Malicious PDF — malware analysis report

Static analysis result for SHA-256 5c413bbc544a1d7b…

MALICIOUS

PDF

59.3 KB Created: 2021-04-05 19:49:27 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7) First seen: 2021-09-22
MD5: f7b87e70ec265378df0ee859b6191662 SHA-1: e7842d26020fa7ae36e8835187420cce48a93f06 SHA-256: 5c413bbc544a1d7b9f97252500bd572595e485ba95d7e107ff2e197929ba0d1e
122 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious File

The document uses a social engineering lure related to 'Free Robux' and impersonates Amazon to trick users into downloading a malicious PDF. The embedded URL and numerous other similar URLs suggest a campaign distributing malware disguised as game-related cheats or generators. While no scripts were explicitly extracted, the PDF structure and ML classifier indicate malicious intent, likely involving exploitation or further payload delivery.

Machine Learning

  • Nyx PDF Classifier malicious score 0.7795

Heuristics 5

  • Browser extension / update installation lure high SE_BROWSER_INSTALL_LURE
    Document tells the user to install a browser extension, plugin, viewer, or browser update to view content — a common social-engineering path for credential theft and malware installation
  • Brand-impersonation credential phishing lure high SE_BRAND_CREDENTIAL_PHISH
    Document impersonates a well-known consumer brand and uses account-security / verification language ('unusual activity', 'account on hold', 'verify your account') to steer the reader to a credential-harvesting link. Corroborated by: call-to-action link host does not match the impersonated brand: http://gaminggenerator.org/app/431946152/free-robux-no-verification-or-offer.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://gaminggenerator.org/app/431946152/free-robux-no-verification-or-offer PDF link annotation
    • http://schlossschaenke-andernach.de/images/cerberus-hack-roblox.pdfIn PDF document text
    • http://ecoleduchat-grenoble.fr/images/free-robux-generator-no-servey.pdfIn PDF document text
    • http://www.hawler.in/images/free-rs999-999-999-on-roblox.pdfIn PDF document text
    • http://imp.lg.ua/images/roblox-mod-apk-unlimited-robux-2021-download-free.pdfIn PDF document text
    • http://www.mediaxin.net/images/how-to-get-free-robux-july-2021.pdfIn PDF document text
    • http://tc-kulmbach.de/images/cheats-infinte-jump-roblox-fe2.pdfIn PDF document text
    • http://legs11.co.za/images/free-robux-hack-us.pdfIn PDF document text
    • http://bwharrisalumniusa.org/images/league-of-roblox-hack.pdfIn PDF document text
    • http://linde-erbach.de/images/roblox-exploit-download-2021-free.pdfIn PDF document text
    • http://www.inservis.cl/images/robux-hack-download-ios.pdfIn PDF document text
    • http://www.drent.se/images/free-robux-generator-tool-paste.pdfIn PDF document text
    • http://safwafurniture.com/images/roblox-murder-mystery-2-candies-hack.pdfIn PDF document text
    • http://learningarabic.co.uk/images/shoulderless-shirt-in-roblox-free.pdfIn PDF document text
    • http://www.lionel-seppoloni.fr/images/bleu-roblox-exploit-download-free.pdfIn PDF document text
    • http://bibliodetki.ru/images/roblox-games-that-have-free-boomboxes.pdfIn PDF document text
    • http://ernstgloves.co.il/images/free4mobile24-com-free-robux.pdfIn PDF document text
    • http://www.mikramarine.gr/images/roblox-group-admin-hack.pdfIn PDF document text
    • http://genialica.de/images/roblox-player-download-2021-free.pdfIn PDF document text
    • http://stomatolog-choszczno.pl/images/how-to-hack-fly-on-skyward-roblox.pdfIn PDF document text
    • http://ecoleduchat-grenoble.fr/images/roblox-cheat-engine-mac-download.pdfIn PDF document text
    • http://www.lionel-seppoloni.fr/images/roblox-how-to-hack-into-gallant-gaming-account.pdfIn PDF document text
    • https://www.fhccu.com/images/free-roblox-account-cookies.pdfIn PDF document text
    • http://demenagementlandry.com/images/protosmasher-free-download-roblox.pdfIn PDF document text
    • http://serviio.org/images/free-robux-in-robolx.pdfIn PDF document text
    • https://gestionpatrimonial.net/images/free-roblox-accounts-robuxian.pdfIn PDF document text
    • http://the-specials.ch/images/free-gameplay-to-use-shooting-star-roblox.pdfIn PDF document text
    • https://ballaratcaravans.com.au/images/roblox-get-free-robux-card-codes.pdfIn PDF document text
    • http://rumler.pl/images/free-owner-admin-roblox.pdfIn PDF document text
    • http://www.fanciullovito.it/images/hacks-for-roblox-ro-boxing.pdfIn PDF document text
    • https://www.najeebqasmi.com/images/free-roblox-executor-good-api.pdfIn PDF document text
    • https://www.lavigny.ch/images/breezex-adventures-hacks-roblox.pdfIn PDF document text
    • http://wokbaarlo.nl/images/how-do-you-get-free-robux-easy-2021.pdfIn PDF document text
    • http://huananhai.net/images/free-robux-hack-2021-lenovo.pdfIn PDF document text
    • https://gigbagwinkel.nl/images/counter-blox-roblox-offensive-free-skins.pdfIn PDF document text
    • http://legs11.co.za/images/roblox-kill-script-hack.pdfIn PDF document text
    • http://dos.most.gov.la/images/auto-clicker-mac-free-roblox.pdfIn PDF document text
    • http://famoirs.co.uk/images/how-to-speed-hack-on-roblox-without-cheat-engine-2021.pdfIn PDF document text
    • https://jsgwertherborgholzhausen.de/images/how-to-hack-robux-with-cheat-engine-64-2021.pdfIn PDF document text
    • http://fratellimazzoleni.it/images/roblox-one-piece-golden-age-cheat-engine.pdfIn PDF document text
    • https://www.sauvonsleclimat.org/images/free-robux-generator-no-verification-or-survey.pdfIn PDF document text
    • http://asiashop-france.fr/images/cheat-roblox-kick-players.pdfIn PDF document text
    • http://dermaceutic.co.uk/images/is-it-possible-to-hack-robux.pdfIn PDF document text
    • https://kunstmalen.ch/images/hack-robux-2021-android.pdfIn PDF document text
    • http://safwafurniture.com/images/how-to-get-400-robux-on-roblox-for-free-2021.pdfIn PDF document text
    • http://iluvlocalplaces.com/images/roblox-strucid-battle-royale-aimbot-hack-full-lua.pdfIn PDF document text
    • http://www.inservis.cl/images/roblox-robux-generator-v1-0-free-download.pdfIn PDF document text
    • http://smart-pro.co.uk/images/roblox-apocalypse-rising-spawn-hack.pdfIn PDF document text
    • http://lakeshistory.com/images/hack-knife-roblox.pdfIn PDF document text
    • http://www.campiresine.it/images/free-robux-urban.pdfIn PDF document text
    +17 more URL(s)

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_003_off000085d6.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x85D6 27684 bytes
SHA-256: 3c591cd086eb70909c10892731d6abecff6a13df3ff15d5d3a6e442c8be856ba
font_01_sfnt_off0000c47c.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xC47C 18292 bytes
SHA-256: 4be2acf3b89502f7babf90116784591cd3c7d985d408e7d822b3c7de0a2b1ee9