Malicious PDF — malware analysis report

Static analysis result for SHA-256 d3d8dc4776f5947f…

MALICIOUS

PDF

51.8 KB Created: 2021-04-06 12:28:19 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7) First seen: 2021-09-23
MD5: f3756bd198eef89d5a46efbafda8f091 SHA-1: 330b5b4d91edfc4eeb3c904b53c907f34bbdce55 SHA-256: d3d8dc4776f5947f47c849a5092fb8328f33c867db4011ecd133d2deada53697
82 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

This PDF document was flagged as malicious by an ML classifier. The file routes users through malicious redirector infrastructure and presents a deceptive download button. Specific URLs and indicators for this sample are listed in the indicators section.

Machine Learning

  • Nyx PDF Classifier malicious score 0.8896

Heuristics 4

  • PDF links to a 'free generator / game hack' redirector high PDF_GAME_HACK_REDIRECT_LURE
    PDF's clickable action targets a redirector of the form /app/<id>/<slug>-game-hack — the landing-page shape of a large SEO 'free spins / generator / game hack' lure family that funnels victims through rotating disposable hosts to a malware/scam payload. The multi-link variants also trip ML/link-farm rules; this catches the single-link variants that otherwise score clean.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://enigmagenerator.com/app/431946152/roblox-game-hack PDF link annotation
    • http://beer-holzhaus.ch/images/roblox-bubblegum-simulator-how-to-get-the-tank-for-free.pdfIn PDF document text
    • http://horsa18.ru/images/white-shirt-roblox-free.pdfIn PDF document text
    • https://newenglandafs.com/images/free-to-use-roblox-shirt-new.pdfIn PDF document text
    • http://imp.lg.ua/images/free-to-use-roblox-ads.pdfIn PDF document text
    • http://manfeld.dk/images/free-rolls-hack-elemental-wars-roblox.pdfIn PDF document text
    • http://axia-verlag.at/images/roblox-mobile-hacks-for-free-robux.pdfIn PDF document text
    • http://smoothjazzclub.net/images/how-to-change-your-skin-in-roblox-for-free.pdfIn PDF document text
    • http://ehma.com/images/free-robux-roblox-music-id.pdfIn PDF document text
    • http://www.vktzunami.cz/images/redeem-roblox-promotions-free.pdfIn PDF document text
    • http://junktiquecollector.com/images/roblox-hack-exploit-spvx-2021.pdfIn PDF document text
    • http://halitbayramoglu.com.tr/images/roblox-free-robux-hack-no-verification.pdfIn PDF document text
    • https://kunstmalen.ch/images/utiliser-manette-free-roblox.pdfIn PDF document text
    • https://www.cpnf.ch/images/roblox-mm2-hack-para-tener-godly-2021.pdfIn PDF document text
    • http://www.das-kinderzimmer.net/images/lazy-blocks-com-free-robux.pdfIn PDF document text
    • http://yogaschooldecypres.be/images/chat-hack-10-roblox.pdfIn PDF document text
    • http://portal.crfsp.org.br/images/roblox-avatar-for-hackers.pdfIn PDF document text
    • https://billiekawende.com/images/free-robux-rbxboost.pdfIn PDF document text
    • http://kfz-ilg.com/images/free-robux-no-surveys-no-human-verification.pdfIn PDF document text
    • http://bluediffusion.it/images/free-money-generator-cbr-roblox.pdfIn PDF document text
    • https://www.najeebqasmi.com/images/t-shirt-hacker-roblox.pdfIn PDF document text
    • http://salantiskis.lt/images/how-to-get-free-tix-on-roblox-without-hacks.pdfIn PDF document text
    • http://britishcomics.com/images/how-to-get-free-roblox-money-hack.pdfIn PDF document text
    • https://lobergetart.se/images/youtube-have-to-get-free-robux.pdfIn PDF document text
    • http://www.isril.it/images/roblox-hack-adopt-me-2021.pdfIn PDF document text
    • http://www.rezbb.sk/images/how-to-get-free-robux-and-keep-it-youtube.pdfIn PDF document text
    • https://www.millatgears.com/images/roblox-how-to-get-in-bloxburg-for-free.pdfIn PDF document text
    • https://www.sitiwebjoomla.it/images/free-robux-generator-real.pdfIn PDF document text
    • http://www.gadanie.lv/images/1k-robux-hack.pdfIn PDF document text
    • https://www.elevage-chiot.fr/images/hack-de-roblox-para-todos-los-juegos.pdfIn PDF document text
    • https://www.air-shop.cz/images/shirt-free-roblox.pdfIn PDF document text
    • http://iluvlocalplaces.com/images/hack-de-invisibilidad-mega-roblox.pdfIn PDF document text
    • http://behsanroshd.com/images/how-to-get-robux-for-free-fast-and-easy.pdfIn PDF document text
    • http://tehergumi.hu/images/free-funny-outfits-roblox.pdfIn PDF document text
    • http://energotestcontrol.ru/images/every-roblox-cheat.pdfIn PDF document text
    • https://www.air-shop.cz/images/free-mermaid-halo-roblox-royale-high.pdfIn PDF document text
    • http://serviio.org/images/robloxgiveaway-xyz-hack-robux.pdfIn PDF document text
    • https://gafaseo.com/images/roblox-synapse-x-download-free.pdfIn PDF document text
    • https://www.linzgau-kjh.de/images/shinobi-life-roblox-hack-onyx-2021.pdfIn PDF document text
    • https://icefuture.ru/images/free-superhero-roblox.pdfIn PDF document text
    • http://taskcyg.nl/images/vechile-simulator-roblox-hack.pdfIn PDF document text
    • http://echosvoix.ch/images/how-to-hack-into-a-roblox-acount.pdfIn PDF document text
    • https://www.anagoria.com/images/roblox-free-robux-codes-card.pdfIn PDF document text
    • http://papec.ir/images/roblox-cheat-engine-64-speed-hack.pdfIn PDF document text
    • http://posterprintshop.nl/images/robux-generator-no-pasword-no-hack.pdfIn PDF document text
    • https://www.porthos.it/images/www-roblox-com-sign-up-for-free.pdfIn PDF document text
    • https://www.audipec.com.br/images/free-robux-generator-2021-hack.pdfIn PDF document text
    • http://septik-centr76.ru/images/1x1x1x1-roblox-hacker.pdfIn PDF document text
    • http://escolaarboc.cat/images/how-to-hack-a-roblox-account-june-2021.pdfIn PDF document text
    • https://www.iadh.bi/images/get-free-robux-no-download-no-waiting.pdfIn PDF document text
    +12 more URL(s)

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_003_off00006da8.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x6DA8 25976 bytes
SHA-256: 591cd0b304b1fe6ce220683b71aa08d553f87b60303c2ef2c2513a3b13c24470
font_01_sfnt_off0000a840.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xA840 17704 bytes
SHA-256: bb85531d64b185a9429431262b6b83b58de7001551b96e4d3936e2f006a6b8e0