Malicious PDF — malware analysis report

Static analysis result for SHA-256 baeb20711d154e7f…

MALICIOUS

PDF

58.4 KB Created: 2021-04-05 19:43:44 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7) First seen: 2021-09-23
MD5: 05820409c916391adbc75139df3e747a SHA-1: 6b65d940667b13fb736bf8343a71f519d69fbe9e SHA-256: baeb20711d154e7f3e231d2008ecdc8ea3ffbb7a41a3ff3683030f6e51d73155
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious File

This PDF document was flagged as malicious by an ML classifier. It uses brand-impersonation credential phishing and an urgency-based lure. The file presents a deceptive download button. Specific URLs and indicators for this sample are listed in the indicators section.

Machine Learning

  • Nyx PDF Classifier malicious score 0.7795

Heuristics 5

  • Brand-impersonation credential phishing lure high SE_BRAND_CREDENTIAL_PHISH
    Document impersonates a well-known consumer brand and uses account-security / verification language ('unusual activity', 'account on hold', 'verify your account') to steer the reader to a credential-harvesting link. Corroborated by: call-to-action link host does not match the impersonated brand: http://gaminggenerator.org/app/431946152/free-robux-no-human-verification-easy.
  • Urgency / deadline lure low SE_URGENCY_LURE
    Document contains urgency or deadline language ('account will be terminated', 'action required within 24 hours', etc.) — useful context, but low-signal without other findings
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://gaminggenerator.org/app/431946152/free-robux-no-human-verification-easy PDF link annotation
    • http://legs11.co.za/images/free-robux-using-pastebin.pdfIn PDF document text
    • https://corbo.ru/images/free-4now-info-roblox.pdfIn PDF document text
    • http://abst-brandschutztechnik.at/images/how-to-get-free-builders-club-on-roblox-on-phone.pdfIn PDF document text
    • https://www.fhccu.com/images/free-computer-core-roblox.pdfIn PDF document text
    • http://evro-okna.net/images/free-robux-games-that-work-2021.pdfIn PDF document text
    • https://www.u-pin-it.com/images/how-to-hack-roblox-like-a-boss.pdfIn PDF document text
    • http://www.pcclawyers.com.au/images/roblox-trade-hangout-hack.pdfIn PDF document text
    • https://www.stayon.no/images/resourcly-cf-free-robux.pdfIn PDF document text
    • https://www.ghknights.org/images/how-to-hack-musical-chairs-in-roblox.pdfIn PDF document text
    • http://selectionspdf.fr/images/client-hack-roblox-2021-download.pdfIn PDF document text
    • http://pia2000.net/images/free-jordan-shirt-roblox.pdfIn PDF document text
    • http://interpretation-dessins-enfants.net/images/apps-that-will-give-you-free-robux.pdfIn PDF document text
    • http://joshherman.com/images/how-to-hack-into-somones-account-roblox.pdfIn PDF document text
    • http://www.fanciullovito.it/images/hacker-destruye-la-ciudad-roblox-pokemon-go-miannn.pdfIn PDF document text
    • http://www.teapotjewelry.com/images/new-free-items-on-roblox-promocode-november-2021.pdfIn PDF document text
    • http://vipservice-bg.com/images/cheats-and-codes-for-roblox-for-pc.pdfIn PDF document text
    • https://semanasantacehegin.com/images/robux-free-ohne-handynummer.pdfIn PDF document text
    • http://greenoase.be/images/inside-the-world-of-roblox-free.pdfIn PDF document text
    • http://poltekkeskhjogja.ac.id/images/roblox-cheats-for-pc.pdfIn PDF document text
    • https://socialvalue.gr/images/admin-hack-download-roblox.pdfIn PDF document text
    • http://www.les2alpes-location.com/images/cheat-engine-67-on-roblox.pdfIn PDF document text
    • http://www.remiauclair.fr/images/roblox-cheat-engine-table-download.pdfIn PDF document text
    • https://pneukalousek.cz/images/hack-para-roblox-hack-exploit.pdfIn PDF document text
    • http://mydevice.com.au/images/tradelands-roblox-hack.pdfIn PDF document text
    • https://gabrieliassociati.com/images/efree-robux-hack-toold.pdfIn PDF document text
    • https://pemadamapi.net/images/roblox-hack-script-impact.pdfIn PDF document text
    • http://news123.it/images/como-tener-robux-gratis-sin-hacks.pdfIn PDF document text
    • http://www.torvet11.dk/images/assassin-always-jumping-hack-roblox.pdfIn PDF document text
    • https://www.osoc.com/images/how-to-hack-roblox-mad-paintball-2.pdfIn PDF document text
    • http://fairwaygolftravel.co.uk/images/free-h-robux.pdfIn PDF document text
    • https://corbo.ru/images/roblox-free-hat-pastebin.pdfIn PDF document text
    • https://www.academiaanticorrupcion.org/images/how-to-download-roblox-cheats.pdfIn PDF document text
    • https://verdensbarn.no/images/free-items-with-inspect-roblox.pdfIn PDF document text
    • http://j-cook.pro/images/free-robux-codes-2021-june.pdfIn PDF document text
    • https://www.europap.cz/images/como-descargar-hack-para-roblox-de-robux.pdfIn PDF document text
    • http://safeandsecurelocksmith.ca/images/comment-avoir-des-robux-gratuit-hack.pdfIn PDF document text
    • http://vagency.us/images/roblox-hack-kill-script.pdfIn PDF document text
    • https://reggieslockandkey.com/images/carlox-hack-de-la-sable-laser-de-goku-oscuro-roblox.pdfIn PDF document text
    • http://aeroclub-kaernten.at/images/free-robux-games-no-scam.pdfIn PDF document text
    • http://poltekkeskhjogja.ac.id/images/how-to-get-free-robux-dylan.pdfIn PDF document text
    • http://fiur-malermeister.de/images/obby-for-free-robux.pdfIn PDF document text
    • https://kunstmalen.ch/images/liberty-county-roblox-free.pdfIn PDF document text
    • http://www.hotelcomelico.it/images/free-roblox-cards-youtube.pdfIn PDF document text
    • http://aimp-market.ru/images/how-do-you-get-free-robux-2021.pdfIn PDF document text
    • https://gryps.de/images/free-promotion-codes-roblox.pdfIn PDF document text
    • http://salantiskis.lt/images/roblox-how-to-get-any-gamepass-for-free-2021.pdfIn PDF document text
    • http://www.compusiteinc.com/images/how-to-change-the-name-of-free-morphs-on-roblox.pdfIn PDF document text
    • http://eooe.gr/images/how-to-get-a-hack-client-for-roblox.pdfIn PDF document text
    • http://www.hotelcomelico.it/images/free-robux-no-password-or-username-may.pdfIn PDF document text
    +15 more URL(s)

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_003_off0000837b.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x837B 27420 bytes
SHA-256: d18a1cb2c22e08b0ab9701aa7a6614b10c77f5006e25ce21aaa68c348f91b254
font_01_sfnt_off0000befd.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xBEFD 18928 bytes
SHA-256: 504ec56a4b35f1f9d2bf730151666c4333a59b41ebe8ba6b1cc4fbc06f1a9685