Malicious PDF — malware analysis report

Static analysis result for SHA-256 6dc4cf4528d7c8c0…

MALICIOUS

PDF

58.2 KB Created: 2021-04-05 23:26:15 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7) First seen: 2026-06-04
MD5: 1a8a54fd5d9648553e0f0e4833ff18b2 SHA-1: 84715ab55c621cd8bfc34146140a5038e6a87b58 SHA-256: 6dc4cf4528d7c8c08589e9ad34f5a74965a7c6daa62b065fcb921d5e4cc5ef8e
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains heuristics indicating an urgency lure and a visual download button, suggesting a phishing or scam attempt. The embedded URL points to a site related to hacking Roblox, which is likely a lure to a malicious domain. No scripts were extracted from this sample, limiting further analysis of its behavior.

Machine Learning

  • Nyx PDF Classifier malicious score 0.7795

Heuristics 5

  • Brand-impersonation credential phishing lure high SE_BRAND_CREDENTIAL_PHISH
    Document impersonates a well-known consumer brand and uses account-security / verification language ('unusual activity', 'account on hold', 'verify your account') to steer the reader to a credential-harvesting link. Corroborated by: call-to-action link host does not match the impersonated brand: http://gaminggenerator.org/app/431946152/how-do-you-hack-someone-on-roblox.
  • Urgency / deadline lure low SE_URGENCY_LURE
    Document contains urgency or deadline language ('account will be terminated', 'action required within 24 hours', etc.) — useful context, but low-signal without other findings
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://gaminggenerator.org/app/431946152/how-do-you-hack-someone-on-roblox PDF link annotation
    • https://www.sitiwebjoomla.it/images/free-robux-hack-on-pc-2021.pdfIn PDF document text
    • http://www.flotom.at/images/roblox-potara-dragon-ball-rage-hack.pdfIn PDF document text
    • http://salantiskis.lt/images/how-to-hack-legends-of-speed-in-roblox.pdfIn PDF document text
    • http://safeandsecurelocksmith.ca/images/roblox-hack-free-robux-on-ipad.pdfIn PDF document text
    • http://halitbayramoglu.com.tr/images/roblox-paypal-hack.pdfIn PDF document text
    • https://sectorpravdy.com/images/apk-free-download-roblox.pdfIn PDF document text
    • http://ce-tsv-nantes.fr/images/tp-hack-roblox-execute-command.pdfIn PDF document text
    • http://santjoandelesabadesses.cat/images/how-to-make-hats-free-roblox.pdfIn PDF document text
    • http://evro-okna.net/images/the-bird-says-roblox-free.pdfIn PDF document text
    • https://kimolos-link.gr/images/how-to-get-free-robux-no-verification.pdfIn PDF document text
    • http://maslabaou.com/images/clothes-that-are-free-on-roblox.pdfIn PDF document text
    • https://www.hofe-gmbh.de/images/lua-cheat-engine-roblox.pdfIn PDF document text
    • http://www.bripi.pl/images/free-tix-and-robux-website.pdfIn PDF document text
    • http://www.bernardisrl.eu/images/roblox-uploader-for-free.pdfIn PDF document text
    • http://hk-kan.org/images/how-to-get-free-rolls-on-roblox-elemental-wars.pdfIn PDF document text
    • https://eurekaaccounting.co.za/images/counter-blox-roblox-offensive-hack-money.pdfIn PDF document text
    • http://echosvoix.ch/images/how-to-do-a-roblox-hack.pdfIn PDF document text
    • http://jackson-pr.com/images/roblox-generator-download-free.pdfIn PDF document text
    • https://zsdunajskaluzna.sk/images/roblox-comment-metre-un-script-cheat.pdfIn PDF document text
    • https://www.gymun.cz/images/free-minecraft-items-in-roblox.pdfIn PDF document text
    • http://baah.ca/images/all-packages-in-roblox-free.pdfIn PDF document text
    • http://grand-ural74.ru/images/roblox-theme-park-tycoon-2-cheat-codes.pdfIn PDF document text
    • http://www.gongoff.com/images/roblox-infinite-health-hack.pdfIn PDF document text
    • http://cosver.eu/images/hacks-for-legends-of-speed-roblox.pdfIn PDF document text
    • http://www.mjclautrec.fr/images/how-to-hack-step-by-step-password-pictures-roblox.pdfIn PDF document text
    • http://lichtdrukkerijwijchen.nl/images/free-robux-now-2021.pdfIn PDF document text
    • http://mostowicz.pl/images/roblox-case-clciker-hack.pdfIn PDF document text
    • http://k2visual.com.br/images/roblox-free-wiki-item.pdfIn PDF document text
    • http://www.fluidtech.hu/images/roblox-studio-hack-message.pdfIn PDF document text
    • http://bagna.pl/images/roblox-cheat-engine-august.pdfIn PDF document text
    • https://verdensbarn.no/images/free-roblox-chrome-add-on.pdfIn PDF document text
    • http://sexythings.gr/images/roblox-hacks-and-cheats.pdfIn PDF document text
    • https://www.foodsafety.cz/images/cheat-engine-fly-hack-roblox.pdfIn PDF document text
    • https://www.ghknights.org/images/hackaron-roblox-hack-download.pdfIn PDF document text
    • http://lakomat.by/images/free-roblox-clothes-promo-codes.pdfIn PDF document text
    • http://agroturismoarkaia.com/images/prison-life-vending-machine-gives-free-robux-roblox.pdfIn PDF document text
    • http://bilhetim.com.br/images/free-account-roblox-2021-obc.pdfIn PDF document text
    • http://iluvlocalplaces.com/images/how-to-get-free-robux-by-joining-groups.pdfIn PDF document text
    • http://www.arredifunebri.com/images/how-to-cheat-on-roblox-murder.pdfIn PDF document text
    • https://consorziocsa-asicaivano.it/images/roblox-black-pants-white-shoes-free.pdfIn PDF document text
    • http://pgk-polaniec.pl/images/roblox-apocalypse-rising-hack-2021.pdfIn PDF document text
    • https://www.cnte.org.br/images/how-do-you-get-free-roblox-gift-card-codes.pdfIn PDF document text
    • https://masseymotorcars.com/images/how-to-hack-roblox-account-2021-zero.pdfIn PDF document text
    • https://gestionpatrimonial.net/images/get-any-roblox-item-for-free-new-2021-working-legit.pdfIn PDF document text
    • https://www.sauvonsleclimat.org/images/roblox-hack-scripts-fe.pdfIn PDF document text
    • http://svp-steinmaur.ch/images/all-the-hacking-games-on-roblox.pdfIn PDF document text
    • https://pagadder.com/images/roblox-money-cheat-jailbreak.pdfIn PDF document text
    • http://xn----7sbq6amdnuk.xn--p1ai/images/new-free-roblox-items.pdfIn PDF document text
    • https://reggieslockandkey.com/images/free-obfuscator-2021-roblox.pdfIn PDF document text
    +12 more URL(s)

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_003_off0000830e.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x830E 26596 bytes
SHA-256: c76e6fdbaa8518ba1a320214288842b5b03276dbc6f8d7e91becbd1706f114ac
font_01_sfnt_off0000bf91.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xBF91 18452 bytes
SHA-256: 664b8e4f586c6d9372b7dd1f2eb374c0bd2b6543b6d362a0a8718d9d6761877d