Malicious PDF — malware analysis report

Static analysis result for SHA-256 31e5d9ee0f94ea14…

MALICIOUS

PDF

55.4 KB Created: 2021-04-06 22:08:56 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7) First seen: 2021-09-29
MD5: fb8975f7822292fe5ed6e4b8f141c385 SHA-1: 0fa560a1c5029eebaaca8b0000816bed408a15c3 SHA-256: 31e5d9ee0f94ea144f6579435cfc5359906eb6a5c58baa7b130d83d570e8d6f8
82 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF document contains a lure related to 'free Robux' and game hacks, directing users to external URLs. The presence of embedded URLs and the 'ML_NYX_PDF_MALICIOUS' heuristic strongly suggest malicious intent. While no scripts were explicitly extracted, the PDF structure and embedded links indicate a phishing or redirection attempt to a site likely hosting further malicious content or exploits.

Machine Learning

  • Nyx PDF Classifier malicious score 0.6397

Heuristics 4

  • PDF links to a 'free generator / game hack' redirector high PDF_GAME_HACK_REDIRECT_LURE
    PDF's clickable action targets a redirector of the form /app/<id>/<slug>-game-hack — the landing-page shape of a large SEO 'free spins / generator / game hack' lure family that funnels victims through rotating disposable hosts to a malware/scam payload. The multi-link variants also trip ML/link-farm rules; this catches the single-link variants that otherwise score clean.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://enigmagenerator.com/app/431946152/roblox-game-hack PDF link annotation
    • https://luminouswisdom.org/images/how-to-hack-peoples-roblox-accounts-2021.pdfIn PDF document text
    • http://legs11.co.za/images/free-robux-online-2021.pdfIn PDF document text
    • http://ivanflores.cl/images/create-your-own-roblox-shirt-for-free.pdfIn PDF document text
    • http://www.centromedicoaurora.it/images/roblox-hacks-with-windows-8.pdfIn PDF document text
    • http://santjoandelesabadesses.cat/images/roblox-closes-as-soon-as-i-open-cheat-engine.pdfIn PDF document text
    • http://roberto-gac.org/images/how-to-record-roblox-for-free.pdfIn PDF document text
    • http://j-cook.pro/images/free-nike-shirts-and-with-alpha-4-roblox.pdfIn PDF document text
    • http://nikabio.com/images/free-stuff-for-roblox-avatar.pdfIn PDF document text
    • http://only1you.ru/images/get-free-roblox-robux-generator.pdfIn PDF document text
    • https://www.stkdb.cz/images/free-roblox-clothes-and-hair-boy.pdfIn PDF document text
    • https://jdlgroup.ca/images/how-to-get-free-robux-n-roblox.pdfIn PDF document text
    • http://uctovnictvosnv.sk/images/free-roblox-bubble-gum-simulator-accounts.pdfIn PDF document text
    • http://fmbompastor.com.br/images/how-to-get-2021-robux-free-2021.pdfIn PDF document text
    • http://www.drent.se/images/hack-de-roblox-mad-city.pdfIn PDF document text
    • http://eventgo.fr/images/free-robux-generator-meme.pdfIn PDF document text
    • http://mycounty.com.ua/images/free-ears-roblox-hat.pdfIn PDF document text
    • http://ericvanpraet.eu/images/easy-hack-online-roblox.pdfIn PDF document text
    • http://safari-crimea.com/images/survivor-hacks-script-roblox.pdfIn PDF document text
    • https://servotecnica.com/images/how-to-get-your-hacked-account-back-on-roblox-2021.pdfIn PDF document text
    • https://koeltotaal.com/images/flippy-hacking-people-roblox.pdfIn PDF document text
    • http://bb-im2.com/images/free-robux-generaters.pdfIn PDF document text
    • http://boliviagasenergia.com/images/free-girl-account-roblox.pdfIn PDF document text
    • https://enpav.it/images/roblox-builders-club-hack-free-download.pdfIn PDF document text
    • http://farwesterndistrict.org/images/comment-ont-fais-pour-avoir-un-cheat-sur-roblox.pdfIn PDF document text
    • http://uctaren.eu/images/how-to-get-the-free-popkon-hat-in-roblox.pdfIn PDF document text
    • http://peche-madagascar.com/images/how-to-hack-roblox-games-no-download.pdfIn PDF document text
    • https://www.hotschool.com.au/images/cheat-robux-roblox-2021-free.pdfIn PDF document text
    • https://servotecnica.com/images/roblox-copyright-free-music.pdfIn PDF document text
    • http://beagles-of-harmony.de/images/how-to-hack-robux-using-inspect-element-2021.pdfIn PDF document text
    • https://proviant.kz/images/hack-client-for-counter-blox-roblox-offensive.pdfIn PDF document text
    • https://reggieslockandkey.com/images/robux-generator-no-survey-no-hack.pdfIn PDF document text
    • https://www.hotschool.com.au/images/hack-for-hoops-beta-roblox.pdfIn PDF document text
    • http://shiny-nn.ru/images/roblox-free-level-7-exploit.pdfIn PDF document text
    • http://gc-sistemas.com.ar/images/roblox-membership-free.pdfIn PDF document text
    • https://www.ergolight.at/images/how-to-get-free-robux-youtube-2021.pdfIn PDF document text
    • https://www.beaufortcollege.ie/images/free-robux-admin-codes-2021.pdfIn PDF document text
    • http://santeh-40.ru/images/roblox-cat-hacked.pdfIn PDF document text
    • http://jugendfeuerwehr-scheinfeld.de/images/how-to-hack-the-roblox-buy-button-with-inspect.pdfIn PDF document text
    • http://butkimloai.com/images/chat-hack-roblox-pastebin.pdfIn PDF document text
    • http://iluvlocalplaces.com/images/roblox-make-shirt-free.pdfIn PDF document text
    • http://the-specials.ch/images/roblox-free-robux-codes-2021-no-human-verification.pdfIn PDF document text
    • http://briankellyforcongress.com/images/roblox-top3k-free-model.pdfIn PDF document text
    • http://lanoblaie.fr/images/roblox-how-to-get-rubux-hack-free.pdfIn PDF document text
    • http://sudamericarural.org/images/free-roblox-cloths-reddit.pdfIn PDF document text
    • https://imagineclimb.com/images/800-robux-free-pub.pdfIn PDF document text
    • http://www.zdravazena.sk/images/how-to-hack-roblox-money-2021.pdfIn PDF document text
    • http://agrupamentoescolas-alfredo-da-silva.com/images/roblox-song-code-for-cheat-codes.pdfIn PDF document text
    • https://cintasoeste.com.ar/images/fun-games-to-hack-on-roblox.pdfIn PDF document text
    • http://ordineavvocatitempio.it/images/30-robux-free.pdfIn PDF document text
    +17 more URL(s)

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00006f62.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x6F62 26852 bytes
SHA-256: 8e65072cb5c35bd13f0004fedae80db2b789cbad1cd6711ea6167b8a66293845
font_01_sfnt_off0000abb9.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xABB9 2832 bytes
SHA-256: 77ae1c4cffa647a8fd533dfa4102e94364989f9e80b9cd131876e9d1005899a2
font_02_sfnt_off0000b56a.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xB56A 17924 bytes
SHA-256: a9df1a35d068d7eee71c314044d00a6ef29ca43d53c8c463a662e0508eefb84b