Malicious PDF — malware analysis report

Static analysis result for SHA-256 d82400a5c24002bc…

MALICIOUS

PDF

47.4 KB Created: 2021-06-08 17:50:25 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: 51cbf10ed387de7c438fc76b2050bd72 SHA-1: a399b915c705fe633541039df3ac7c8ef68360e1 SHA-256: d82400a5c24002bc107f83f3b3520dc3b3efff7f75c4e475012f3891b4d96ca5
142 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 User Execution: Malicious Link

The PDF contains numerous external links, many of which are part of a link farm designed to boost SEO. The document also presents a fake CAPTCHA or human verification prompt to trick users into interacting with these links. The primary goal appears to be driving traffic to SEO spam pages related to game cheats and hacks.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9832

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Fake CAPTCHA / human verification prompt high SE_FAKE_CAPTCHA
    Document displays a fake CAPTCHA or human-verification prompt — used to trick users into running commands or pressing keyboard shortcuts
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://netcdn.tw/app/431946152/how-to-get-1-million-robux-hack-by-inspecting-robux-game-hack
    • https://zbych-pol.pl/wp-content/uploads/fsqm-files/free-roblox-girl-accounts-with-robux_GM431946152.pdf
    • https://zbych-pol.pl/wp-content/uploads/fsqm-files/coin-master-15-free-spin-link-of-last-5-days_GM406889139.pdf
    • https://zbych-pol.pl/wp-content/uploads/fsqm-files/rare-roblox-hacked-face_GM431946152.pdf
    • https://zbych-pol.pl/wp-content/uploads/fsqm-files/how-to-get-free-spins-on-coin-master_GM406889139.pdf
    • https://zbych-pol.pl/wp-content/uploads/fsqm-files/free-robux-generator-tool-download_GM431946152.pdf
    • https://zbych-pol.pl/wp-content/uploads/fsqm-files/free-promo-codes-for-robux_GM431946152.pdf
    • https://zbych-pol.pl/wp-content/uploads/fsqm-files/coin-master-free-blogspot_GM406889139.pdf
    • https://zbych-pol.pl/wp-content/uploads/fsqm-files/hack-tool-roblox-pokemon-adventures_GM431946152.pdf
    • https://zbych-pol.pl/wp-content/uploads/fsqm-files/como-desbloquear-un-cuenta-hackeada-de-roblox_GM431946152.pdf
    • https://zbych-pol.pl/wp-content/uploads/fsqm-files/minecraft-online-free-no-download_GM479516143.pdf
    • https://zbych-pol.pl/wp-content/uploads/fsqm-files/is-minecraft-free-on-pc_GM479516143.pdf
    • https://zbych-pol.pl/wp-content/uploads/fsqm-files/how-to-speed-hack-in-swordburst-2-in-roblox-2021_GM431946152.pdf
    • https://zbych-pol.pl/wp-content/uploads/fsqm-files/free-superhero-roblox_GM431946152.pdf
    • https://zbych-pol.pl/wp-content/uploads/fsqm-files/roblox-robux-generator-tool-2021-robux-hack-robux-free_GM431946152.pdf
    • https://zbych-pol.pl/wp-content/uploads/fsqm-files/coin-master-free-spin-codes_GM406889139.pdf
    • https://zbych-pol.pl/wp-content/uploads/fsqm-files/coin-master-free-spins-link-2021_GM406889139.pdf
    • https://zbych-pol.pl/wp-content/uploads/fsqm-files/free-robux-for-tablet-pro_GM431946152.pdf
    • https://zbych-pol.pl/wp-content/uploads/fsqm-files/cruise-ship-tycoon-hack-roblox_GM431946152.pdf
    • https://zbych-pol.pl/wp-content/uploads/fsqm-files/tiktok-followers-for-free_GM835599320.pdf
    • https://zbych-pol.pl/wp-content/uploads/fsqm-files/roblox-cheat-engine-the-streets_GM431946152.pdf
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_004_off000055fa.bin
d192c31c2d1cf9dec08823446d7934317bb15739311919463c314f779876317d
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x55FA 26276 bytes
font_01_sfnt_off000092bf.bin
a00dacef47d6a632f789a510ee57b4ac84e42aa74654f238db0050f10f9c1be7
pdf-font-stream PDF embedded font (sfnt) at offset 0x92BF 19656 bytes