Malicious PDF — malware analysis report

Static analysis result for SHA-256 e9b51b671d8d3b23…

MALICIOUS

PDF

34.4 KB Created: 2021-07-06 00:46:18 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: 9d212548893ababbf75f58ee855237d4 SHA-1: 24f200129a7b1a5a7f89ac97059a40be3456c9f4 SHA-256: e9b51b671d8d3b23a35d99ffb183089eee40c9358dad064ac7fbcbd1b24417f5
122 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

This PDF document contains a large number of links to external PDFs, many hosted on an IP address, promoting free game currency or cheats. The heuristic 'PDF_SEO_LINK_FARM' indicates a mass of external PDF links, suggesting a link farm or phishing attempt. The ML classifier also flagged this PDF as malicious with high confidence.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9980

Heuristics 5

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Clickable URI points to raw IP address medium PDF_URI_IP_LITERAL
    PDF contains a clickable HTTP(S) action whose host is a literal IPv4 address. Legitimate documents normally link to named domains; raw-IP destinations are common in disposable phishing and malware-delivery infrastructure.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://netcdn.tw/app/479516143/minecraft-games-to-play-for-free-game-hack
    • http://202.56.165.220/digilab/repository/rbx-boots-earn-free-robux_GM431946152.pdf
    • http://202.56.165.220/digilab/repository/free-account-for-roblox-infinite-robux_GM431946152.pdf
    • http://202.56.165.220/digilab/repository/roblox-generator-no-human-verification_GM431946152.pdf
    • http://202.56.165.220/digilab/repository/best-games-to-hack-on-roblox_GM431946152.pdf
    • http://202.56.165.220/digilab/repository/coin-master-free-spins-link-download-apk_GM406889139.pdf
    • http://202.56.165.220/digilab/repository/penguinson-roblox-free-robux-hack_GM431946152.pdf
    • http://202.56.165.220/digilab/repository/how-to-cheat-in-roblox-ninja-legends_GM431946152.pdf
    • http://202.56.165.220/digilab/repository/free-robux-generator-no-password-required_GM431946152.pdf
    • http://202.56.165.220/digilab/repository/free-robux-easy-and-fast-2021_GM431946152.pdf
    • http://202.56.165.220/digilab/repository/minecraft-noob-vs-pro-vs-hacker-vs-god_GM479516143.pdf
    • http://202.56.165.220/digilab/repository/how-to-hack-on-accounts-on-roblox_GM431946152.pdf
    • http://202.56.165.220/digilab/repository/how-to-get-free-robux-2021-october_GM431946152.pdf
    • http://202.56.165.220/digilab/repository/italwhts-the-best-free-horror-games-on-roblox_GM431946152.pdf
    • http://202.56.165.220/digilab/repository/coin-master-50-spin-link_GM406889139.pdf
    • http://202.56.165.220/digilab/repository/coin-master-game_GM406889139.pdf
    • http://202.56.165.220/digilab/repository/coin-master-hackcom-xyz_GM406889139.pdf
    • http://202.56.165.220/digilab/repository/wurst-112_GM479516143.pdf
    • http://202.56.165.220/digilab/repository/roblox-ninja-legends-free-vip-server-2021_GM431946152.pdf
    • http://202.56.165.220/digilab/repository/roblox-ainti-cheat_GM431946152.pdf
    • http://202.56.165.220/digilab/repository/roblox-hack-hay-day_GM431946152.pdf
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00003168.bin
b02cd49ded53fb32dd8bf5bc8b6e8f755a016a473c42578884b49a2954708ffa
pdf-font-stream PDF embedded font (sfnt) at offset 0x3168 22248 bytes
font_01_sfnt_off000062b2.bin
0725e80f6a4e873f5ab50492ee12f8fb405ccf899727b50dbe4c632344f48946
pdf-font-stream PDF embedded font (sfnt) at offset 0x62B2 18664 bytes