Malicious PDF — malware analysis report

Static analysis result for SHA-256 9c91e83b6577afd3…

MALICIOUS

PDF

55.7 KB Created: 2021-04-06 15:02:48 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7) First seen: 2021-09-29
MD5: cd6c486a86eb4f5d0dffc55386f8b617 SHA-1: 0d7366b32523addb16781c45713e614e4a2faa0c SHA-256: 9c91e83b6577afd39fa775bdcd0c5de48e430c06d4a2c6c38cc103385da3b47f
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

This PDF document was flagged as malicious by an ML classifier. It uses an urgency-based lure. The file routes users through malicious redirector infrastructure and presents a deceptive download button. Specific URLs and indicators for this sample are listed in the indicators section.

Machine Learning

  • Nyx PDF Classifier malicious score 0.6397

Heuristics 5

  • PDF links to a 'free generator / game hack' redirector high PDF_GAME_HACK_REDIRECT_LURE
    PDF's clickable action targets a redirector of the form /app/<id>/<slug>-game-hack — the landing-page shape of a large SEO 'free spins / generator / game hack' lure family that funnels victims through rotating disposable hosts to a malware/scam payload. The multi-link variants also trip ML/link-farm rules; this catches the single-link variants that otherwise score clean.
  • Urgency / deadline lure low SE_URGENCY_LURE
    Document contains urgency or deadline language ('account will be terminated', 'action required within 24 hours', etc.) — useful context, but low-signal without other findings
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://enigmagenerator.com/app/431946152/roblox-game-hack PDF link annotation
    • http://agrao.in/images/boku-no-roblox-remastered-hack-script-2021.pdfIn PDF document text
    • http://bkd1.balikpapan.go.id/images/hack-roblox-jailbreak-noclip-2021.pdfIn PDF document text
    • http://poltekkeskhjogja.ac.id/images/free-robux-it-meme.pdfIn PDF document text
    • http://ferienwohnung-walker.de/images/free-robux-no-human-verification-2021.pdfIn PDF document text
    • http://classicskitours.net/images/roblox-bio-hack.pdfIn PDF document text
    • http://fotoclub3b.it/images/roblox-promos-hack-pastebin.pdfIn PDF document text
    • http://bolsaycapital.com/images/fencing-roblox-hacks.pdfIn PDF document text
    • http://nevesomost.by/images/roblox-phantom-force-cheat-dill.pdfIn PDF document text
    • http://iricamidelcuore.it/images/change-roblox-username-free-2021.pdfIn PDF document text
    • https://kldcardio.ru/images/bux-life-roblox-cheats.pdfIn PDF document text
    • http://axiapublishers.com/images/hack-sur-roblox.pdfIn PDF document text
    • http://www.mjclautrec.fr/images/roblox-shaded-shirt-template-free-shipping.pdfIn PDF document text
    • http://www.maranata4x4.co.za/images/hack-roblox-tener-nepe.pdfIn PDF document text
    • http://www.hotel-seminaire.com/images/roblox-hack-and-cheats-apk.pdfIn PDF document text
    • https://www.appartamenticroazia24.com/images/roblox-gui-hack-pastebin.pdfIn PDF document text
    • http://hk-kan.org/images/how-to-change-username-roblox-for-free-2021.pdfIn PDF document text
    • https://willifox.com/images/roblox-jailbreak-hack-money-cheat-engine.pdfIn PDF document text
    • http://malichy.pl/images/gaming-app-cheats-com-roblox.pdfIn PDF document text
    • https://www.ghknights.org/images/how-to-get-free-robux-at-computer.pdfIn PDF document text
    • http://agrupamentoescolas-alfredo-da-silva.com/images/free-candy-id-roblox.pdfIn PDF document text
    • http://scuttworksdesigns.us/images/mad-city-roblox-money-hack-no-human-verification.pdfIn PDF document text
    • https://www.tsdb.com.au/images/free-roblox-accounts-with-bc-2021.pdfIn PDF document text
    • http://jackson-pr.com/images/how-to-hack-into-peoples-roblox-accounts-2021.pdfIn PDF document text
    • https://www.porthos.it/images/feel-the-rainbow-besh-roblox-hacking.pdfIn PDF document text
    • http://schlossschaenke-andernach.de/images/free-robux-no-verification-youtube.pdfIn PDF document text
    • https://www.laarsenco.nl/images/roblox-hack-iosgods.pdfIn PDF document text
    • http://www.pacoestrada.it/images/how-to-glitch-builders-club-for-free-on-roblox.pdfIn PDF document text
    • http://echosvoix.ch/images/free-roblox-gui.pdfIn PDF document text
    • https://inspiration-modellbau.de/images/how-to-get-free-vip-servers-roblox.pdfIn PDF document text
    • http://solidcom.ch/images/free-vip-server-roblox-lumber-tycoon-2.pdfIn PDF document text
    • http://chocolats-boccardi-carcassonne.com/images/how-to-use-cheat-engine-on-roblox-retail-tycoon.pdfIn PDF document text
    • https://www.fhccu.com/images/free-robux-game-cards.pdfIn PDF document text
    • http://logisticgroup.co/images/roblox-how-to-hack-a-person.pdfIn PDF document text
    • http://modlingua.com/images/roblox-jailbreak-hack-keycard.pdfIn PDF document text
    • https://www.stkdb.cz/images/roblox-hack-scrip.pdfIn PDF document text
    • http://cmme.it/images/free-robux-codes-2021-september.pdfIn PDF document text
    • http://posterprintshop.nl/images/roblox-police-shirt-free.pdfIn PDF document text
    • http://5346000.com/images/www-free-robux-tips.pdfIn PDF document text
    • http://ines.co.rs/images/free-robux-you-dont-have-to-do-anything.pdfIn PDF document text
    • http://www.actae.gr/images/how-do-you-change-your-roblox-username-for-free.pdfIn PDF document text
    • http://musical-arts.de/images/free-admin-hack-roblox.pdfIn PDF document text
    • https://www.lauresa.de/images/roblox-legendary-swords-rpg-hack.pdfIn PDF document text
    • http://vokna.by/images/how-to-hack-weight-lifting-simulator-roblox.pdfIn PDF document text
    • https://www.najeebqasmi.com/images/free-xbox-gameachievements-roblox.pdfIn PDF document text
    • http://abqwinair.com/images/free-items-on-roblox-2021-catalog.pdfIn PDF document text
    • https://www.tsdb.com.au/images/roblox-free-avatar-items-2021.pdfIn PDF document text
    • http://iacovoulaw.com/images/roblox-speed-hack-2021-may.pdfIn PDF document text
    • https://www.hbproducts.dk/images/roblox-change-username-for-free-nanoo.pdfIn PDF document text
    • http://www.eptaviation.com/images/how-to-spawn-in-working-gears-roblox-hack-script.pdfIn PDF document text
    +17 more URL(s)

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_003_off000071ec.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x71EC 25648 bytes
SHA-256: fd98e8dcf96c96b87e4b99e7fc295ff0cd22058cc83e0f0fc49456965d1a2e8e
font_01_sfnt_off0000aadd.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xAADD 3312 bytes
SHA-256: 40bd8eebcb3a0d68a8646f1930e84f30a44bfa48525263c6c528f0bc1e9c1677
font_02_sfnt_off0000b62d.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xB62D 18124 bytes
SHA-256: f4cec5a3bb0b377b6aaa205fca4fe5868fd9ed56824a79ae1475d8b9b579eac4