Malicious PDF — malware analysis report

Static analysis result for SHA-256 f38f4e4b57df1a5a…

MALICIOUS

PDF

45.0 KB Created: 2021-06-08 01:22:30 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: 68de1a8b0561b5f9ea30d2bb25b6de3e SHA-1: d4334253e2762608f8d03feebcde1a86c1a797ea SHA-256: f38f4e4b57df1a5adb11136d6cfa1c4f59e4634457343e0a47bbf856fb034329
102 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF document contains numerous embedded links, forming a link farm, and a prominent call-to-action related to free in-game currency. The ML classifier strongly flagged this PDF as malicious. The presence of external URIs suggests an attempt to redirect the user to malicious websites, likely for credential harvesting or to download further payloads.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9865

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://netcdn.tw/app/431946152/free-robux-that-only-needs-your-password-totally-game-hack
    • http://apostolosandreaslemesou.com/images/como-generar-coin-master-free-spins_GM406889139.pdf
    • http://apostolosandreaslemesou.com/images/free-robux-for-nintendo-switch_GM431946152.pdf
    • http://apostolosandreaslemesou.com/images/free-pokemon-go-accounts-level-35_GM1094591345.pdf
    • http://apostolosandreaslemesou.com/images/free-robux-easy-and-fast_GM431946152.pdf
    • http://apostolosandreaslemesou.com/images/robux-codes-generator-no-human-verification_GM431946152.pdf
    • http://apostolosandreaslemesou.com/images/minecraft-bedrock-edition-download-pc-free_GM479516143.pdf
    • http://apostolosandreaslemesou.com/images/daily-free-spins-coin-master_GM406889139.pdf
    • http://apostolosandreaslemesou.com/images/free-printable-roblox-images_GM431946152.pdf
    • http://apostolosandreaslemesou.com/images/daily-free-spins-for-coin-master_GM406889139.pdf
    • http://apostolosandreaslemesou.com/images/minecraft-bedrock-hacks_GM479516143.pdf
    • http://apostolosandreaslemesou.com/images/coin-master-free-daily-spins-and-coins_GM406889139.pdf
    • http://apostolosandreaslemesou.com/images/free-attacks-coin-master_GM406889139.pdf
    • http://apostolosandreaslemesou.com/images/free-robux-kid-friendly_GM431946152.pdf
    • http://apostolosandreaslemesou.com/images/free-coins-coin-master-2021_GM406889139.pdf
    • http://apostolosandreaslemesou.com/images/free-robux-com-real_GM431946152.pdf
    • http://apostolosandreaslemesou.com/images/coin-master-daily-rewards_GM406889139.pdf
    • http://apostolosandreaslemesou.com/images/how-to-hack-roblox-games_GM431946152.pdf
    • http://apostolosandreaslemesou.com/images/get-free-spins-coin-master-2021_GM406889139.pdf
    • http://apostolosandreaslemesou.com/images/free-coin-master-spins-for-today_GM406889139.pdf
    • http://apostolosandreaslemesou.com/images/how-to-get-free-robux-easy-and-fast-2021_GM431946152.pdf
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_004_off000051ff.bin
3ad693245d09bb16ab09eb38efed927e993a3ca9f9e80e1125a986ae596ef2d9
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x51FF 24572 bytes
font_01_sfnt_off000089cf.bin
bbd31ea4fd6f829eb722e4ae93c8deb1621dbeca2fc4bf196a7587250aba73a2
pdf-font-stream PDF embedded font (sfnt) at offset 0x89CF 19420 bytes