Malicious PDF — malware analysis report

Static analysis result for SHA-256 f1c02485eb945806…

MALICIOUS

PDF

42.5 KB Created: 2021-05-12 19:43:31 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: 7e88348b74e37e98c6b8723dceb30558 SHA-1: a5f52688555516a3b155ba6e7e8f3c4d23489291 SHA-256: f1c02485eb94580686ed03e55d92d1b4d99fd96adcb014b75bc951fb668a6985
102 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF document contains numerous embedded URLs that lead to websites offering game-related downloads and cheats, indicative of a link farm or phishing lure. The presence of a PDF_SEO_LINK_FARM heuristic firing suggests a large number of these links were generated programmatically. While no scripts were explicitly extracted, the PDF structure and embedded URLs strongly suggest an attempt to redirect users to malicious or unwanted content, likely for financial gain or to distribute further malware.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9971

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://netcdn.xyz/app/479516143/minecraft-pe-texture-packs-free-download-game-hack
    • http://pandaplast.com/images/free-roblox-accounts-with-robux_GM431946152.pdf
    • http://pandaplast.com/images/free-robux-download_GM431946152.pdf
    • http://pandaplast.com/images/www-bandicam-com-free-robux_GM431946152.pdf
    • http://pandaplast.com/images/coin-master-hack-download-apk_GM406889139.pdf
    • http://pandaplast.com/images/daily-free-spins-for-coin-master_GM406889139.pdf
    • http://pandaplast.com/images/how-to-get-free-robux-easy-hack_GM431946152.pdf
    • http://pandaplast.com/images/roblox-script-hack_GM431946152.pdf
    • http://pandaplast.com/images/ear-free-spins-for-coin-master_GM406889139.pdf
    • http://pandaplast.com/images/hack-minecraft_GM479516143.pdf
    • http://pandaplast.com/images/coin-master-game-hack-version-download_GM406889139.pdf
    • http://pandaplast.com/images/buy-robux-free_GM431946152.pdf
    • http://pandaplast.com/images/how-to-get-more-robux-for-free_GM431946152.pdf
    • http://pandaplast.com/images/coin-master-shield-hack_GM406889139.pdf
    • http://pandaplast.com/images/roblox-free-body_GM431946152.pdf
    • http://pandaplast.com/images/roblox-builders-club-free_GM431946152.pdf
    • http://pandaplast.com/images/coin-master-hack-version-download-ios_GM406889139.pdf
    • http://pandaplast.com/images/get-roebucks-com_GM431946152.pdf
    • http://pandaplast.com/images/coin-master-free-spins-link-blogspot-2021_GM406889139.pdf
    • http://pandaplast.com/images/pig-master-free-coins-and-spins_GM406889139.pdf
    • http://pandaplast.com/images/free-robux-generator-without-verification_GM431946152.pdf
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_003_off00004903.bin
31655befae0b0c34a50434e2b2b1a39b2c975bcf9675c5323fb3c0f57c257359
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x4903 24732 bytes
font_01_sfnt_off000081ff.bin
1b5792c60b30e583584a054579e4e1bc8a5b61d7ac54d764bc66a902e5cfcfa0
pdf-font-stream PDF embedded font (sfnt) at offset 0x81FF 18964 bytes