Malicious PDF — malware analysis report

Static analysis result for SHA-256 da9559f813f8dfef…

MALICIOUS

PDF

59.7 KB Created: 2021-04-06 06:24:04 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7) First seen: 2021-10-24
MD5: 080703fb171da64e3c56a5fc1caf1803 SHA-1: c67ea0f8d9f039b308d2f9ab73fb20719bb479d7 SHA-256: da9559f813f8dfef05ffba66e8801240430dcbeac24ab267a03311b58041860e
142 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1203 Exploitation for Client Execution

The PDF document contains a lure related to 'Free Robux Code For Roblox' and impersonates Amazon, directing users to a malicious URL. The heuristic firings indicate this is a credential phishing attempt disguised as a game hack. While no scripts were explicitly extracted, the PDF structure and embedded links suggest potential for exploitation or redirection to malicious content.

Machine Learning

  • Nyx PDF Classifier malicious score 0.6193

Heuristics 5

  • PDF links to a 'free generator / game hack' redirector critical PDF_GAME_HACK_REDIRECT_LURE
    PDF's clickable action targets a redirector of the form /app/<id>/<slug>-game-hack — the landing-page shape of a large SEO 'free spins / generator / game hack' lure family that funnels victims through rotating disposable hosts to a malware/scam payload. The multi-link variants also trip ML/link-farm rules; this catches the single-link variants that otherwise score clean. CRITICAL on its own: the /app/<id>/<slug>-game-hack path shape is unambiguous scam infra, and the host rotates so a host-list match can't be relied on.
  • Brand-impersonation credential phishing lure high SE_BRAND_CREDENTIAL_PHISH
    Document impersonates a well-known consumer brand and uses account-security / verification language ('unusual activity', 'account on hold', 'verify your account') to steer the reader to a credential-harvesting link. Corroborated by: call-to-action link host does not match the impersonated brand: http://enigmagenerator.com/app/431946152/roblox-game-hack.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://enigmagenerator.com/app/431946152/roblox-game-hack PDF link annotation
    • http://southernhills-golf.com/images/are-any-boys-free-in-roblox.pdfIn PDF document text
    • http://www.pro-futuro.eu/images/roblox-hacks-case-clicker.pdfIn PDF document text
    • http://e-mailservis.cz/images/hack-roblox-high-school.pdfIn PDF document text
    • http://www.nielsen2u.dk/images/robux-hack-download-android.pdfIn PDF document text
    • https://www.porthos.it/images/console-hack-free-hats-roblox.pdfIn PDF document text
    • https://www.stkdb.cz/images/tiroblox-cheats-for-robux-and-tix-robloxcheatsnet-roblox.pdfIn PDF document text
    • http://www.sanjosedeminas.gob.ec/images/how-to-get-2021-robux-for-free-2021.pdfIn PDF document text
    • http://ims-77.fr/images/robux-hack-apps.pdfIn PDF document text
    • http://pa-tanjungselor.go.id/images/how-to-get-roblox-hack-for-apocoleps-rizing.pdfIn PDF document text
    • https://plumbingmedics.com/images/free-glitches-roblox.pdfIn PDF document text
    • https://rietenwinkel.nl/images/roblox-saut-infini-cheat.pdfIn PDF document text
    • http://stomatolog-choszczno.pl/images/roblox-cheats-admin-commands.pdfIn PDF document text
    • http://www.lycee-langevin-wallon.com/images/unpatchable-free-robux-made-by-robuxian.pdfIn PDF document text
    • http://zarinnameh.ir/images/diamond-roblox-hack.pdfIn PDF document text
    • http://www.hawler.in/images/how-to-get-roblox-jailbreak-hacka.pdfIn PDF document text
    • https://www.arquetopia.org/images/free-roblox-clothes-celular.pdfIn PDF document text
