Malicious PDF — malware analysis report

Static analysis result for SHA-256 d3a189752fadc748…

MALICIOUS

PDF

34.9 KB Created: 2021-06-22 11:53:09 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: 5d3a10733ec57c17e7e2b1ab27ddee1e SHA-1: cd132723a4aa5a5915785cc653af143d57b0d854 SHA-256: d3a189752fadc748a536634757b41b64d0a2bc44a4a02db88f155ce8594ee9c0
102 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1203 Exploitation for Client Execution

The PDF document contains numerous external links, many of which are presented as 'SEO links' and point to pages offering game cheats and hacks. The ML classifier strongly indicates maliciousness, and the presence of a download button lure reinforces the deceptive nature of the document. The primary goal appears to be directing users to download potentially harmful files or visit malicious websites.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9980

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://netcdn.co/app/431946152/cheat-codes-roblox-mad-city-game-hack
    • https://www.orbai.ai/uploaded_files/userfiles/files/how-to-get-free-robux-without-human-verification-or-email_GM431946152.pdf
    • https://www.orbai.ai/uploaded_files/userfiles/files/free-coins-and-spins-coin-master_GM406889139.pdf
    • https://www.orbai.ai/uploaded_files/userfiles/files/coin-master-hack-xyz-download-free_GM406889139.pdf
    • https://www.orbai.ai/uploaded_files/userfiles/files/robux-com-free_GM431946152.pdf
    • https://www.orbai.ai/uploaded_files/userfiles/files/coin-master-hack-without-verification-code_GM406889139.pdf
    • https://www.orbai.ai/uploaded_files/userfiles/files/roblox-free-roblox_GM431946152.pdf
    • https://www.orbai.ai/uploaded_files/userfiles/files/coin-master-free-spins-iphone-2021_GM406889139.pdf
    • https://www.orbai.ai/uploaded_files/userfiles/files/i-want-robux_GM431946152.pdf
    • https://www.orbai.ai/uploaded_files/userfiles/files/free-card-link-coin-master_GM406889139.pdf
    • https://www.orbai.ai/uploaded_files/userfiles/files/free-robux-with-no-human-verification_GM431946152.pdf
    • https://www.orbai.ai/uploaded_files/userfiles/files/promo-codes-to-get-free-robux_GM431946152.pdf
    • https://www.orbai.ai/uploaded_files/userfiles/files/orewards-com-free-robux_GM431946152.pdf
    • https://www.orbai.ai/uploaded_files/userfiles/files/coin-master-heaven-free-spins_GM406889139.pdf
    • https://www.orbai.ai/uploaded_files/userfiles/files/how-can-i-get-free-spins-on-coin-master_GM406889139.pdf
    • https://www.orbai.ai/uploaded_files/userfiles/files/hack-my-game-xyz-coin-master_GM406889139.pdf
    • https://www.orbai.ai/uploaded_files/userfiles/files/omg-free-robux_GM431946152.pdf
    • https://www.orbai.ai/uploaded_files/userfiles/files/free-robux-ad_GM431946152.pdf
    • https://www.orbai.ai/uploaded_files/userfiles/files/coin-master-free-spin-and-coin-links_GM406889139.pdf
    • https://www.orbai.ai/uploaded_files/userfiles/files/free-robux-only-username_GM431946152.pdf
    • https://www.orbai.ai/uploaded_files/userfiles/files/coin-master-free-spins-daily_GM406889139.pdf
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000030b7.bin
e5d6f9fcd35d30ed346dc701e476da6f9e22d3990afbb2bfdcf3d8cd109ccba6
pdf-font-stream PDF embedded font (sfnt) at offset 0x30B7 22212 bytes
font_01_sfnt_off00006240.bin
e95d4cb9270ad83f601a02f9713982a5aa856e5aa0bda7ff809999a50b777a97
pdf-font-stream PDF embedded font (sfnt) at offset 0x6240 19424 bytes