Malicious PDF — malware analysis report

Static analysis result for SHA-256 5756ef549f109c76…

MALICIOUS

PDF

59.5 KB Created: 2021-04-06 00:21:04 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7) First seen: 2021-10-02
MD5: b9c1bf47cd69b61e04cae9c7954af373 SHA-1: 13c95859b2ab142e79dbeeea8a3880121aaa4fc7 SHA-256: 5756ef549f109c761e06faa41aeda518b16e2afdc4a225a3baa4ea362be868eb
82 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

This PDF document was flagged as malicious by an ML classifier. It uses a password-protected-archive lure. The file presents a deceptive download button. Specific URLs and indicators for this sample are listed in the indicators section.

Machine Learning

  • Nyx PDF Classifier malicious score 0.6193

Heuristics 4

  • Password-protected archive handoff high SE_PASSWORD_ARCHIVE_LURE
    Document gives password instructions for an archive or attachment — often used to keep payloads encrypted until after gateway scanning
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://gaminggenerator.org/app/431946152/how-to-get-free-roblox-hats-2021 PDF link annotation
    • http://www.tamogatoweb.hu/images/free-valid-roblox-promocodes.pdfIn PDF document text
    • http://www.gravel.ru/images/fashion-frenzy-game-roblox-free.pdfIn PDF document text
    • http://www.exikom.com.ua/images/cloudbux-net-roblox-hack.pdfIn PDF document text
    • http://linde-erbach.de/images/how-to-hack-dayz-roblox.pdfIn PDF document text
    • http://loszavera.com/images/como-hacker-roblox.pdfIn PDF document text
    • http://learningarabic.co.uk/images/hack-for-roblox-project-pokemon.pdfIn PDF document text
    • https://www.millatgears.com/images/roblox-password-guessing-hack.pdfIn PDF document text
    • http://www.occquimica.com.br/images/shirt-for-roblox-free.pdfIn PDF document text
    • http://dottgagliardi.com/images/free-robux-games-without-password.pdfIn PDF document text
    • http://www.eptaviation.com/images/free-roblox-accounts-with-robux-that-work-not-banned.pdfIn PDF document text
    • http://s-punkt-objects.de/images/free-online-roblox-no-sign-up.pdfIn PDF document text
    • http://towtrucklosangeles.com/images/how-to-get-free-robux-2021-ad.pdfIn PDF document text
    • https://sitam.co.in/images/free-cool-roblox-accounts.pdfIn PDF document text
    • https://schaefer-rechtsanwaelte.com/images/roblox-today-free-robux.pdfIn PDF document text
    • https://studentcareerinfo.com/images/roblox-hack-somones-robux.pdfIn PDF document text
    • http://iluvlocalplaces.com/images/is-there-any-free-ways-of-getting-robux.pdfIn PDF document text
    • http://mycounty.com.ua/images/script-for-free-robux.pdfIn PDF document text
    • http://www.torvet11.dk/images/hack-into-any-roblox-account.pdfIn PDF document text
    • http://medicalafrica.net/images/how-to-fly-in-roblox-with-cheat-engine.pdfIn PDF document text
    • https://www.iadh.bi/images/get-free-robux-no-download-no-waiting.pdfIn PDF document text
    • http://panaceafamilymedicine.com/images/free-robux-zephplayz.pdfIn PDF document text
    • https://www.air-shop.cz/images/roblox-free-robux-server.pdfIn PDF document text
    • http://pacatuamigo.com/images/free-roblox-accounts-that-work-2021.pdfIn PDF document text
    • http://www.thecoffeebaron.co.za/images/roblox-hack-and-cheats-for-exploit-free-download.pdfIn PDF document text
    • http://e-onlinearchiv.de/images/cheat-speed-roblox.pdfIn PDF document text
    • http://hotel-buta.by/images/best-roblox-hack-download.pdfIn PDF document text
    • http://cleanteclogistics.com/images/roblox-murderer-mystery-2-candy-hack.pdfIn PDF document text
    • http://www.hotel-seminaire.com/images/game-api-free-robux.pdfIn PDF document text
    • http://xn----7sbabhw4a8b0addm1c.xn--p1ai/images/roblox-free-item-generator.pdfIn PDF document text
    • http://www.htc.edu.au/images/roblox-hack-kick-script.pdfIn PDF document text
    • http://www.fanciullovito.it/images/como-tener-robux-gratis-sin-hacks-facil-y-rapido.pdfIn PDF document text
    • https://www.utalii.ac.ke/images/roblox-ninja-legends-hack.pdfIn PDF document text
    • http://prodajalec.si/images/free-shoulder-accessories-roblox.pdfIn PDF document text
    • https://almaville.org.kz/images/roblox-vehicle-simulator-speed-hack-2021.pdfIn PDF document text
    • http://www.hawler.in/images/free4mobile24-com-free-robux.pdfIn PDF document text
    • http://principessalialaofegypt.com/images/adoptme-club-free-robux.pdfIn PDF document text
    • https://www.europap.cz/images/roblox-free-exploit-that-support-fireclickdetector.pdfIn PDF document text
    • http://ff-obertraun.at/images/hack-ed-roblox.pdfIn PDF document text
    • https://www.cosmosdawn.net/images/1-000-subscriber-roblox-hack-tool.pdfIn PDF document text
    • http://agroturismoarkaia.com/images/roblox-play-roblox-for-free.pdfIn PDF document text
    • http://abqwinair.com/images/cheat-engine-wallhack-roblox.pdfIn PDF document text
    • http://www.brtes.com/images/roblox-hack-the-free-generator-robuxgaminghacking.pdfIn PDF document text
    • https://gaj.rs/images/how-to-make-a-free-shirt-in-roblox-no-bc.pdfIn PDF document text
    • https://www.cnte.org.br/images/earn-robux-free-2021.pdfIn PDF document text
    • https://sectorpravdy.com/images/wiki-free-robux.pdfIn PDF document text
    • https://www.hbproducts.dk/images/free-roblox-accounts-and-passwords-in-roblox-shown-on-wikia.pdfIn PDF document text
    • https://www.lavigny.ch/images/roblox-hack-scropts.pdfIn PDF document text
    • http://santjoandelesabadesses.cat/images/roblox-animation-pack-free.pdfIn PDF document text
    • http://britishcomics.com/images/how-to-get-free-clothes-on-roblox-hack.pdfIn PDF document text
    +17 more URL(s)

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_003_off00007e5b.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x7E5B 27036 bytes
SHA-256: fd543daec19056679fda381fb23f3e76609beac2bbbd2ab8bd4d8c38aabea115
font_01_sfnt_off0000bb20.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xBB20 2848 bytes
SHA-256: 4737c2778a085e0cb49e73f3b054b1a71e3f40720d213b4bfda97f95a31bfbf1
font_02_sfnt_off0000c4e1.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xC4E1 18268 bytes
SHA-256: f47ed60a461902914813098c05388edde43119fa715c96961da287fe2a7a8c89