Malicious PDF — malware analysis report

Static analysis result for SHA-256 88a5bba4804dc8d9…

MALICIOUS

PDF

55.4 KB Created: 2021-04-06 13:59:48 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7) First seen: 2021-09-29
MD5: 254c94d12314477f3f83dee8f71f1e9a SHA-1: 174b2f89f4d4630a1deba7cb0f8bf2a57961863b SHA-256: 88a5bba4804dc8d9d56209cda9e0076af271c52d8f3786305ad797dcfa79ac4e
82 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF document contains multiple links and a call-to-action phrase, all directing the user towards websites promising hacks and free currency for the game Roblox. The primary link, 'https://enigmagenerator.com/app/431946152/roblox-game-hack', is flagged as a lure for game hacks. While no scripts were explicitly extracted, the PDF structure and embedded links suggest a phishing or scam attempt designed to redirect users to potentially malicious sites.

Machine Learning

  • Nyx PDF Classifier malicious score 0.7960

Heuristics 4

  • PDF links to a 'free generator / game hack' redirector high PDF_GAME_HACK_REDIRECT_LURE
    PDF's clickable action targets a redirector of the form /app/<id>/<slug>-game-hack — the landing-page shape of a large SEO 'free spins / generator / game hack' lure family that funnels victims through rotating disposable hosts to a malware/scam payload. The multi-link variants also trip ML/link-farm rules; this catches the single-link variants that otherwise score clean.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://enigmagenerator.com/app/431946152/roblox-game-hack PDF link annotation
    • http://www.campiresine.it/images/how-to-hack-in-mm2-roblox.pdfIn PDF document text
    • https://esl.ipb.ac.id/images/hack-pp-jailbreak-roblox.pdfIn PDF document text
    • http://sostactical.ca/images/how-to-get-free-face-in-roblox.pdfIn PDF document text
    • https://fkg.usu.ac.id/images/free-robux-inspect-element-2021.pdfIn PDF document text
    • https://scraperite.com/images/paint-net-free-download-for-roblox.pdfIn PDF document text
    • http://pa-tanjungselor.go.id/images/roblox-counterstrikes-hack.pdfIn PDF document text
    • https://www.audipec.com.br/images/codes-for-free-robux-2021-that-nowon-use.pdfIn PDF document text
    • https://www.ferienhausdirektkroatien.de/images/javascript-roblox-hack.pdfIn PDF document text
    • http://sbm-nn.ru/images/how-to-get-free-white-shirts-on-roblox-2021.pdfIn PDF document text
    • http://aspiesretreat.org/images/nuke-hack-for-roblox.pdfIn PDF document text
    • http://ericvanpraet.eu/images/free-robux-cards-no-survey.pdfIn PDF document text
    • http://biccairo.com/images/hack-roblox-exploiting.pdfIn PDF document text
    • http://kids-academy.pl/images/roblox-hack-999999-robux-2021.pdfIn PDF document text
    • https://waterpark.by:443/images/how-to-hack-in-lumber-tycoon-2-roblox-any-game.pdfIn PDF document text
    • https://vstarnippers.com/images/is-it-possible-to-get-banned-for-cheating-roblox.pdfIn PDF document text
    • http://sfera-express.ru/images/hack-roblox-for-robux-no-details.pdfIn PDF document text
    • https://sitam.co.in/images/roblox-hack-mad-city-2021.pdfIn PDF document text
    • https://esl.ipb.ac.id/images/get-free-hair-in-roblox.pdfIn PDF document text
    • https://weightlessriding.com/images/how-to-hack-robux-2021.pdfIn PDF document text
    • https://www.mrsz.ir/images/how-to-get-free-robux-no-download-2021.pdfIn PDF document text
    • http://unifieo.br/images/roblox-hack-download-no-survey-2021.pdfIn PDF document text
    • http://bau-lk.de/images/get-roblox-games-for-free.pdfIn PDF document text
    • http://keepcasscountybeautiful.com/images/how-do-u-hack-someones-account-on-roblox.pdfIn PDF document text
    • http://eddieblum.nl/images/free-robux-hack-really-works.pdfIn PDF document text
    • http://hospitalsalamanca.cl/images/the-neighbourhood-roblox-money-hack-pastebin.pdfIn PDF document text
    • https://www.cnte.org.br/images/hacks-for-roblox-how-to-fix-them.pdfIn PDF document text
    • http://pesok-rk.ru/images/roblox-nockip-hack-2021-feb.pdfIn PDF document text
    • https://jdlgroup.ca/images/hack-pour-avoir-plein-de-lgendaire-roblox-bubble-gum.pdfIn PDF document text
    • https://www.dierenartsberghman.be/images/how-to-hack-into-anyones-roblox-account-2021.pdfIn PDF document text
    • https://www.yewtreealpacas.co.uk/images/how-to-get-a-hacker-banned-on-roblox.pdfIn PDF document text
    • http://www.pcclawyers.com.au/images/free-robux-script-pastable.pdfIn PDF document text
    • https://www.abrapppe.org.br/images/free-ways-to-get-robux-on-roblox.pdfIn PDF document text
    • http://schlossschaenke-andernach.de/images/free-nike-clothes-on-roblox.pdfIn PDF document text
    • https://laconce.com/images/how-to-hack-roblox-mad-paintball-2.pdfIn PDF document text
    • https://ballaratcaravans.com.au/images/how-to-get-a-hacked-account-back-on-roblox-2021.pdfIn PDF document text
    • http://www.malonmalon.com.ar/images/free-items-for-google-play-roblox.pdfIn PDF document text
    • http://legitame.org/images/how-to-hack-on-pc-roblox.pdfIn PDF document text
    • http://www.bois-ariegeois.fr/images/unpatched-cheat-engine-roblox.pdfIn PDF document text
    • http://bkd1.balikpapan.go.id/images/free-robux-tool-created-by-redboyrb-h2.pdfIn PDF document text
    • http://www.vktzunami.cz/images/impact-roblox-hack-website.pdfIn PDF document text
    • http://www.campiresine.it/images/lua-script-pour-hack-roblox.pdfIn PDF document text
    • https://domoticaaplicada.com/images/free-unused-roblox-gift-cards.pdfIn PDF document text
    • http://elie-khalil.com/images/roblox-someone-thinks-im-hacking.pdfIn PDF document text
    • https://www.milewood.co.uk/images/free-robux-generator-without-any-verifacations-or-downloads-to-chrome.pdfIn PDF document text
    • http://tegeler-segler.de/images/roblox-arcane-adventures-v4-hack.pdfIn PDF document text
    • https://technospektr.com.ua/images/roblox-cheats-for-laptop.pdfIn PDF document text
    • http://zarinnameh.ir/images/hide-and-seek-extreme-roblox-hack.pdfIn PDF document text
    • http://news123.it/images/how-to-get-free-pet-dog-in-adopt-me-roblox.pdfIn PDF document text
    • https://www.iadh.bi/images/download-for-free-roblox.pdfIn PDF document text
    +15 more URL(s)

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_003_off00007384.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x7384 28252 bytes
SHA-256: f4d997a76aca6f4546c20e957588175830b0de29f2732e50110428f03c749c08
font_01_sfnt_off0000b3e2.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xB3E2 18640 bytes
SHA-256: f5219a2cbe44bd350241c05358beaba774344934befeda6bf4e89bab8dba5080