Malicious PDF — malware analysis report

Static analysis result for SHA-256 2d1d960d4d59c353…

MALICIOUS

PDF

58.0 KB Created: 2021-04-05 21:15:39 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7) First seen: 2021-10-11
MD5: ebb5d73d93376fbd74cc3b3467c5bb64 SHA-1: 39a2cc125a8a887bf743b72edf6d33988f1b64cd SHA-256: 2d1d960d4d59c353e45d7f4b3eb4e78c2a8df6dd4be806f2c41adc79b523d9ae
122 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 User Execution: Malicious Link

The PDF document contains heuristics indicating a browser installation lure and brand-impersonation credential phishing, specifically impersonating Microsoft. The document body and extracted URLs promote free Robux and hacking methods, directing users to external sites like http://gaminggenerator.org/app/431946152/how-to-make-a-cool-roblox-character-free, which is likely a phishing or malware distribution site. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.7795

Heuristics 5

  • Browser extension / update installation lure high SE_BROWSER_INSTALL_LURE
    Document tells the user to install a browser extension, plugin, viewer, or browser update to view content — a common social-engineering path for credential theft and malware installation
  • Brand-impersonation credential phishing lure high SE_BRAND_CREDENTIAL_PHISH
    Document impersonates a well-known consumer brand and uses account-security / verification language ('unusual activity', 'account on hold', 'verify your account') to steer the reader to a credential-harvesting link. Corroborated by: call-to-action link host does not match the impersonated brand: http://gaminggenerator.org/app/431946152/how-to-make-a-cool-roblox-character-free.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://gaminggenerator.org/app/431946152/how-to-make-a-cool-roblox-character-free PDF link annotation
    • http://grupodin.com.br/images/roblox-parkour-cheater-tag.pdfIn PDF document text
    • http://teksomak.com/images/get-free-robux-no-fike.pdfIn PDF document text
    • http://aviaprofsoyuz.info/images/hacks-to-get-money-on-roblox.pdfIn PDF document text
    • https://www.cpnf.ch/images/pastebin-robux-hack-2021.pdfIn PDF document text
    • http://www.ntc.edu.za/images/scp-anomaly-breach-roblox-hack.pdfIn PDF document text
    • http://www.anies.eu/images/how-can-you-earn-robux-for-free.pdfIn PDF document text
    • http://addair.co.uk/images/roblox-hacking-users-no-verifacation.pdfIn PDF document text
    • http://www.visiblefilm.com/images/best-exploit-roblox-free.pdfIn PDF document text
    • http://www.eurologistiki.gr/images/how-to-hack-roblox-plaza.pdfIn PDF document text
    • http://nevesomost.by/images/best-roblox-free-exploit.pdfIn PDF document text
    • https://arcasict.nl/images/how-long-can-you-get-banned-for-hacking-in-roblox.pdfIn PDF document text
    • http://www.pcclawyers.com.au/images/roblox-vehicle-simulator-free-vip-server-link-2021.pdfIn PDF document text
    • http://lakomat.by/images/hacking-method-for-roblox-accounts.pdfIn PDF document text
    • https://hassel-event.de/images/free-robux-card-hack.pdfIn PDF document text
    • https://kimolos-link.gr/images/free-multiplayer-games-like-roblox.pdfIn PDF document text
    • http://safwafurniture.com/images/free-roblox-accounts-v3rm.pdfIn PDF document text
    • https://koeltotaal.com/images/how-to-speed-hack-and-noclip-on-roblox-jailbreak-patched.pdfIn PDF document text
    • http://domaizdereva24.ru/images/roblox-games-that-can-give-you-free-robux.pdfIn PDF document text
    • http://www.arredifunebri.com/images/hacking-ryrylol3-on-roblox.pdfIn PDF document text
    • http://quatangthienthan.com/images/roblox-hacks-forum.pdfIn PDF document text
    • http://feuerwehr-rheinau.de/images/hacks-para-pixel-gun-roblox.pdfIn PDF document text
    • http://www.lycee-langevin-wallon.com/images/www-roblox-cheatus-limited-amount-hurry-and-claim.pdfIn PDF document text
    • http://forsazh-51.ru/images/robux-hack-no-verification-or-survey-2021.pdfIn PDF document text
    • http://salantiskis.lt/images/free-roblox-2021-rich-accounts.pdfIn PDF document text
    • https://www.abrapppe.org.br/images/hacks-roblox-yt.pdfIn PDF document text
    • http://www.fluidtech.hu/images/comment-hack-un-compte-roblox-2021.pdfIn PDF document text
    • http://finettifrs.it/images/how-do-i-get-free-robux-in-roblox.pdfIn PDF document text
    • http://www.les2alpes-location.com/images/roblox-free-download-for-windows-7.pdfIn PDF document text
    • http://pythonbikers.de/images/free-owner-roblox.pdfIn PDF document text
    • https://www.ergolight.at/images/free-russian-clothes-roblox.pdfIn PDF document text
    • https://wandpiraten.de/images/roblox-conquerors-3-hack.pdfIn PDF document text
    • http://alexandrion.com/images/get-free-robux-easy-simple.pdfIn PDF document text
    • http://kancelaria-legnica.eu/images/cheat-roblox-one-piece-millenium.pdfIn PDF document text
    • http://pa-tanjungselor.go.id/images/free-robux-discord-ggroups.pdfIn PDF document text
    • https://verdensbarn.no/images/70-free-robux.pdfIn PDF document text
    • http://www.mjclautrec.fr/images/how-how-to-cheat-on-roblox-pc.pdfIn PDF document text
    • http://www.arredifunebri.com/images/peple-hacking-to-get-robux.pdfIn PDF document text
    • https://pa-waingapu.go.id/images/free-robux-for-android-apk-downloads.pdfIn PDF document text
    • https://springhorn-reisen.de/images/coolkid-roblox-hack-download.pdfIn PDF document text
    • http://www.herbasacra.gr/images/how-to-get-free-radio-in-roblox-jailbreak.pdfIn PDF document text
    • http://fairwaygolftravel.co.uk/images/roblox-how-to-get-free-wings.pdfIn PDF document text
    • http://briankellyforcongress.com/images/free-trades-roblox.pdfIn PDF document text
    • http://www.mjclautrec.fr/images/roblox-robux-hack-no-survey-android.pdfIn PDF document text
    • http://www.awakeningtruth.org/images/hack-para-roblox-apocalypse-rising-2021.pdfIn PDF document text
    • http://santeh-40.ru/images/free-roblox-stuff-2021-promocodes.pdfIn PDF document text
    • http://domaizdereva24.ru/images/roblox-dinosaur-simulator-hack.pdfIn PDF document text
    • http://shiny-nn.ru/images/hack-de-roblox-para-todos-los-juegos.pdfIn PDF document text
    • http://unionmusicaldebenidorm.com/images/how-to-get-free-robux-100-working-secret-method.pdfIn PDF document text
    • https://masseymotorcars.com/images/hacks-for-roblox-mining-simulator.pdfIn PDF document text
    +15 more URL(s)

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_003_off000081c2.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x81C2 27216 bytes
SHA-256: 33b16a1b4e83001e1afffcbe984096d64b6dee38e36161dcfad931d8ab3c9b8b
font_01_sfnt_off0000bf3d.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xBF3D 18348 bytes
SHA-256: f9a47bf3a6000cb5eb565776936d2eec800ac53cc9cc9b9e6520a8203e9f0a00