Malicious PDF — malware analysis report

Static analysis result for SHA-256 21bb97e43c7ce7a0…

MALICIOUS

PDF

47.1 KB Created: 2021-04-02 21:10:16 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7) First seen: 2021-10-12
MD5: 7744598591288bb79dd5d9baf133903c SHA-1: 97121fecfb3ab410ee169c4d67adebfa903fc3f0 SHA-256: 21bb97e43c7ce7a0fc9ae79d3d92cbd7cb87ffaa9254c7c90d00183f73b7e932
82 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious File

The PDF document contains a lure for a Roblox hack script, directing users to download a file from a suspicious URL. Heuristics indicate a browser installation lure and a general malicious classification, suggesting the document's primary purpose is to trick users into downloading and executing a malicious payload. No scripts were extracted, but the embedded URLs and social engineering tactics strongly indicate a malware distribution attempt.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9192

Heuristics 4

  • Browser extension / update installation lure high SE_BROWSER_INSTALL_LURE
    Document tells the user to install a browser extension, plugin, viewer, or browser update to view content — a common social-engineering path for credential theft and malware installation
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://gaminggenerator.org/app/431946152/roblox-dbz-legendary-powers-hack-script PDF link annotation
    • http://www.anies.eu/images/how-to-get-free-robux-without-downloading-any-apps.pdfIn PDF document text
    • http://agrao.in/images/roblox-robux-hack-mega.pdfIn PDF document text
    • http://sscclc.edu.ec/images/free-robux-no-generator-no-survey.pdfIn PDF document text
    • http://pa-tanjungselor.go.id/images/best-and-easiest-roblox-hack-for-robux.pdfIn PDF document text
    • http://www.drent.se/images/roblox-how-to-get-free-robux-on-phone.pdfIn PDF document text
    • http://cosver.eu/images/how-to-get-free-robux-and-free-stuff-on-catilog.pdfIn PDF document text
    • https://www.dierenartsberghman.be/images/free-roblox-dlls.pdfIn PDF document text
    • https://www.ghknights.org/images/roblox-free-downloadf.pdfIn PDF document text
    • https://corbo.ru/images/how-to-hack-roblox-games-with-cheat-engine-64.pdfIn PDF document text
    • http://www.pcclawyers.com.au/images/roblox-secret-free-items.pdfIn PDF document text
    • http://domaizdereva24.ru/images/roblox-hacked-online-game.pdfIn PDF document text
    • http://www.inservis.cl/images/guuuddinfo-online-hack-for-robux.pdfIn PDF document text
    • http://www.awakeningtruth.org/images/how-to-hack-on-roblox-with-cheat-engine.pdfIn PDF document text
    • http://sscclc.edu.ec/images/roblox-free-robux-download-2021.pdfIn PDF document text
    • https://technospektr.com.ua/images/roblox-free-t-shirt-for-girl.pdfIn PDF document text
    • http://salantiskis.lt/images/is-free-robux-fake.pdfIn PDF document text
    • http://legs11.co.za/images/free-robux-no-hack-no-inspect.pdfIn PDF document text
    • https://www.elevage-chiot.fr/images/how-to-get-free-packs-in-roblox.pdfIn PDF document text
    • https://www.abrapppe.org.br/images/comoponerse-hacks-en-roblox.pdfIn PDF document text
    • https://www.ncscolour.no/images/lockview-hack-roblox.pdfIn PDF document text
    • http://learningarabic.co.uk/images/half-guest-and-noob-roblox-free.pdfIn PDF document text
    • http://energotestcontrol.ru/images/play-roblox-for-free-unblocked.pdfIn PDF document text
    • http://www.jureclomas.com.ar/images/robloxs-got-talent-piano-hacks.pdfIn PDF document text
    • https://technospektr.com.ua/images/op-rewards-free-robux-2021.pdfIn PDF document text
    • https://www.tsdb.com.au/images/2021-pastebin-free-robux.pdfIn PDF document text
    • http://kruiz21.ru/images/hack-roblox-pc-sur-jailbreak.pdfIn PDF document text
    • http://www.lovecraftiana.com.ar/images/free-robux-with-just-a-click.pdfIn PDF document text
    • http://cosver.eu/images/free-robux-quiz-diva.pdfIn PDF document text
    • http://kruiz21.ru/images/roblox-superhuman-training-simulator-cheats-on-speed.pdfIn PDF document text
    • http://www.lycee-langevin-wallon.com/images/how-to-get-free-stuff-on-roblox-2021-on-phone.pdfIn PDF document text
    • https://crank.ee/images/how-to-get-free-stuff-on-roblox-2021-on-phone.pdfIn PDF document text
    • http://www.vktzunami.cz/images/roblox-com-cheats-for-tix.pdfIn PDF document text
    • https://kimolos-link.gr/images/roblox-free-robux-unlimited-robux-and-tix.pdfIn PDF document text
    • http://agrao.in/images/how-to-hack-hilton-hotel-roblox.pdfIn PDF document text
    • https://amatq.ca/images/how-to-use-no-clip-hacks-roblox-2021-novenmber.pdfIn PDF document text
    • https://technospektr.com.ua/images/roblox-speed-and-jump-hack.pdfIn PDF document text
    • https://www.sitiwebjoomla.it/images/roblox-free-privat-server.pdfIn PDF document text
    • http://learningarabic.co.uk/images/free-robux-accounts-2021.pdfIn PDF document text
    • https://tokunfome.com.br/images/how-to-get-everything-free-in-roblox-2021.pdfIn PDF document text
    • https://www.abrapppe.org.br/images/is-there-a-free-trial-for-roblox-bc.pdfIn PDF document text
    • https://www.cpnf.ch/images/how-to-become-antman-for-free-roblox-sharkblox.pdfIn PDF document text
    • http://www.boic.nl/images/roblox-free-account-generator.pdfIn PDF document text
    • https://www.eglihotel.gr/images/free-3d-modeling-software-for-roblox.pdfIn PDF document text
    • http://www.hawler.in/images/free-parris-island-roblox.pdfIn PDF document text
    • http://www.rezbb.sk/images/robux-hacknetpremium-robux-generator.pdfIn PDF document text
    • http://www.exikom.com.ua/images/roblox-maze-runner-cheats.pdfIn PDF document text
    • https://verdensbarn.no/images/hang-hack-for-roblox.pdfIn PDF document text
    • http://hemmet-strand.dk/images/roblox-dragon-ball-after-future-hack.pdfIn PDF document text
    • https://www.sitiwebjoomla.it/images/hack-for-roblox-create-a-security-base.pdfIn PDF document text
    +2 more URL(s)

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_003_off000059a1.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x59A1 23832 bytes
SHA-256: f7e2e1d5b4fed6f4a4a7561ad6ac0ae3a37e845adb3e9b7cb528997df755752e
font_01_sfnt_off00008fa3.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x8FA3 19520 bytes
SHA-256: 9e06f8f949820909d6a1c284c576ac0c7667a06cc059e3a457459b0699374e19