Malicious PDF — malware analysis report

Static analysis result for SHA-256 b84ac88b63a4872f…

MALICIOUS

PDF

64.1 KB Created: 2021-04-05 20:13:19 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7) First seen: 2021-09-29
MD5: c84fece20920bd269bfd7aabc3d9162c SHA-1: 96c87b45b4a911eaed40a6e013fd06b9c1c8cc16 SHA-256: b84ac88b63a4872f70d3dab836cc35d38c4071b866d89e1ea9da0d01e75e01a4
82 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF document impersonates PayPal and uses a lure related to Roblox hacks to entice users to click on malicious links. The primary link, http://gaminggenerator.org/app/431946152/roblox-online-hack-robux, is hosted on a domain unrelated to PayPal, indicating a credential phishing or malware distribution attempt. The ML classifier also flagged this PDF as malicious.

Machine Learning

  • Nyx PDF Classifier malicious score 0.6301

Heuristics 4

  • Brand-impersonation credential phishing lure high SE_BRAND_CREDENTIAL_PHISH
    Document impersonates a well-known consumer brand and uses account-security / verification language ('unusual activity', 'account on hold', 'verify your account') to steer the reader to a credential-harvesting link. Corroborated by: call-to-action link host does not match the impersonated brand: http://gaminggenerator.org/app/431946152/roblox-online-hack-robux.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://gaminggenerator.org/app/431946152/roblox-online-hack-robux PDF link annotation
    • http://www.inservis.cl/images/roblox-hack-robux-ios.pdfIn PDF document text
    • http://consultinggirona.es/images/how-to-hack-almost-any-game-roblox-youtube.pdfIn PDF document text
    • http://www.awakeningtruth.org/images/is-roblox-being-hacked-right-now.pdfIn PDF document text
    • https://www.tsdb.com.au/images/can-you-make-free-shirts-on-roblox.pdfIn PDF document text
    • http://domaizdereva24.ru/images/all-game-roblox-admin-gui-hack-working.pdfIn PDF document text
    • https://heritagebanquethall.ca/images/can-u-hack-roblox.pdfIn PDF document text
    • https://www.seeingindependence.org/images/how-to-hack-a-persons-in-roblox.pdfIn PDF document text
    • https://www.ausecus.com/images/how-to-hack-games-on-roblox-2021.pdfIn PDF document text
    • https://www.osoc.com/images/how-to-get-any-roblox-game-pass-for-free-2021.pdfIn PDF document text
    • http://condit-pack.com/images/hackaron-roblox-hack-download.pdfIn PDF document text
    • https://www.stoehr-sauer.de/images/rbc-points-get-free-robux-points.pdfIn PDF document text
    • http://www.notaioricci.it/images/cuentas-gratis-de-roblox-hack.pdfIn PDF document text
    • http://elitesoftsolutions.com/images/roblox-best-free-t-shirts.pdfIn PDF document text
    • http://parkinsononline.com/images/how-to-hack-on-accounts-on-roblox.pdfIn PDF document text
    • https://www.quistschoenenhalsteren.nl/images/hacks-roblox-jailbreak-2021.pdfIn PDF document text
    • https://bancroftandsons.com/images/fe-dll-hacks-roblox.pdfIn PDF document text
    • http://www.eptaviation.com/images/comment-cheater-sur-roblox-relail-ticoon.pdfIn PDF document text
    • https://www.eglihotel.gr/images/can-you-use-cheat-engine-to-hack-robux.pdfIn PDF document text
    • http://businessmart.ro/images/how-to-hack-people-acount-in-roblox.pdfIn PDF document text
    • http://bwharrisalumniusa.org/images/como-ser-um-hacker-de-roblox-iniciante-no-pc.pdfIn PDF document text
    • http://rushxpress.de/images/free-t-shirt-give-roblox.pdfIn PDF document text
    • http://cmme.it/images/how-to-get-free-robux-2021-on-ipad.pdfIn PDF document text
    • https://www.acoustiguard.com/images/free-knife-code-assasins-roblox.pdfIn PDF document text
    • http://petarda.hu/images/free-robux-codes-no-survey-or-human-verification.pdfIn PDF document text
    • http://amtabor2.at/images/roblox-the-legendary-swords-rpg-hack.pdfIn PDF document text
    • https://www.stayon.no/images/calamari-free-roblox.pdfIn PDF document text
    • http://aeroclub-kaernten.at/images/hack-robux-gratis-como-tener-robux-gratis-en-roblox.pdfIn PDF document text
    • https://reggieslockandkey.com/images/how-to-get-free-robux-2021-with-no-inspection.pdfIn PDF document text
    • http://www.cosver.nl/images/roblox-dbor-how-to-hack-levels.pdfIn PDF document text
    • https://www.appartamenticroazia24.com/images/hacking-into-my-brothers-roblox-account.pdfIn PDF document text
    • http://getthelook-bkk.com/images/scp-2021-roblox-hacks.pdfIn PDF document text
    • https://verdensbarn.no/images/roblox-urbis-money-hack-cheat-engine.pdfIn PDF document text
    • http://tehergumi.hu/images/we-hack-com-robux.pdfIn PDF document text
    • https://www.audev.com/images/roblox-accont-hacking.pdfIn PDF document text
    • https://reggieslockandkey.com/images/free-robux-hack-today.pdfIn PDF document text
    • http://cmme.it/images/free-knife-code-assasins-roblox.pdfIn PDF document text
    • http://ns1.radiofacil.net/images/can-you-get-free-robux-by-playing-games-on-roblox.pdfIn PDF document text
    • http://unifieo.br/images/all-free-shirt-in-roblox.pdfIn PDF document text
    • http://poltekkeskhjogja.ac.id/images/free-robux-no-human-verification-and-no-downloading-apps.pdfIn PDF document text
    • http://lllaw.eu/images/cheats-for-robux-2021.pdfIn PDF document text
    • http://akademiatenisa.org/images/roblox-csgo-cases-free.pdfIn PDF document text
    • https://masseymotorcars.com/images/can-you-sell-shirts-for-free-in-roblox.pdfIn PDF document text
    • https://www.albisser.ch/images/roblox-hack-jailbreak-julian-juegos.pdfIn PDF document text
    • http://www.copoint.co.uk/images/flob-fun-robux-hack-free-robux-generator.pdfIn PDF document text
    • http://eooe.gr/images/red-boy-cheat-roblox-download.pdfIn PDF document text
    • https://pagadder.com/images/roblox-shirt-template-designs-free.pdfIn PDF document text
    • http://keepcasscountybeautiful.com/images/roblox-fast-speed-hack-script.pdfIn PDF document text
    • http://agroturismoarkaia.com/images/hack-para-roblox-2021-diciembre.pdfIn PDF document text
    • https://www.porthos.it/images/free-account-with-robux-2021.pdfIn PDF document text
    +17 more URL(s)

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_003_off0000853f.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x853F 38960 bytes
SHA-256: 8bc9137526de0e40fb3792c9e622d53c05c85d3a31597ab1792b4b4976537835
font_01_sfnt_off0000d95e.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xD95E 17820 bytes
SHA-256: dc965a99b267b9cd8e3a8daa4dfed07a65bf8a20222f77f810ac283eff535f31