Malicious PDF — malware analysis report

Static analysis result for SHA-256 d0c8d2cfef578dbc…

MALICIOUS

PDF

60.6 KB Created: 2021-04-05 21:05:02 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7) First seen: 2021-11-25
MD5: a4329d29eb82b872d36fe2c4b0b72d82 SHA-1: c89053bc8770c54bd63d564b52fea9af32112d59 SHA-256: d0c8d2cfef578dbc7bd4bded1c7c2d0a3785b49b3d704751ea219163d844ee0f
82 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.001 User Execution: Malicious Link

The PDF document contains a lure impersonating Facebook to trick users into clicking a link related to Roblox game cheats. The ML classifier flagged this PDF as malicious, and multiple external URLs were embedded, suggesting a credential phishing or malware distribution attempt. No scripts were extracted, but the presence of embedded URLs and brand impersonation strongly indicates a phishing or social engineering attack.

Machine Learning

  • Nyx PDF Classifier malicious score 0.6193

Heuristics 4

  • Brand-impersonation credential phishing lure high SE_BRAND_CREDENTIAL_PHISH
    Document impersonates a well-known consumer brand and uses account-security / verification language ('unusual activity', 'account on hold', 'verify your account') to steer the reader to a credential-harvesting link. Corroborated by: call-to-action link host does not match the impersonated brand: http://gaminggenerator.org/app/431946152/roblox-mcdonalds-tycoon-cheats.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://gaminggenerator.org/app/431946152/roblox-mcdonalds-tycoon-cheats PDF link annotation
    • http://shahriyarclimb.com/images/claim-free-robux-today.pdfIn PDF document text
    • http://thomas-hartl.at/images/free-gun-locationb-roblox-jail-break.pdfIn PDF document text
    • http://hemmet-strand.dk/images/roblox-skin-coluor-robux-hack-youtube-robuxianyoutube.pdfIn PDF document text
    • https://gzog.pl/images/free-robux-generator-no-survey-2021.pdfIn PDF document text
    • https://osk-sibir.ru/images/free-robux-websites-that-work-2021.pdfIn PDF document text
    • http://ipdrs.org/images/roblox-free-roming-camera.pdfIn PDF document text
    • http://cosver.eu/images/roblox-hack-2021-no-human-verification.pdfIn PDF document text
    • http://www.vktzunami.cz/images/roblox-meepcity-hacked.pdfIn PDF document text
    • http://fradiomas.com/images/hacker-vs-pro-roblox.pdfIn PDF document text
    • http://bufbd.org/images/free-robux-no-password-or-human-verification.pdfIn PDF document text
    • https://bgescc.com/images/free-robux-mac-download.pdfIn PDF document text
    • https://www.wijhalenhetop.nl/images/roblox-password-guessing-hack-download.pdfIn PDF document text
    • http://www.agri-tech.com.au/images/cheat-robux-roblox-2021-free.pdfIn PDF document text
    • https://www.tsdb.com.au/images/free-roblox-keywords.pdfIn PDF document text
    • http://sscclc.edu.ec/images/roblox-cheat-engine-god.pdfIn PDF document text
    • http://loszavera.com/images/roblox-free-robux-gift-card-codes.pdfIn PDF document text
    • https://www.udivadlahotel.cz/images/how-to-hack-any-server-in-roblox.pdfIn PDF document text
    • https://www.lavigny.ch/images/free-supreme-roblox-model.pdfIn PDF document text
    • http://cosver.eu/images/how-to-hack-back-into-your-old-roblox-account.pdfIn PDF document text
    • http://vagency.us/images/roblox-how-to-get-into-paid-access-games-for-free.pdfIn PDF document text
    • https://www.foodsafety.cz/images/roblox-how-to-get-to-be-free-storytellers-ballad.pdfIn PDF document text
    • http://www.peterdejonge.nl/images/sentinel-roblox-hack.pdfIn PDF document text
    • http://jasperfirstumc.com/images/free-item-november-2021-roblox.pdfIn PDF document text
    • https://www.romedia.gr/images/has-my-computer-been-hacked-playing-roblox.pdfIn PDF document text
    • http://scarlier.fr/images/free-admin-roblox-jailbreak.pdfIn PDF document text
    • https://www.fhccu.com/images/roblox-cheat-engine-62-robux-hack.pdfIn PDF document text
    • http://www.vktzunami.cz/images/roblox-alt-delete-hack-2021.pdfIn PDF document text
    • http://hemmet-strand.dk/images/free-roblox-account-over-30-days.pdfIn PDF document text
    • http://genialica.com/images/free-robux-codes-october-2021.pdfIn PDF document text
    • http://vagency.us/images/how-to-hack-the-northern-frontier-roblox.pdfIn PDF document text
    • https://gestionpatrimonial.net/images/nicsterv-roblox-hackers.pdfIn PDF document text
    • http://ce-tsv-nantes.fr/images/roblox-mm2-hack-script.pdfIn PDF document text
    • http://the-specials.ch/images/how-to-make-a-game-on-roblox-for-free.pdfIn PDF document text
    • http://farwesterndistrict.org/images/hack-rapido-roblox.pdfIn PDF document text
    • http://domaizdereva24.ru/images/free-nerd-glasses-roblox.pdfIn PDF document text
    • http://www.boic.nl/images/free-mobile-360-free-robux.pdfIn PDF document text
    • http://76remont-kvartir.ru/images/gaming-tutorials-com-free-robux.pdfIn PDF document text
    • http://only1you.ru/images/roblox-mm2-hack-download.pdfIn PDF document text
    • http://fiur-malermeister.de/images/if-you-have-builders-club-do-you-get-free-robux.pdfIn PDF document text
    • https://pa-waingapu.go.id/images/how-to-hack-into-someone-roblox-account-2021.pdfIn PDF document text
    • http://chjames.com.au/images/how-to-hack-any-tycoon-game-roblox.pdfIn PDF document text
    • http://www.adravietnam.org/images/hacker-prison-life-roblox-2021-pc.pdfIn PDF document text
    • http://geemarco.com/images/the-only-free-robux-game-that-works1.pdfIn PDF document text
    • http://ghegamethu.vn/images/como-tener-ropa-gratis-en-roblox-hack-2021.pdfIn PDF document text
    • https://www.cfdcnv.com/images/no-verification-free-robux-generator.pdfIn PDF document text
    • https://www.beaufortcollege.ie/images/rolblox-robux-hack.pdfIn PDF document text
    • https://estalagemmonteverde.com.br/images/how-to-hack-alone-batle-royale-with-roblox.pdfIn PDF document text
    • https://pa-waingapu.go.id/images/www-roblox-com-free-clothes.pdfIn PDF document text
    • https://pemadamapi.net/images/hack-web-tool-roblox-descargar-gratis.pdfIn PDF document text
    +9 more URL(s)

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_003_off000081f5.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x81F5 25364 bytes
SHA-256: 5d87d41090ed7ac839f7050f4006ef56be4f3348b041a044f65067d5b9c866c5
font_01_sfnt_off0000bc2e.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xBC2E 3884 bytes
SHA-256: 40b61f8938bd710dc29dc58ba3fde91c245a6a69596ec569b4d27c769ca417cf
font_02_sfnt_off0000c8d5.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xC8D5 18400 bytes
SHA-256: f0625cb2eca5594ca2fe2d939c9f2148d81ad4c5b112541bf10b513f6d13fdb4