Malicious PDF — malware analysis report

Static analysis result for SHA-256 93eaf1b0f6e2b1b9…

MALICIOUS

PDF

53.8 KB Created: 2021-04-07 03:15:02 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7) First seen: 2021-09-17
MD5: f8cdb6c0393c78032fd71b22b53dece5 SHA-1: d21004fb2ee108cf3582cedc4c19dd592ca39489 SHA-256: 93eaf1b0f6e2b1b9f6f9a2e85da025e3d4aaac9487fb4f2770bc0308ca1e4491
82 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF document contains multiple links to websites advertising game hacks and cheats, specifically for Roblox. The heuristic 'PDF_GAME_HACK_REDIRECT_LURE' confirms this intent. While no scripts were directly extracted, the presence of embedded URLs and the nature of the lure suggest a phishing or malware distribution attempt, likely initiated via a spearphishing attachment.

Machine Learning

  • Nyx PDF Classifier malicious score 0.8413

Heuristics 4

  • PDF links to a 'free generator / game hack' redirector high PDF_GAME_HACK_REDIRECT_LURE
    PDF's clickable action targets a redirector of the form /app/<id>/<slug>-game-hack — the landing-page shape of a large SEO 'free spins / generator / game hack' lure family that funnels victims through rotating disposable hosts to a malware/scam payload. The multi-link variants also trip ML/link-farm rules; this catches the single-link variants that otherwise score clean.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://enigmagenerator.com/app/431946152/roblox-game-hack PDF link annotation
    • http://www.torvet11.dk/images/roblox-spawn-cheat.pdfIn PDF document text
    • http://sealysports.com/images/how-to-go-free-camrea-in-roblox.pdfIn PDF document text
    • https://ceranique.nl/images/free-robux-no-verification-2021-android.pdfIn PDF document text
    • http://serviio.org/images/free-robux-android-hack.pdfIn PDF document text
    • http://moralcenter.or.th/images/best-roblox-fps-unlocker-free.pdfIn PDF document text
    • http://www.lovecraftiana.com.ar/images/cheat-engine-robux-2021.pdfIn PDF document text
    • https://www.showalterpropertyconsultants.com/images/hacker-song-roblox-id.pdfIn PDF document text
    • http://racunari.in.rs/images/evil-hacker-game-roblox.pdfIn PDF document text
    • http://medimacs.eu/images/how-to-hack-roblox-to-get-free-robux-easy.pdfIn PDF document text
    • http://harmonygardens.ca/images/roblox-ghost-hack-download-2021.pdfIn PDF document text
    • http://mou16-murmansk.ru/images/free-rich-roblox-accounts-2021.pdfIn PDF document text
    • http://fred.com.ua/images/guuudinfo-robux-hack-2021.pdfIn PDF document text
    • http://www.remiauclair.fr/images/free-robux-no-human-verfaction.pdfIn PDF document text
    • http://santeh-40.ru/images/free-robux-cards-no-verification.pdfIn PDF document text
    • http://columbuscigar.com/images/old-roblox-hack.pdfIn PDF document text
    • http://depilhome-fr.fr/images/how-to-get-free-robux-kid-friendly.pdfIn PDF document text
    • http://www.colledellaselva.it/images/my-roblox-account-has-beem-hacked.pdfIn PDF document text
    • https://www.lomrad.go.th/images/elemental-cheats-war-magic-roblox.pdfIn PDF document text
    • http://naturschutzgossau-zh.ch/images/free-account-that-have-robux-that-are-100-real.pdfIn PDF document text
    • http://ordineingsa.it/images/roblox-person-with-free-hoodie.pdfIn PDF document text
    • http://www.remiauclair.fr/images/cowboy-t-shirt-roblox-free.pdfIn PDF document text
    • http://intrasservices.com/images/free-robux-no-human-verification-no-scam.pdfIn PDF document text
    • http://legs11.co.za/images/roblox-alone-hack-script.pdfIn PDF document text
    • https://liceucastrodelapenya.com/images/roblox-music-player-hack-2021.pdfIn PDF document text
    • http://gaec.cl/images/how-to-make-an-audio-for-free-in-roblox.pdfIn PDF document text
    • http://www.teapotjewelry.com/images/how-to-insert-a-hack-script-into-roblox-game.pdfIn PDF document text
    • http://www.mcveicolicommerciali.it/images/how-to-get-free-bc-for-roblox.pdfIn PDF document text
    • http://www.imwd.it/images/free-robux-card-generator.pdfIn PDF document text
    • http://technologicalsc.com/images/roblox-how-to-get-free-robux-no-hacks-2021.pdfIn PDF document text
    • http://pa-tanjungselor.go.id/images/roblox-a380-free-model.pdfIn PDF document text
    • http://escolaarboc.cat/images/free-robux-gift-card-codes-live.pdfIn PDF document text
    • http://www.zdravazena.sk/images/roblox-assassin-moving-cheat.pdfIn PDF document text
    • https://komakinosite.jp/images/how-to-use-cheat-engine-64-on-roblox-2021.pdfIn PDF document text
    • https://gabrieliassociati.com/images/como-hackear-roblox-prison-life-20.pdfIn PDF document text
    • https://kimolos-link.gr/images/roblox-free-candy-van-script-pastebin.pdfIn PDF document text
    • https://www.sauvonsleclimat.org/images/free-lua-executor-roblox.pdfIn PDF document text
    • http://kaleasm.org/images/free-robux-hack-installer.pdfIn PDF document text
    • http://soma.com.ua/images/how-to-get-free-robux-2021-to-keep.pdfIn PDF document text
    • http://almacargo.com/images/roblox-hack-exploit-no-virus.pdfIn PDF document text
    • http://hindicenter.com/images/how-to-get-a-lot-of-robux-for-free-2021.pdfIn PDF document text
    • http://www.web.stc-part.co.th/images/roblox-make-shirt-price-free.pdfIn PDF document text
    • http://scuttworksdesigns.us/images/how-to-hack-sword-art-online-roblox.pdfIn PDF document text
    • http://iedarelief.us/images/free-roblox-hack-com-free-roblox-hack.pdfIn PDF document text
    • http://www.gadanie.lv/images/noclip-hacks-for-roblox.pdfIn PDF document text
    • http://www.zdravazena.sk/images/free-roblox-templates.pdfIn PDF document text
    • http://ivalor.fr/images/free-robux-codes-no-human-verification-2021.pdfIn PDF document text
    • https://www.devries-group.de/images/how-to-get-free-robux-youtube.pdfIn PDF document text
    • http://dennemaat.nl/images/money-hack-adopt-me-roblox.pdfIn PDF document text
    • http://escolaarboc.cat/images/hacker-t-dog-roblox.pdfIn PDF document text
    +14 more URL(s)

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_003_off00006e81.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x6E81 26232 bytes
SHA-256: 24e0dc237f002dd019a157fae9537b14bf349e1907b4e39f36abec345a762f36
font_01_sfnt_off0000a990.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xA990 19904 bytes
SHA-256: e88c755db459b22862a2aeb28c0572d4ce3fdb7ee090c6fbad6ef4bf972932a8