Malicious PDF — malware analysis report

Static analysis result for SHA-256 73af8dd326356269…

MALICIOUS

PDF

238.2 KB Created: 2021-04-04 12:56:30 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: dc46ad9b101b559405fdf57ba3e87d95 SHA-1: b9d3bac9579b6a62295706f24ddf9076f9d3e775 SHA-256: 73af8dd326356269345e5b63d738d261812d7a5d008559d4ee2b411f5dcc9c12
132 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious File

The PDF file is detected as malicious by ClamAV and uses an image-based lure related to Roblox hacks. It instructs the user to copy and paste content into a command-line interface, indicating an attempt to trick the user into executing malicious commands. The presence of multiple URLs suggests a phishing or malware distribution attempt.

Machine Learning

  • Nyx PDF Classifier clean score 0.2248

Heuristics 6

  • ClamAV: Pdf.Phishing.Roblox062100-9873116-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.Roblox062100-9873116-0
  • Clipboard command execution lure high SE_CLIPBOARD_COMMAND_LURE
    Document tells the user to copy or paste clipboard content into Run, PowerShell, cmd, or another shell-like execution context
  • Image-only document with action trigger (screenshot lure) medium PDF_IMAGE_LURE
    PDF has 1 image(s), only 0 text block(s), carries a click-outward action, and is only 238 KB — typical shape of a phishing lure where a full-page screenshot hides a clickable button that launches or submits to an attacker URL.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://gaminggenerator.org/app/431946152/heist-2-roblox-hack
    • http://businessmart.ro/images/roblox-software-free-download.pdf
    • https://uofk.edu/images/how-can-you-hack-roblox-tattletail.pdf
    • https://www.foodsafety.cz/images/free-online-games-roblox-no-download.pdf
    • http://www.elis-strechy.cz/images/how-to-get-free-hair-on-roblox-no-inspect-element.pdf
    • http://mydevice.com.au/images/ninja-legends-roblox-hacked-pet.pdf
    • https://www.brainpads.com/images/how-to-get-free-robux-no-human-verification-2021-real.pdf
    • http://safari-crimea.com/images/how-to-use-an-illuminati-skybox-hack-on-roblox.pdf
    • https://www.lavigny.ch/images/roblox-chp-free.pdf
    • http://www.htc.edu.au/images/play-roblox-com-free.pdf
    • http://jackson-pr.com/images/free-roblox-level-creating-scripts.pdf
    • http://daksz.hu/images/roblox-pinewood-hack-script.pdf
    • https://www.lomrad.go.th/images/level-hack-roblox.pdf
    • https://gestionpatrimonial.net/images/free-pet-roblox-grow-a-candy-cane.pdf
    • http://www.gravel.ru/images/roblox-apoc-rising-cheat-code.pdf
    • https://reggieslockandkey.com/images/hack-tool-roblox-pokemon.pdf
    • https://www.seeingindependence.org/images/how-to-hack-legend-of-the-bone-sword-roblox.pdf
    • https://www.audev.com/images/robux-hack-for-robux-outrageous-bilders-club.pdf
    • http://salantiskis.lt/images/rocash-roblox-free-robux.pdf
    • http://www.mosaikshop.at/images/free-robux-no-robot-check.pdf
    • http://moralcenter.or.th/images/how-to-get-free-robux-from-joining-a-group.pdf
    • https://esl.ipb.ac.id/images/roblox-upload-audio-for-free.pdf
    • http://loszavera.com/images/roblox-bc-hack.pdf
    • http://www.rezbb.sk/images/uirbx-club-roblox-robux-hack-generator.pdf
    • http://www.lycee-langevin-wallon.com/images/roblox-spongebob-hacker.pdf
    • http://bb-im2.com/images/free-roblox-usernames.pdf
    • http://iricamidelcuore.it/images/did-biggie-get-robux-free.pdf
    • http://museumkk.ru/images/black-magic-roblox-hack.pdf
    • http://fiur-malermeister.de/images/get-free-roblox-by-playi.pdf
    • http://huananhai.net/images/free-robux-no-scam-no-survey-2021.pdf
    • http://ecoleduchat-grenoble.fr/images/free-robux-no-bot-verification.pdf
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00036af5.bin
41e0d0694f32d334ae523f75931739973f00becc36f9cd2989ff1a3c551fe7e1
pdf-font-stream PDF embedded font (sfnt) at offset 0x36AF5 19012 bytes
font_01_sfnt_off000392a6.bin
5a084cf4c06c52544add45b2a56e084617823da412db68f7d428d02587dbd67a
pdf-font-stream PDF embedded font (sfnt) at offset 0x392A6 17936 bytes