Malicious PDF — malware analysis report

Static analysis result for SHA-256 ef5d15013fb22b26…

MALICIOUS

PDF

48.1 KB Created: 2021-06-02 19:29:23 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: a594cb64c2ef7fa384b054baaee37122 SHA-1: 641d1f165deefc9df7e0fa728f6c9a19cf2e311d SHA-256: ef5d15013fb22b2657874d1ca7b13d08984ecf77f098b49887b7e7c8676ae1c0
96 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF document contains numerous embedded links to external websites, many of which appear to be related to game hacks, cheats, or scams. The ML classifier strongly indicates maliciousness, and the presence of a large number of external links suggests a link farm or redirection to malicious content. No scripts were extracted, but the document body and heuristics point towards a phishing or scamming attempt.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9993

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • External URI info PDF_URI
    PDF contains an external URL action
  • PDF differential parser failed info PDF_DIFFERENTIAL_PARSE_FAILED
    The cross-check parser (pdfminer.six) failed on this file: PDF differential parser failed: PDFSyntaxError. Static heuristics still ran and any of their findings above are valid; only the differential cross-check signal is missing.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://netcdn.xyz/app/431946152/download-roblox-pc-windows-10-free-game-hack
    • http://szekelymozes.ro/images/coin-master-hack-tool-without-human-verification_GM406889139.pdf
    • http://szekelymozes.ro/images/free-roblox-outfits-2021_GM431946152.pdf
    • http://szekelymozes.ro/images/download-coin-master-apk-hack_GM406889139.pdf
    • http://szekelymozes.ro/images/how-to-get-minecraft-java-for-free_GM479516143.pdf
    • http://szekelymozes.ro/images/how-to-get-free-robux-app_GM431946152.pdf
    • http://szekelymozes.ro/images/how-to-hack-roblox-for-robux_GM431946152.pdf
    • http://szekelymozes.ro/images/coinmaster-spin-ml-free_GM406889139.pdf
    • http://szekelymozes.ro/images/how-to-hack-mcpe-master-coins_GM406889139.pdf
    • http://szekelymozes.ro/images/rbxoffers-earn-free-robux_GM431946152.pdf
    • http://szekelymozes.ro/images/roblox-free-robux-no-human-verification_GM431946152.pdf
    • http://szekelymozes.ro/images/coin-master-free-spins-promo-code_GM406889139.pdf
    • http://szekelymozes.ro/images/minecraft-ps4-code-free_GM479516143.pdf
    • http://szekelymozes.ro/images/coin-master-heaven-free-spins-today_GM406889139.pdf
    • http://szekelymozes.ro/images/coin-master-spins-hack-2021_GM406889139.pdf
    • http://szekelymozes.ro/images/free-robux-no-human-verification-generator_GM431946152.pdf
    • http://szekelymozes.ro/images/minecraft-world-free-download_GM479516143.pdf
    • http://szekelymozes.ro/images/how-many-levels-in-coin-master_GM406889139.pdf
    • http://szekelymozes.ro/images/roblox-catalog-free_GM431946152.pdf
    • http://szekelymozes.ro/images/free-robux-no-human-verification-or-survey-or-download_GM431946152.pdf
    • http://szekelymozes.ro/images/how-to-get-free-fans-on-tiktok_GM835599320.pdf
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_004_off000052b6.bin
54723e59d6313911a44eea28d37ac769f8a6c173a1750cd9ae5d2e53e2b46b58
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x52B6 27024 bytes
font_01_sfnt_off00008f74.bin
3fb127b764b9d10f5525bc4de5ec8316de704409ccb0cf21cff3ad8a30d11676
pdf-font-stream PDF embedded font (sfnt) at offset 0x8F74 2840 bytes
font_02_sfnt_off00009926.bin
ee1809217b52adb4f2b0727edbb9917094df3730f8bb4fb0975337aef5c81433
pdf-font-stream PDF embedded font (sfnt) at offset 0x9926 19432 bytes