Malicious PDF — malware analysis report

Static analysis result for SHA-256 8d18d299b6d53b39…

MALICIOUS

PDF

51.9 KB Created: 2021-04-06 16:42:41 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7) First seen: 2021-09-29
MD5: 75a72d1f4e4cd4a48c192056447c4982 SHA-1: 1d0603cbd5c6f6ff9af0e85af305d41597967f38 SHA-256: 8d18d299b6d53b39b9068423c7caf1818caee6a3812570dc163b8d2384cc27e4
82 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains multiple embedded links and a prominent call-to-action related to 'Roblox hacks' and 'free Robux'. The heuristic PDF_GAME_HACK_REDIRECT_LURE specifically flags this type of lure. While no scripts were extracted, the document body and heuristics indicate a strong likelihood that clicking these links leads to malicious websites designed to exploit user interest in game cheats, likely for phishing or malware distribution.

Machine Learning

  • Nyx PDF Classifier malicious score 0.8896

Heuristics 4

  • PDF links to a 'free generator / game hack' redirector high PDF_GAME_HACK_REDIRECT_LURE
    PDF's clickable action targets a redirector of the form /app/<id>/<slug>-game-hack — the landing-page shape of a large SEO 'free spins / generator / game hack' lure family that funnels victims through rotating disposable hosts to a malware/scam payload. The multi-link variants also trip ML/link-farm rules; this catches the single-link variants that otherwise score clean.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://enigmagenerator.com/app/431946152/roblox-game-hack PDF link annotation
    • http://tc-kulmbach.de/images/want-free-robux-ad.pdfIn PDF document text
    • http://www.exikom.com.ua/images/roblox-skywars-mega-vip-free-glitch.pdfIn PDF document text
    • http://xn--apartementos-smfora-cala-ratjada-4vc.de/images/design-it-cheats-roblox.pdfIn PDF document text
    • http://www.lycee-langevin-wallon.com/images/how-to-get-hacks-on-roblox-mobile.pdfIn PDF document text
    • http://www.marambio.com.ar/images/roblox-pitch-black-shirt-free.pdfIn PDF document text
    • https://osk-sibir.ru/images/robux-rbx-calc-free.pdfIn PDF document text
    • http://iglesiashispanas.org/images/my-roblox-game-was-hacked.pdfIn PDF document text
    • http://zinicrom.com/images/roblox-copyright-free-music.pdfIn PDF document text
    • https://schaefer-rechtsanwaelte.com/images/objet-roblox-free.pdfIn PDF document text
    • http://fmbompastor.com.br/images/hack-roblox-gratuito.pdfIn PDF document text
    • http://www.eurologistiki.gr/images/how-to-hack-robux-using-cheat-engine-64.pdfIn PDF document text
    • http://fradiomas.com/images/robux-maniac-free-catlog-bookmarks.pdfIn PDF document text
    • http://uptodate.az/images/roblox-hack-phantom-forces-cheat-engine.pdfIn PDF document text
    • https://www.quistschoenenhalsteren.nl/images/best-roblox-exploits-for-free.pdfIn PDF document text
    • http://genialica.de/images/free-bc-roblox-accounts-pastebin.pdfIn PDF document text
    • http://www.sanjosedeminas.gob.ec/images/learn-lua-roblox-free.pdfIn PDF document text
    • http://nosocomium.rv.ua/images/nbc-roblox-free-accounts.pdfIn PDF document text
    • https://wandpiraten.de/images/roblox-lumber-tycon-2-menu-no-cheat-engine.pdfIn PDF document text
    • http://www.cosver.nl/images/roblox-hack-client-mac.pdfIn PDF document text
    • http://www.hawler.in/images/how-to-play-paid-acess-roblox-games-free.pdfIn PDF document text
    • http://verenacrow.at/images/how-to-play-roblox-liberty-county-for-free.pdfIn PDF document text
    • http://icomsolutions.com.au/images/free-roblox-accounts-made-in-2021.pdfIn PDF document text
    • https://www.eglihotel.gr/images/hack-speed-booga-booga-roblox.pdfIn PDF document text
    • https://rieber-transporte.de/images/free-shirt-roblox-2021.pdfIn PDF document text
    • http://www.isril.it/images/best-roblox-hacks-gui.pdfIn PDF document text
    • http://escolaarboc.cat/images/free-roblox-promo-codes-2021-for-robux.pdfIn PDF document text
    • http://www.vktzunami.cz/images/free-robux-videos-recent.pdfIn PDF document text
    • http://vipservice-bg.com/images/roblox-i-hacked-place-rebuilder.pdfIn PDF document text
    • http://www.remiauclair.fr/images/mc-the-miner-free-robux-hack.pdfIn PDF document text
    • http://www.duchidicastelluccio.it/images/roblox-fly-hack-2021.pdfIn PDF document text
    • https://www.utalii.ac.ke/images/cheats-for-getting-money-in-roblox-meep-city.pdfIn PDF document text
    • http://5346000.com/images/cheat-roblox-soros-resataurant.pdfIn PDF document text
    • https://estalagemmonteverde.com.br/images/roblox-hack-mod-menu-android-2021.pdfIn PDF document text
    • https://www.gymun.cz/images/roblox-muscle-simulater-cheat-codes.pdfIn PDF document text
    • https://waterpark.by:443/images/get-free-25-robux.pdfIn PDF document text
    • http://joshherman.com/images/comment-hacker-roblox-robux.pdfIn PDF document text
    • https://www.stoehr-sauer.de/images/free-robux-generator-no-human-verification-mobile.pdfIn PDF document text
    • http://techmobil.pl/images/hacks-on-roblox-chat.pdfIn PDF document text
    • https://www.knxuk.org/images/how-to-hack-linkmon99-roblox-account.pdfIn PDF document text
    • http://www.sapaengineering.kz/images/free-boat-ride-roblox-funneh.pdfIn PDF document text
    • https://www.u-pin-it.com/images/aimbot-cheat-roblox.pdfIn PDF document text
    • https://meltonschool.org/images/hack-per-roblox-2021.pdfIn PDF document text
    • http://optsuvenir.by/images/free-roblox-promocode-for-robux-july-2021.pdfIn PDF document text
    • http://sdservicesrl.it/images/hot-to-hack-roblox-games.pdfIn PDF document text
    • http://tc-kulmbach.de/images/5-robux-for-free.pdfIn PDF document text
    • http://www.copoint.co.uk/images/how-to-get-free-wings-on-roblox-2021.pdfIn PDF document text
    • https://zapoj-kharkov.com.ua/images/mad-city-roblox-hack-pain.pdfIn PDF document text
    • http://sscclc.edu.ec/images/codes-to-get-free-items-on-roblox.pdfIn PDF document text
    • http://evp-sanorlenok.ru/images/como-hackear-ropa-en-roblox-2021.pdfIn PDF document text
    +19 more URL(s)

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_003_off00006f17.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x6F17 25048 bytes
SHA-256: 8007588bce483c2fe205693815175fb80e5df88fc7e95c57b092998060d05fb4
font_01_sfnt_off0000a8eb.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xA8EB 17652 bytes
SHA-256: d94885841f93f0d61364a0eb876a26955db5a45519eb5ca6232d0137e6903913