Malicious PDF — malware analysis report

Static analysis result for SHA-256 e1146437fbef803f…

MALICIOUS

PDF

34.4 KB Created: 2021-07-05 01:27:53 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: 7f3bbc3ad8f4ca24c514f3239562fb29 SHA-1: 138f0f9dc011f3e255cf075849a7683c357b4e6d SHA-256: e1146437fbef803f17ecd0c157f59c3702597bc94a3f33af33247a38d2357f4b
102 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF document contains a large number of embedded links, many of which are SEO-optimized and point to sites offering game-related hacks and free accounts. The ML classifier strongly indicated maliciousness, and the presence of numerous external links suggests a link farm or phishing attempt. The document body explicitly mentions 'free roblox adopt me accounts' and includes URLs that reinforce this lure.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9980

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://netcdn.tw/app/431946152/free-roblox-adopt-me-accounts-game-hack
    • http://ebook.itn.ac.id/repository/coin-master-hack-https-coinms-net_GM406889139.pdf
    • http://ebook.itn.ac.id/repository/roblox-premium-free_GM431946152.pdf
    • http://ebook.itn.ac.id/repository/get-free-robux-info_GM431946152.pdf
    • http://ebook.itn.ac.id/repository/free-roblox-accounts-dump_GM431946152.pdf
    • http://ebook.itn.ac.id/repository/free-robux-by-watching-ads_GM431946152.pdf
    • http://ebook.itn.ac.id/repository/deadly-sins-online-roblox-hacks_GM431946152.pdf
    • http://ebook.itn.ac.id/repository/coin-master-hack-apk-no-fb-login_GM406889139.pdf
    • http://ebook.itn.ac.id/repository/coin-master-hack-version-download-2021-android_GM406889139.pdf
    • http://ebook.itn.ac.id/repository/how-to-get-free-robux-without-verification-2021_GM431946152.pdf
    • http://ebook.itn.ac.id/repository/free-robux-2021-no-verification_GM431946152.pdf
    • http://ebook.itn.ac.id/repository/coin-master-free-daily-spins_GM406889139.pdf
    • http://ebook.itn.ac.id/repository/how-to-get-free-robux-on-pc_GM431946152.pdf
    • http://ebook.itn.ac.id/repository/minecraft-java-edition-redeem-code-free-2021_GM479516143.pdf
    • http://ebook.itn.ac.id/repository/how-to-change-roblox-username-for-free_GM431946152.pdf
    • http://ebook.itn.ac.id/repository/earn-robux-com_GM431946152.pdf
    • http://ebook.itn.ac.id/repository/how-to-get-spins-on-coin-master-hack_GM406889139.pdf
    • http://ebook.itn.ac.id/repository/roblox-free-robux-codes_GM431946152.pdf
    • http://ebook.itn.ac.id/repository/roblox-hacked-version_GM431946152.pdf
    • http://ebook.itn.ac.id/repository/how-to-hack-roblox-to-get-robux_GM431946152.pdf
    • http://ebook.itn.ac.id/repository/free-spins-for-coin-master-2021_GM406889139.pdf
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00002d89.bin
d98a6d3ffd97e2fc2f03871aa39b7c0b06505b8ae8410f0f91bd254dfd3958ed
pdf-font-stream PDF embedded font (sfnt) at offset 0x2D89 22676 bytes
font_01_sfnt_off0000601d.bin
88194e20aa1d794cbfbc6ec60bdf20d6817b6f04f409d3f051b45d150e534ec5
pdf-font-stream PDF embedded font (sfnt) at offset 0x601D 19440 bytes