Malicious PDF — malware analysis report

Static analysis result for SHA-256 2a2734621c4cd77a…

MALICIOUS

PDF

60.2 KB Created: 2021-04-05 23:13:22 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7) First seen: 2021-10-23
MD5: 820b8aa4132e5adce962463a27c7a74e SHA-1: 0f1930e17f131f175029f611a27150ab3bde9401 SHA-256: 2a2734621c4cd77a350f2c06e1d7f10ca3d0946cc3cf9c70c612e7aa4b41996c
82 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains a clear lure for "Free Robux" and impersonates a brand (Facebook) to encourage clicks on malicious links. The primary link, http://gaminggenerator.org/app/431946152/free-robux-no-human-verification-no-hack, is associated with credential phishing or malware distribution. While no scripts were explicitly extracted, the presence of embedded URLs and the ML classifier's high confidence suggest malicious intent.

Machine Learning

  • Nyx PDF Classifier malicious score 0.6193

Heuristics 4

  • Brand-impersonation credential phishing lure high SE_BRAND_CREDENTIAL_PHISH
    Document impersonates a well-known consumer brand and uses account-security / verification language ('unusual activity', 'account on hold', 'verify your account') to steer the reader to a credential-harvesting link. Corroborated by: call-to-action link host does not match the impersonated brand: http://gaminggenerator.org/app/431946152/free-robux-no-human-verification-no-hack.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://gaminggenerator.org/app/431946152/free-robux-no-human-verification-no-hack PDF link annotation
    • http://lv-siegen.de/images/robux-hack-generator-2021.pdfIn PDF document text
    • http://vagency.us/images/roblox-how-to-get-non-free-models.pdfIn PDF document text
    • https://www.eglihotel.gr/images/get-free-robux-no-apps.pdfIn PDF document text
    • https://www.albisser.ch/images/easy-robux-today-for-free.pdfIn PDF document text
    • https://corbo.ru/images/change-stat-roblox-cheat-engine.pdfIn PDF document text
    • http://almacargo.com/images/free-clothes-on-roblox-image.pdfIn PDF document text
    • http://businessmart.ro/images/free-robux-real-with-proof.pdfIn PDF document text
    • http://iluvlocalplaces.com/images/how-to-get-free-robux-without-generator.pdfIn PDF document text
    • http://www.bbnest.it/images/v3rmillion-roblox-hack.pdfIn PDF document text
    • https://www.manisoft.ir/images/how-to-try-roblox-accessoryes-for-free.pdfIn PDF document text
    • http://www.hawler.in/images/dayz-2-hack-roblox.pdfIn PDF document text
    • http://jasperfirstumc.com/images/hack-in-jailbreak-roblox-2021.pdfIn PDF document text
    • http://ordineingsa.it/images/free-download-robloxcom.pdfIn PDF document text
    • https://belixconstructions.com.au/images/free-roblox-exploit-list.pdfIn PDF document text
    • http://legs11.co.za/images/roblox-giant-survival-2-hack.pdfIn PDF document text
    • https://abqyorkrite.org/images/gear-in-roblox-free.pdfIn PDF document text
    • http://wireprod.net/images/roblox-hack-piratebay-what-it-does.pdfIn PDF document text
    • https://www.ncscolour.no/images/how-to-get-free-robux-2021-working-august-2021.pdfIn PDF document text
    • http://cmfd.nl/images/code-how-to-get-50-free-crystals-roblox-miners-haven.pdfIn PDF document text
    • http://modenese.net/images/dino-sim-roblox-apk-to-albino-terror-for-free.pdfIn PDF document text
    • https://socialvalue.gr/images/how-to-hack-roblox-project-pokemon.pdfIn PDF document text
    • http://smart-pro.co.uk/images/roblox-free-no-download-online.pdfIn PDF document text
    • http://www.actae.gr/images/buy-old-accounts-for-roblox-for-free.pdfIn PDF document text
    • http://wsit.at/images/roblox-pokemon-bronze-brick-cheats.pdfIn PDF document text
    • https://www.lomrad.go.th/images/como-hackear-roblox-2021.pdfIn PDF document text
    • http://massimocarpegna.com/images/cheat-engine-la-roblox-para-hilesi-nasil-yapilir.pdfIn PDF document text
    • http://uctovnictvosnv.sk/images/free-roblox-gift-codes-2021.pdfIn PDF document text
    • http://kruiz21.ru/images/free-roblox-code-giveaway.pdfIn PDF document text
    • http://palogar.es/images/roblox-hacked-place-database.pdfIn PDF document text
    • http://stomatolog-choszczno.pl/images/edm-reaper-how-to-get-free-robux.pdfIn PDF document text
    • http://genialica.com/images/robux-maker-free.pdfIn PDF document text
    • http://linde-erbach.de/images/best-roblox-hack-2021.pdfIn PDF document text
    • http://www.rezbb.sk/images/how-tzo-hack-robux-links.pdfIn PDF document text
    • http://instrumenttut.by/images/free-roblox-gift-card-codes-2021-live.pdfIn PDF document text
    • https://www.eglihotel.gr/images/roblox-hacks-discusion.pdfIn PDF document text
    • http://caraless.com/images/roblox-how-to-be-a-nerd-no-robux-no-hacks.pdfIn PDF document text
    • http://lichtdrukkerijwijchen.nl/images/a-roblox-hacks.pdfIn PDF document text
    • http://www.lionel-seppoloni.fr/images/install-roblox-free-latest-version.pdfIn PDF document text
    • http://ofiserco.es/images/free-robux-in-speech-bubble.pdfIn PDF document text
    • http://aeroclub-kaernten.at/images/roblox-gamecards-redeem-2021-free.pdfIn PDF document text
    • http://brandyourbody.com/images/aplicaciones-para-hackear-juegos-roblox.pdfIn PDF document text
    • http://magnipsor.su/images/hack-roblox-payant.pdfIn PDF document text
    • http://hondenspecialist-engelien.nl/images/roblox-hack-pastebin-2021.pdfIn PDF document text
    • http://poltekkeskhjogja.ac.id/images/roblox-how-to-speed-hack-2021.pdfIn PDF document text
    • http://joshherman.com/images/2021-robux-hack-inspect-element.pdfIn PDF document text
    • https://www.hotschool.com.au/images/cheats-for-tower-battles-roblox.pdfIn PDF document text
    • https://open-coffee-drimmelen-geertruidenberg.nl/images/free-robux-simple-easy.pdfIn PDF document text
    • https://gabrieliassociati.com/images/hacker-roblox-bobsponga.pdfIn PDF document text
    • http://zibai.eu/images/strucid-roblox-hacks.pdfIn PDF document text
    +12 more URL(s)

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_003_off0000805f.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x805F 26024 bytes
SHA-256: b32fde56048f9a6b73fc8a8b653e7682cf8d5e8a554eb5b9d96f7b01208fd347
font_01_sfnt_off0000bcc1.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xBCC1 2848 bytes
SHA-256: 4737c2778a085e0cb49e73f3b054b1a71e3f40720d213b4bfda97f95a31bfbf1
font_02_sfnt_off0000c682.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xC682 18724 bytes
SHA-256: 935d62867881b0d1a7d5d5567699df38602ec7cfc987cb0c630eff68f378cd2f