Malicious PDF — malware analysis report

Static analysis result for SHA-256 280f50207b4a9135…

MALICIOUS

PDF

33.7 KB Created: 2021-06-19 11:14:50 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7) First seen: 2021-09-27
MD5: 99212e74be0fcefedcbb3910f4ea2025 SHA-1: 7ce612541c0b72f70b2c748587ec5896410e263e SHA-256: 280f50207b4a9135f5cee5fcde3de8bd07adef069fb825bc24a7c9be9e91368e
102 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains numerous embedded URLs and a call-to-action phrase, indicating a phishing or scam attempt. The document body explicitly mentions "Hacking Prestonplayz Roblox Account" and "CLICK HERE TO ACCESS ROBLOX GENERATOR", strongly suggesting a lure for users seeking game cheats or exploits. The ML classifier also flagged this PDF as malicious with high confidence.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9980

Heuristics 4

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://netcdn.co/app/431946152/hacking-prestonplayz-roblox-account-game-hack PDF link annotation
    • http://kermas.eu/images/can-we-hack-in-roblox-2021_GM431946152.pdfIn PDF document text
    • http://kermas.eu/images/how-do-i-get-free-spins-on-coin-master_GM406889139.pdfIn PDF document text
    • http://kermas.eu/images/rbx-sites_GM431946152.pdfIn PDF document text
    • http://kermas.eu/images/is-minecraft-free-on-nintendo-switch_GM479516143.pdfIn PDF document text
    • http://kermas.eu/images/coin-master-hack-android-no-root_GM406889139.pdfIn PDF document text
    • http://kermas.eu/images/free-spins-coin-master_GM406889139.pdfIn PDF document text
    • http://kermas.eu/images/hack-robux-gratis-como-tener-robux-gratis-en-roblox_GM431946152.pdfIn PDF document text
    • http://kermas.eu/images/free-spins-and-coins-for-coin-master-game_GM406889139.pdfIn PDF document text
    • http://kermas.eu/images/pokemon-go-free-pokecoins-hack_GM1094591345.pdfIn PDF document text
    • http://kermas.eu/images/free-transformer-roblox-costumes_GM431946152.pdfIn PDF document text
    • http://kermas.eu/images/free-spins-coin-master-unlimited_GM406889139.pdfIn PDF document text
    • http://kermas.eu/images/byfantics-com-free-robux_GM431946152.pdfIn PDF document text
    • http://kermas.eu/images/roblox-free-robux-give-away-lve_GM431946152.pdfIn PDF document text
    • http://kermas.eu/images/coin-master-mod-version-free-download-ios_GM406889139.pdfIn PDF document text
    • http://kermas.eu/images/daily-free-spins_GM406889139.pdfIn PDF document text
    • http://kermas.eu/images/free-robux-please_GM431946152.pdfIn PDF document text
    • http://kermas.eu/images/free-robux-only-username-no-human-verification_GM431946152.pdfIn PDF document text
    • http://kermas.eu/images/united-gaming-net-coin-master-hack_GM406889139.pdfIn PDF document text
    • http://kermas.eu/images/how-to-get-any-game-pass-for-free-2021-roblox_GM431946152.pdfIn PDF document text
    • http://kermas.eu/images/2021-free-spins-coin-master_GM406889139.pdfIn PDF document text
    • http://en.wikipedia.org/wiki/MIT_LicenseIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00002ca6.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x2CA6 22064 bytes
SHA-256: d16da15701b26839e57755fe42f56d4be763c0797c7f15fa2a9cb1f9898ca992
font_01_sfnt_off00005d5f.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x5D5F 19428 bytes
SHA-256: e7bebc7d2a2ce87a076f008b3a0d1bf70b0d9e6b328a127be6ebab6f8999b599