Malicious PDF — malware analysis report

Static analysis result for SHA-256 897af9a754e59576…

MALICIOUS

PDF

59.7 KB Created: 2021-04-05 19:51:24 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7) First seen: 2021-10-05
MD5: 527e18804c5681350108d1f5e740dacf SHA-1: 9a3b6ee8623e45453d0778c1a09138084acd61b9 SHA-256: 897af9a754e595768aea5c67bdb41927c1c07e58a282c91cc7cf74a5ee4d2401
82 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF document uses a lure related to obtaining free in-game currency for Roblox, a common social engineering tactic. It contains multiple embedded URLs pointing to potentially malicious sites, and a heuristic identified it as a browser extension/update installation lure. The document body, though partially corrupted, contains text and URLs consistent with this phishing attempt.

Machine Learning

  • Nyx PDF Classifier malicious score 0.6193

Heuristics 4

  • Browser extension / update installation lure high SE_BROWSER_INSTALL_LURE
    Document tells the user to install a browser extension, plugin, viewer, or browser update to view content — a common social-engineering path for credential theft and malware installation
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://gaminggenerator.org/app/431946152/how-to-change-your-username-on-roblox-for-free PDF link annotation
    • https://www.ghknights.org/images/does-hacking-on-roblox-get-u-banned.pdfIn PDF document text
    • http://uptodate.az/images/free-military-costume-roblox.pdfIn PDF document text
    • http://arcnjournals.org/images/roblox-hack-999999-robux-pc-en-espaol.pdfIn PDF document text
    • http://legitame.org/images/roblox-free-online-no-signing-up-or-nothing.pdfIn PDF document text
    • https://www.iadh.bi/images/hacks-para-roblox-robux.pdfIn PDF document text
    • http://lakomat.by/images/generator-robux-free-2021.pdfIn PDF document text
    • https://www.hotschool.com.au/images/www-roblox-hack-com.pdfIn PDF document text
    • http://www.fanciullovito.it/images/roblox-download-mac-free.pdfIn PDF document text
    • http://modlingua.com/images/dragon-ball-final-stand-roblox-hacks.pdfIn PDF document text
    • https://www.air-shop.cz/images/zombie-free-zone-roblox.pdfIn PDF document text
    • http://dorfgaragethalwil.ch/images/roblox-the-rake-hack-script.pdfIn PDF document text
    • https://www.lomrad.go.th/images/robloc-robux-hack.pdfIn PDF document text
    • http://bc97.de/images/how-to-get-wall-hack-roblox.pdfIn PDF document text
    • http://behsanroshd.com/images/roblox-play-free-no-sign-in.pdfIn PDF document text
    • https://omhelsjehart.nu/images/roblox-nation-hack.pdfIn PDF document text
    • http://sealysports.com/images/how-to-win-free-robux.pdfIn PDF document text
    • http://escolaarboc.cat/images/como-hackear-roblox-jailbreak-2021.pdfIn PDF document text
    • http://www.hotelcomelico.it/images/free-robux-and-bc-update.pdfIn PDF document text
    • http://dermaceutic.co.uk/images/nuevo-hack-de-robux-2021-realmente-funciona.pdfIn PDF document text
    • https://www.millatgears.com/images/free-codes-for-roblox-to-get-robux.pdfIn PDF document text
    • http://dottgagliardi.com/images/error-roblox-hacker.pdfIn PDF document text
    • http://brusivojimi.com/images/free-robux-rixty-codes-2021.pdfIn PDF document text
    • https://www.tsdb.com.au/images/how-to-cheat-robux-in-roblox-2021.pdfIn PDF document text
    • http://cadcam.no/images/hack-in-roblox-that-everyone-can-see.pdfIn PDF document text
    • http://principessalialaofegypt.com/images/robux-cheats-no-verification.pdfIn PDF document text
    • https://www.stayon.no/images/how-to-hack-roblox-accounts-kid.pdfIn PDF document text
    • http://cmme.it/images/roblox-hack-week-custom-materials.pdfIn PDF document text
    • https://itv-grabungen.de/images/how-to-speed-hack-on-roblox-without-cheat-engine-2021.pdfIn PDF document text
    • https://www.eglihotel.gr/images/generator-roblox-hack.pdfIn PDF document text
    • https://www.albisser.ch/images/roblox-shard-seekers-cheat.pdfIn PDF document text
    • http://behsanroshd.com/images/free-robux-2021-february.pdfIn PDF document text
    • http://xn-----clcdhzcbmgnochhb1boe1a6b.xn--p1ai/images/roblox-farming-simulator-cheats.pdfIn PDF document text
    • https://gomsa.nl/images/seven-v2-roblox-free-download.pdfIn PDF document text
    • http://greenoase.be/images/shark-bite-roblox-hack.pdfIn PDF document text
    • http://5346000.com/images/how-to-hack-murder-mystery-roblox.pdfIn PDF document text
    • http://pia2000.net/images/how-do-you-get-free-robux-for-real.pdfIn PDF document text
    • https://fkg.usu.ac.id/images/free-group-generator-for-roblox.pdfIn PDF document text
    • http://www.peterdejonge.nl/images/free-robux-bloxburg.pdfIn PDF document text
    • http://www.homesweethome.pl/images/free-and-easy-unlimited-robux-2021.pdfIn PDF document text
    • http://agrao.in/images/the-fastest-way-to-get-free-robux.pdfIn PDF document text
    • http://elitesoftsolutions.com/images/how-to-hack-a-roblox-account-to-show-peoples.pdfIn PDF document text
    • https://www.gletthofer.at/images/how-to-hack-all-roblox-games-pc.pdfIn PDF document text
    • http://salantiskis.lt/images/free-roblox-outfits-for-boys.pdfIn PDF document text
    • http://legitame.org/images/how-to-hack-super-simon-says-in-roblox.pdfIn PDF document text
    • https://www.hotel-forsthaus.com/images/actual-ways-to-get-free-robux.pdfIn PDF document text
    • https://www.millatgears.com/images/conscle-hacks-for-roblox.pdfIn PDF document text
    • http://www.maakherumusic.net/images/how-to-noclip-2021-roblox-cheat-engine.pdfIn PDF document text
    • https://sitam.co.in/images/roblox-hack-move-2021.pdfIn PDF document text
    • https://www.nema.go.ke/images/free-roblox-pin-codes-generator.pdfIn PDF document text
    +10 more URL(s)

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_003_off00007fb0.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x7FB0 25436 bytes
SHA-256: be80e30c8f8e79f5fba3d1cf19f0b7df21258e1954c563caf23f59d8fb704d37
font_01_sfnt_off0000b99e.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xB99E 2832 bytes
SHA-256: 77ae1c4cffa647a8fd533dfa4102e94364989f9e80b9cd131876e9d1005899a2
font_02_sfnt_off0000c34e.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xC34E 19128 bytes
SHA-256: 410c262f941ae5fb97195e2da4733f695299f1c81a3778f3c3158216d7164c10