Malicious PDF — malware analysis report

Static analysis result for SHA-256 9afbb66e343b41c7…

MALICIOUS

PDF

60.0 KB Created: 2021-04-06 06:11:35 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7) First seen: 2021-09-29
MD5: c8e6bf78f972d4fd8fa7cf17556a5994 SHA-1: 9ca6b5c3d084765c48313857ec2ba9098f3b9100 SHA-256: 9afbb66e343b41c757f9ac1a074fd2e9f20a82e3b21b7017223ba61485247f9d
82 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

This PDF document was flagged as malicious by an ML classifier. The file routes users through malicious redirector infrastructure and presents a deceptive download button. Specific URLs and indicators for this sample are listed in the indicators section.

Machine Learning

  • Nyx PDF Classifier malicious score 0.6193

Heuristics 4

  • PDF links to a 'free generator / game hack' redirector high PDF_GAME_HACK_REDIRECT_LURE
    PDF's clickable action targets a redirector of the form /app/<id>/<slug>-game-hack — the landing-page shape of a large SEO 'free spins / generator / game hack' lure family that funnels victims through rotating disposable hosts to a malware/scam payload. The multi-link variants also trip ML/link-farm rules; this catches the single-link variants that otherwise score clean.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://enigmagenerator.com/app/431946152/roblox-game-hack PDF link annotation
    • http://bernd-voehringer.de/images/roblox-free-costumes.pdfIn PDF document text
    • http://www.brtes.com/images/roblox-afk-cheat.pdfIn PDF document text
    • http://glaubensfragen.org/images/synapse-roblox-cheat-buy.pdfIn PDF document text
    • http://nouveaupavillon.fr/images/how-to-hack-roblox-mad-city.pdfIn PDF document text
    • http://www.marambio.com.ar/images/how-to-change-your-name-in-roblox-for-free-mobile.pdfIn PDF document text
    • https://www.iadh.bi/images/best-hack-of-roblox.pdfIn PDF document text
    • https://www.lavigny.ch/images/how-to-play-roblox-free-online.pdfIn PDF document text
    • http://soma.com.ua/images/roblox-rush-com-free-robux.pdfIn PDF document text
    • https://gestionpatrimonial.net/images/synapse-hack-roblox-download-free-2021.pdfIn PDF document text
    • https://www.utalii.ac.ke/images/roblox-cheat-uscom.pdfIn PDF document text
    • http://per-bittner.de/images/free-robux-25k.pdfIn PDF document text
    • http://salantiskis.lt/images/free-robux-25k.pdfIn PDF document text
    • http://dijelovi.info/images/free4mobile24-com-roblox-hack.pdfIn PDF document text
    • https://www.coriglianocalabro.it/images/how-to-get-hacks-on-roblox-streets-2021.pdfIn PDF document text
    • https://www.seeingindependence.org/images/roblox-free-generator-no-verification.pdfIn PDF document text
    • http://innovativefs.co.uk/images/robux-free-72-claim.pdfIn PDF document text
    • http://www.mediaxin.net/images/roblox-one-piece-grand-trial-hack.pdfIn PDF document text
    • http://joshherman.com/images/free-roblox-account-givaway-may-7th-2021.pdfIn PDF document text
    • http://casabea.de/images/roblox-speed-race-cheats.pdfIn PDF document text
    • http://icomsolutions.com.au/images/roblox-call-of-robloxia-5-hack.pdfIn PDF document text
    • https://verdensbarn.no/images/roblox-premium-hacks.pdfIn PDF document text
    • http://dos.most.gov.la/images/roblox-rocitizens-free-money-codes.pdfIn PDF document text
    • http://www.eurosan1.ba/images/free-uncopylocked-roblox-games.pdfIn PDF document text
    • https://www.cfdcnv.com/images/free-robux-generator-real-2021.pdfIn PDF document text
    • https://omhelsjehart.nu/images/roblox-getting-hacked-right-now.pdfIn PDF document text
    • http://www.visiblefilm.com/images/roblox-dbor-q-button-hack.pdfIn PDF document text
    • http://salantiskis.lt/images/comment-hacker-roblox-2021.pdfIn PDF document text
    • http://www.campiresine.it/images/roblox-security-vest-free.pdfIn PDF document text
    • http://clubpure.org/images/roblox-my-hero-release-boku-no-free-code-2021.pdfIn PDF document text
    • http://pisanie-nut.pl/images/shirt-ash-on-roblox-free-on-shirt.pdfIn PDF document text
    • http://iluvlocalplaces.com/images/free-robux-every-5-seconds-directo.pdfIn PDF document text
    • http://fccsms.com/images/cheat-generator-roblox.pdfIn PDF document text
    • http://icomsolutions.com.au/images/free-cute-royale-high-outfits-roblox-twitter.pdfIn PDF document text
    • http://scuttworksdesigns.us/images/how-to-hack-prison-life-in-roblox.pdfIn PDF document text
    • http://salantiskis.lt/images/how-to-have-a-mad-city-roblox-hack.pdfIn PDF document text
    • http://www.hawler.in/images/how-to-hack-roblox-to-where-you-can-fly.pdfIn PDF document text
    • http://technologicalsc.com/images/how-to-get-free-robux-redeem-code-2021.pdfIn PDF document text
    • http://arhi-z.ru/images/any-free-roblox-exploits-2021-reddit.pdfIn PDF document text
    • http://properteez.com/images/roblox-hack-codes.pdfIn PDF document text
    • http://webstan.be/images/hack-adopt-me-roblox-link.pdfIn PDF document text
    • http://erntefest2016.de/images/get-robux-free-of-charge.pdfIn PDF document text
    • http://racunari.in.rs/images/hack-roblox-now.pdfIn PDF document text
    • https://gabrieliassociati.com/images/how-to-use-a-cheat-on-roblox-jailbreak.pdfIn PDF document text
    • https://camillesplace.org/images/roblox-kick-hack.pdfIn PDF document text
    • https://www.ergolight.at/images/free-robux-no-scam-no-human-verification.pdfIn PDF document text
    • http://kancelaria-legnica.eu/images/roblox-elemental-battlegrounds-speed-hack.pdfIn PDF document text
    • https://www.foodsafety.cz/images/free-online-games-similar-to-roblox.pdfIn PDF document text
    • http://learningarabic.co.uk/images/secure-payment-with-roblox-free-robux.pdfIn PDF document text
    • http://bibliodetki.ru/images/how-to-get-a-free-golden-boombox-in-roblox.pdfIn PDF document text
    +12 more URL(s)

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_003_off00008057.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x8057 25616 bytes
SHA-256: 8440ca08fc621e48b3b76ca2d17f8f67c4ec388d474635c085f083384b487ec9
font_01_sfnt_off0000ba5d.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xBA5D 3312 bytes
SHA-256: 40bd8eebcb3a0d68a8646f1930e84f30a44bfa48525263c6c528f0bc1e9c1677
font_02_sfnt_off0000c5ad.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xC5AD 18724 bytes
SHA-256: 143af944cacd586cdbbc8489deaa028be6c5cc95463efbda51d6a294bfb02fd7