stkip-pgri-sumbar.ac.id/repository/how-to-get-free-robux-codes-2021_GM431946152.pdf
    • https://digilib.stkip-pgri-sumbar.ac.id/repository/minecraft-java-free-download_GM479516143.pdf
    • https://digilib.stkip-pgri-sumbar.ac.id/repository/coin-master-time-hack-2021_GM406889139.pdf
    • https://digilib.stkip-pgri-sumbar.ac.id/repository/hack-coin-master-game-apk_GM406889139.pdf
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_004_off0000542b.bin
530387714c9fcad25b4dad75451aef8cd95434e32ead19bf423c8bd11b1a8878
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x542B 33228 bytes
font_01_sfnt_off000098e4.bin
30dce2b9c1950da345d7fed8f00c38887adfa2f2ddecc31775af2315e819ac37
pdf-font-stream PDF embedded font (sfnt) at offset 0x98E4 2840 bytes
font_02_sfnt_off0000a297.bin
8779a24c74e66c23b33121dd1a71955adfc2f322ab09b0870da4a74651533123
pdf-font-stream PDF embedded font (sfnt) at offset 0xA297 18248 bytes