Malicious PDF — malware analysis report

Static analysis result for SHA-256 ce939567db64820c…

MALICIOUS

PDF

60.7 KB Created: 2021-04-06 01:47:19 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7) First seen: 2021-10-01
MD5: bdbb17075bd80011c7c2882407034f41 SHA-1: 1eda2f396108b43478b9deebdfba6d998345988b SHA-256: ce939567db64820cd35ce3c38d2be4b9f26f78cdda2073b07cc3ca24e71138c8
82 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

This PDF document was flagged as malicious by an ML classifier. It uses a password-protected-archive lure. The file presents a deceptive download button. Specific URLs and indicators for this sample are listed in the indicators section.

Machine Learning

  • Nyx PDF Classifier malicious score 0.6193

Heuristics 4

  • Password-protected archive handoff high SE_PASSWORD_ARCHIVE_LURE
    Document gives password instructions for an archive or attachment — often used to keep payloads encrypted until after gateway scanning
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://gaminggenerator.org/app/431946152/2021-robux-on-robux-free PDF link annotation
    • http://safeandsecurelocksmith.ca/images/free-admin-roblox-jailbreak.pdfIn PDF document text
    • https://www.europap.cz/images/este-es-el-unico-hack-de-robux-funcionando.pdfIn PDF document text
    • https://technospektr.com.ua/images/roblox-mining-sim-hack-2021.pdfIn PDF document text
    • http://www.lionel-seppoloni.fr/images/free-robux-on-phone-2021.pdfIn PDF document text
    • http://erntefest2016.de/images/free-interview-in-roblox-studio.pdfIn PDF document text
    • http://ddsadler.net/images/roblox-hack-bugmenot.pdfIn PDF document text
    • https://www.lavigny.ch/images/how-to-hack-roblox-accounts-for-robux.pdfIn PDF document text
    • http://halal-center.ru/images/how-to-hack-admin-on-roblox-without-cheat-engine.pdfIn PDF document text
    • http://sscclc.edu.ec/images/free-roblox-gift-cards-2021.pdfIn PDF document text
    • https://www.devries-group.de/images/free-robux-apk-modapkdown.pdfIn PDF document text
    • http://altc.de/images/there-is-no-way-to-get-free-robux.pdfIn PDF document text
    • https://itv-grabungen.de/images/hack-robar-cuentas-de-roblox-pastebin.pdfIn PDF document text
    • https://verdensbarn.no/images/how-to-tell-if-your-roblox-account-got-hacked.pdfIn PDF document text
    • http://5346000.com/images/free-robux-hack-no-survey-no-human-verification-2021.pdfIn PDF document text
    • http://gamixpaliwa.pl/images/the-plaza-roblox-money-cheat.pdfIn PDF document text
    • https://accord.kiev.ua/images/roblox-royale-high-diamond-hack-no-human-verification.pdfIn PDF document text
    • https://proviant.kz/images/how-to-hack-someone-on-roblox.pdfIn PDF document text
    • http://cleananddecluttered.com/images/free-robux-promo-codes-2021-not-expired-november.pdfIn PDF document text
    • http://lillysonthelake.com/images/cheats-for-retail-tycoon-roblox.pdfIn PDF document text
    • http://icomsolutions.com.au/images/roblox-hacks-download-pc.pdfIn PDF document text
    • http://xn--80aeb7bbceeegc.xn--p1ai/images/how-to-get-free-robux-2021-june.pdfIn PDF document text
    • http://www.art-concept.gr/images/deleting-baseplate-roblox-hack.pdfIn PDF document text
    • https://fkg.usu.ac.id/images/how-to-get-free-robux-by-watching-a-video.pdfIn PDF document text
    • http://e-mailservis.cz/images/roblox-games-that-you-can-play-online-for-free.pdfIn PDF document text
    • http://www.actae.gr/images/how-to-get-a-free-roblox-necklace.pdfIn PDF document text
    • https://luminouswisdom.org/images/how-to-hack-robux-using-inspect-element-2021.pdfIn PDF document text
    • https://www.stkdb.cz/images/how-to-get-robux-for-free-real.pdfIn PDF document text
    • http://www.pacoestrada.it/images/super-power-training-simulator-roblox-cheats.pdfIn PDF document text
    • http://www.brtes.com/images/killa-in-kalahari-sirius-mashup-copyright-free-roblox.pdfIn PDF document text
    • http://www.lycee-langevin-wallon.com/images/roblox-hack-2021-september.pdfIn PDF document text
    • http://www.torvet11.dk/images/how-to-cheat-on-boku-no-roblox.pdfIn PDF document text
    • http://apcupschennai.com/images/roblox-account-stealing-hack.pdfIn PDF document text
    • http://edelektronarzedzia.pl/images/free-roblox-accounts-with-robux-list.pdfIn PDF document text
    • https://komakinosite.jp/images/free-robux-content-deleted.pdfIn PDF document text
    • http://svp-steinmaur.ch/images/roblox-robux-credit-card-free-2021.pdfIn PDF document text
    • https://www.wildpark-johannismuehle.de/images/roblox-robux-hack-no-download-no-survey-no-human-verification.pdfIn PDF document text
    • http://iluvlocalplaces.com/images/real-free-robux-generator-no-human-verification.pdfIn PDF document text
    • https://www.ncscolour.no/images/free-roblox-stuff-blue-hood.pdfIn PDF document text
    • http://m-sv.net/images/como-hackear-uma-conta-no-roblox.pdfIn PDF document text
    • https://technospektr.com.ua/images/roblox-grab-knife-hack.pdfIn PDF document text
    • http://moralcenter.or.th/images/free-roblox-paddwords-cracker.pdfIn PDF document text
    • https://www.cpnf.ch/images/free-40-robux-survey.pdfIn PDF document text
    • http://www.torvet11.dk/images/free-resell-roblox.pdfIn PDF document text
    • https://www.sitiwebjoomla.it/images/roblox-hacks-lua-vs-lua-c.pdfIn PDF document text
    • http://aiyta.com/images/free-robux-just-email-verification-and-done.pdfIn PDF document text
    • https://www.fhccu.com/images/roblox-free-robux-event.pdfIn PDF document text
    • http://modlingua.com/images/cheat-codes-roblox-solar-strike.pdfIn PDF document text
    • http://escolaarboc.cat/images/five-roblox-games-that-give-free-robux.pdfIn PDF document text
    • http://www.copoint.co.uk/images/roblox-typical-colors-2-hack-script.pdfIn PDF document text
    +16 more URL(s)

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_003_off000082af.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x82AF 26920 bytes
SHA-256: a58e86fd601f18d27f93ba789d226c896be18dd5d3e31773c5a8673b2e63b6db
font_01_sfnt_off0000c153.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xC153 2848 bytes
SHA-256: 4737c2778a085e0cb49e73f3b054b1a71e3f40720d213b4bfda97f95a31bfbf1
font_02_sfnt_off0000cb14.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xCB14 17812 bytes
SHA-256: b977d5676b809c42312ef5f7103d08853d9afbeb731f90f3b13b399a89ae5b16