Malicious PDF — malware analysis report

Static analysis result for SHA-256 d537f1c87034944c…

MALICIOUS

PDF

52.2 KB Created: 2021-04-06 11:27:22 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7) First seen: 2026-06-04
MD5: 56b0c62fb1882b3199f9412a150c4ea0 SHA-1: aac3514743a6ab1b793a89ee61efe5c777111c6d SHA-256: d537f1c87034944c02ceb389059db53d84abac0a2bbe79b4617bfca3fd27205a
110 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF document contains heuristics indicating it is a lure for a game hack, specifically linking to 'enigmagenerator.com'. The document body, though partially corrupted, contains multiple URLs that also point to similar game-related lures. The primary attack vector appears to be social engineering via a malicious attachment, directing users to potentially harmful websites.

Machine Learning

  • Nyx PDF Classifier malicious score 0.8896

Heuristics 5

  • PDF links to a 'free generator / game hack' redirector critical PDF_GAME_HACK_REDIRECT_LURE
    PDF's clickable action targets a redirector of the form /app/<id>/<slug>-game-hack — the landing-page shape of a large SEO 'free spins / generator / game hack' lure family that funnels victims through rotating disposable hosts to a malware/scam payload. The multi-link variants also trip ML/link-farm rules; this catches the single-link variants that otherwise score clean. CRITICAL on its own: the /app/<id>/<slug>-game-hack path shape is unambiguous scam infra, and the host rotates so a host-list match can't be relied on.
  • Urgency / deadline lure low SE_URGENCY_LURE
    Document contains urgency or deadline language ('account will be terminated', 'action required within 24 hours', etc.) — useful context, but low-signal without other findings
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://enigmagenerator.com/app/431946152/roblox-game-hack PDF link annotation
    • http://sealysports.com/images/free-candy-game-roblox.pdfIn PDF document text
    • http://dennemaat.nl/images/easy-free-robux-todaycom.pdfIn PDF document text
    • http://swibome.nl/images/free-robux-codes-no-survey-no-download.pdfIn PDF document text
    • http://drozle.lt/images/roblox-free-shirts-and-pants-2021.pdfIn PDF document text
    • http://rushxpress.de/images/phantom-forces-roblox-hack-aimbot.pdfIn PDF document text
    • http://cleananddecluttered.com/images/roblox-aimbot-using-cheat-engine.pdfIn PDF document text
    • https://www.inova-cuisine.fr/images/roblox-bee-swarm-simulator-super-mega-hack.pdfIn PDF document text
    • https://www.audev.com/images/triga-cheat-roblox.pdfIn PDF document text
    • http://vipservice-bg.com/images/real-robux-hacks.pdfIn PDF document text
    • http://cleanteclogistics.com/images/free-robux-codes-2021-march.pdfIn PDF document text
    • http://evp-sanorlenok.ru/images/roblox-jailbreak-cheats-noclip.pdfIn PDF document text
    • http://www.tamogatoweb.hu/images/roblox-free-unlimited-robux-glitch.pdfIn PDF document text
    • http://sscclc.edu.ec/images/free-robux-codes-2021-december.pdfIn PDF document text
    • https://www.showalterpropertyconsultants.com/images/how-free-robux-codes.pdfIn PDF document text
    • http://jackson-pr.com/images/khaos-free-robux-pastebin.pdfIn PDF document text
    • http://www.occquimica.com.br/images/rbx-free-robux.pdfIn PDF document text
    • https://www.cosmosdawn.net/images/how-to-make-money-on-roblox-for-free.pdfIn PDF document text
    • https://osk-sibir.ru/images/play-roblox-free-robux.pdfIn PDF document text
    • http://huananhai.net/images/roblox-exploit-executor-free.pdfIn PDF document text
    • http://evro-okna.net/images/get-free-robux-live.pdfIn PDF document text
    • https://socialvalue.gr/images/hot-get-free-robux.pdfIn PDF document text
    • http://bullyinformate.org/images/how-to-get-robux-fast-free.pdfIn PDF document text
    • https://www.udivadlahotel.cz/images/play-roblox-on-google-for-free.pdfIn PDF document text
    • http://domaizdereva24.ru/images/como-hackear-roblox-2021-en-pc.pdfIn PDF document text
    • https://verdensbarn.no/images/roblox-dungeon-quest-get-unlimited-gold-and-free-vip.pdfIn PDF document text
    • http://evp-sanorlenok.ru/images/roblox-hacks-for-robux-only-admins-should-know.pdfIn PDF document text
    • http://goldwing-shop.ru/images/how-to-hack-someone-in-roblox-2021.pdfIn PDF document text
    • http://acktivities.com/images/hack-roblox-prion-life.pdfIn PDF document text
    • https://www.manisoft.ir/images/roblox-free-hack-injector-2021.pdfIn PDF document text
    • http://naturschutzgossau-zh.ch/images/robux-cheat-engine-66.pdfIn PDF document text
    • https://www.fhccu.com/images/basic-roblox-lua-programming-book-free.pdfIn PDF document text
    • http://moto98.com/images/free-stuff-on-roblox-2021.pdfIn PDF document text
    • https://pagadder.com/images/roblox-how-to-get-free-robux-no-hacks-2021.pdfIn PDF document text
    • http://ecoleduchat-grenoble.fr/images/roblox-one-piece-grand-trial-hack.pdfIn PDF document text
    • https://gimnaziya6.kz/images/jailbreak-hacks-for-roblox-projec-alph.pdfIn PDF document text
    • http://dermaceutic.co.uk/images/roblox-build-tools-hack.pdfIn PDF document text
    • http://infoagronomia.com.ar/images/drawing-anime-on-roblox-free-draw.pdfIn PDF document text
    • https://my-private-intendant.com/images/play-roblox-free-robux.pdfIn PDF document text
    • https://bancroftandsons.com/images/roblox-jailbreak-hack-android.pdfIn PDF document text
    • http://chjames.com.au/images/roblox-cheats-google-chrome.pdfIn PDF document text
    • http://medimacs.eu/images/hack-this-site-roblox.pdfIn PDF document text
    • http://bibliotheque-perrigny-les-dijon.fr/images/how-to-hack-roblox-robux-easy.pdfIn PDF document text
    • http://sealysports.com/images/earn-free-robux-fast-and-easy.pdfIn PDF document text
    • http://www.taxiaparis.fr/images/hacking-into-a-online-account-roblox.pdfIn PDF document text
    • http://www.studiodamato.it/images/robux-maniac-free-catlog-bookmarks.pdfIn PDF document text
    • http://5346000.com/images/pastebin-roblox-free-obc.pdfIn PDF document text
    • https://www.coriglianocalabro.it/images/how-to-hack-roblox-using-cheat-engine.pdfIn PDF document text
    • http://forsazh-51.ru/images/roblox-lego-hack-2021.pdfIn PDF document text
    • http://pa-bengkulukota.go.id/images/free-robux-cards-2021.pdfIn PDF document text
    +16 more URL(s)

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00006f8b.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x6F8B 25796 bytes
SHA-256: a423f55de92fd060c44c0a42b3ff3274878a56dd67492c3fe58797028cd8c309
font_01_sfnt_off0000a8d3.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xA8D3 18036 bytes
SHA-256: 58deeea8fa1a3671b0a86aa185249c266279c74cce5ae02785c8d56c2a8da57f