Malicious PDF — malware analysis report

Static analysis result for SHA-256 bc08cc7f93f3fb22…

MALICIOUS

PDF

45.9 KB Created: 2021-04-03 00:00:37 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7) First seen: 2021-10-12
MD5: b37797cf38b819141968e874b6037407 SHA-1: 2526328deac6f3869243867b835ca86be18f0123 SHA-256: bc08cc7f93f3fb22df070a4ba31ffeab3411f1ffaab30ee500345e47440596f7
82 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF document contains numerous links related to Roblox cheats and hacks, with the primary URL pointing to 'roblox-free-account-and-password-2021-with-robux'. The heuristic 'SE_CLIPBOARD_COMMAND_LURE' indicates the document attempts to trick the user into executing commands, likely to download and run a malicious payload. The ML classifier also flagged the PDF as malicious with high confidence.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9434

Heuristics 4

  • Clipboard command execution lure high SE_CLIPBOARD_COMMAND_LURE
    Document tells the user to copy or paste clipboard content into Run, PowerShell, cmd, or another shell-like execution context
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://gaminggenerator.org/app/431946152/roblox-free-account-and-password-2021-with-robux PDF link annotation
    • http://www.lionel-seppoloni.fr/images/roblox-ps3-download-free.pdfIn PDF document text
    • http://www.lycee-langevin-wallon.com/images/roblox-adopt-me-how-to-get-free-ride-potion.pdfIn PDF document text
    • http://www.lycee-langevin-wallon.com/images/kuso-icu-roblox-free-robux.pdfIn PDF document text
    • http://www.pcclawyers.com.au/images/you-promised-my-son-you-would-give-him-free-robux.pdfIn PDF document text
    • https://verdensbarn.no/images/roblox-hacked-face-id.pdfIn PDF document text
    • https://www.utalii.ac.ke/images/how-to-hack-into-any-roblox-account-2021.pdfIn PDF document text
    • http://www.gadanie.lv/images/robux-offers-free.pdfIn PDF document text
    • http://energotestcontrol.ru/images/welcome-to-roblox-account-hacker.pdfIn PDF document text
    • https://tokunfome.com.br/images/roblox-treasure-hunt-simulator-coin-hack.pdfIn PDF document text
    • http://www.fanciullovito.it/images/how-to-make-roblox-ads-for-free.pdfIn PDF document text
    • http://www.fanciullovito.it/images/cheat-roblox-jailbreak-2021.pdfIn PDF document text
    • http://uctovnictvosnv.sk/images/free-robux-hack-2021-android.pdfIn PDF document text
    • https://www.romedia.gr/images/sex-cheat-codes-roblox-sound-id.pdfIn PDF document text
    • http://www.maakherumusic.net/images/free-robux-no-verification-android.pdfIn PDF document text
    • http://www.eurologistiki.gr/images/avatar-roblox-skin-free.pdfIn PDF document text
    • http://www.pcclawyers.com.au/images/how-to-hack-roblox-with-brutis.pdfIn PDF document text
    • https://www.fhccu.com/images/how-to-insert-a-hack-script-into-roblox-game.pdfIn PDF document text
    • https://www.coriglianocalabro.it/images/roblox-hack-money-apk.pdfIn PDF document text
    • http://agrao.in/images/roblox-ro-ghoul-hack-2021.pdfIn PDF document text
    • http://www.cosver.nl/images/hack-blob-sim-2-roblox.pdfIn PDF document text
    • http://www.agri-tech.com.au/images/free-robux-no-human-verification-no-survey-2021.pdfIn PDF document text
    • http://www.actae.gr/images/free-robux-really-works-2021.pdfIn PDF document text
    • https://www.utalii.ac.ke/images/how-to-look-cool-on-roblox-free.pdfIn PDF document text
    • http://svp-steinmaur.ch/images/roblox-how-to-get-free-robux-no-hack.pdfIn PDF document text
    • https://www.fhccu.com/images/how-to-cheat-noclip-in-roblox-2021.pdfIn PDF document text
    • http://www.lionel-seppoloni.fr/images/free-old-roblox-bc-accounts-v3rmillion.pdfIn PDF document text
    • https://www.millatgears.com/images/how-to-get-free-admin-in-any-roblox-game-2021.pdfIn PDF document text
    • https://corbo.ru/images/roblox-players-that-give-free-items.pdfIn PDF document text
    • https://estalagemmonteverde.com.br/images/roblox-com-free-codes.pdfIn PDF document text
    • http://nevesomost.by/images/robux-generatr-hack-2021.pdfIn PDF document text
    • https://consorziocsa-asicaivano.it/images/robux-hack-v6-5-mythical.pdfIn PDF document text
    • https://www.foodsafety.cz/images/how-to-fly-hack-in-tower-of-hell-roblox.pdfIn PDF document text
    • https://www.beaufortcollege.ie/images/everythings-free-roblox-mm2-uncopylocked.pdfIn PDF document text
    • http://www.actae.gr/images/how-to-get-any-car-free-in-jailbrake-roblox.pdfIn PDF document text
    • https://pemadamapi.net/images/roblox-free-robux-hack-2021.pdfIn PDF document text
    • https://eddar.fr/images/roblox-v3rmillion-hacks-youtube.pdfIn PDF document text
    • http://cosver.eu/images/free-roblox-premium.pdfIn PDF document text
    • http://www.hawler.in/images/free-t-shirt-roblox-2021.pdfIn PDF document text
    • http://salantiskis.lt/images/free-rpg-roblox.pdfIn PDF document text
    • http://www.eaapiaria.es/images/roblox-comment-hacker.pdfIn PDF document text
    • https://sitam.co.in/images/secret-working-50k-free-robux-code.pdfIn PDF document text
    • https://www.lavigny.ch/images/cheat-roblox-no-exploit.pdfIn PDF document text
    • http://agrao.in/images/how-to-get-free-robux-easy-on-android.pdfIn PDF document text
    • http://sscclc.edu.ec/images/roblox-free-script-sir-meme.pdfIn PDF document text
    • http://www.tamogatoweb.hu/images/free-hack-engines-for-roblox.pdfIn PDF document text
    • https://www.seeingindependence.org/images/free-robux-game-cards.pdfIn PDF document text
    • http://pa-tanjungselor.go.id/images/hacker-pants-roblox.pdfIn PDF document text
    • https://www.ncscolour.no/images/roblox-cheat-engine-esp.pdfIn PDF document text
    • https://www.academiaanticorrupcion.org/images/roblox-hacks-commands.pdfIn PDF document text
    +2 more URL(s)

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_003_off00005704.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x5704 23456 bytes
SHA-256: 8aaf757267d7252ca0af8fe6cb7bf7e62591765e7a5bc90cddd68334b9882889
font_01_sfnt_off00008b45.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x8B45 19524 bytes
SHA-256: 2232bf923c0c08b7ea1c708ea5dbdeff9ada782e9fce8f4727c80a7d6d22cbb9