    • http://agroturismoarkaia.com/images/roblox-car-crusher-28-hack.pdfIn PDF document text
    • http://arthakranti.org/images/roblox-free-hoverboard.pdfIn PDF document text
    • https://fkg.usu.ac.id/images/cerberus-hack-program-roblox.pdfIn PDF document text
    • https://rincondelentrenador.com/images/kuso-ico-roblox-free-robux.pdfIn PDF document text
    • http://santjoandelesabadesses.cat/images/roblox-rc7-cracked-free-download.pdfIn PDF document text
    • http://acktivities.com/images/35-000-robux-for-free.pdfIn PDF document text
    • https://springhorn-reisen.de/images/roblox-case-clicker-cheats.pdfIn PDF document text
    • http://www.nicoifruttidelchicco.org/images/keyon-air-hack-is-model-roblox.pdfIn PDF document text
    • https://www.udivadlahotel.cz/images/how-to-hack-roblox-by-using-inspect.pdfIn PDF document text
    • http://joshherman.com/images/roblox-mad-paintball-2-speed-hack.pdfIn PDF document text
    • https://www.hotschool.com.au/images/roblox-hack-download-jailbreak.pdfIn PDF document text
    • https://www.fhccu.com/images/roblox-wins-hack-boxing-simulator-2.pdfIn PDF document text
    • http://www.nielsen2u.dk/images/easy-hacks-of-money-for-rocitizens-roblox.pdfIn PDF document text
    • http://dos.most.gov.la/images/how-to-hack-on-roblox-apocalypse-rising-2021.pdfIn PDF document text
    • https://corbo.ru/images/roblox-meep-city-cheats.pdfIn PDF document text
    • http://www.fanciullovito.it/images/free-adopt-me-flying-potion-roblox-codes.pdfIn PDF document text
    • http://xn--59-6kcusgqlmfgen3m.xn--p1ai/images/strucid-roblox-hacks-aimbot.pdfIn PDF document text
    • https://tokunfome.com.br/images/free-robux-generator-no-human-verification-pc.pdfIn PDF document text
    • http://www.pcclawyers.com.au/images/roblox-hack-ultra-speed.pdfIn PDF document text
    • http://eliteprofkosmetik.com.ua/images/fray-roblox-hack-script-pastebin.pdfIn PDF document text
    • http://jbm-constructions.com/images/free-robux-boi.pdfIn PDF document text
    • https://vtvvaals.nl/images/roblox-promo-codes-for-robux-free.pdfIn PDF document text
    • https://www.ferienhausdirektkroatien.de/images/cheat-block-piece-roblox.pdfIn PDF document text
    • http://principessalialaofegypt.com/images/cheat-roblox-madcity-money.pdfIn PDF document text
    • http://www.eurosan1.ba/images/free-shirt-templates-for-roblox.pdfIn PDF document text
    • http://cristalysoptic.com/images/what-to-do-when-you-are-hacked-on-roblox.pdfIn PDF document text
    • https://www.beaufortcollege.ie/images/how-to-get-free-robux-for-free-in-2-mins.pdfIn PDF document text
    • http://dermaceutic.co.uk/images/free-robux-codes-2021-no-verification.pdfIn PDF document text
    • http://sexythings.gr/images/cheat-dbr-roblox-ccv3-2021.pdfIn PDF document text
    • http://bkd1.balikpapan.go.id/images/how-to-hack-accounts-on-roblox-2021.pdfIn PDF document text
    • https://rincondelentrenador.com/images/how-to-hack-anyone-on-roblox.pdfIn PDF document text
    • http://horsa18.ru/images/how-to-get-free-robux-in-iphone.pdfIn PDF document text
    • http://petarda.hu/images/hacks-para-infinity-anime-roblox.pdfIn PDF document text
    +15 more URL(s)

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_003_off000082e3.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x82E3 25884 bytes
SHA-256: 9c53821c6ee8c7b362f4d522ad852e160d38092fa4550c6239dcab1f3ae70893
font_01_sfnt_off0000be4f.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xBE4F 2832 bytes
SHA-256: 77ae1c4cffa647a8fd533dfa4102e94364989f9e80b9cd131876e9d1005899a2
font_02_sfnt_off0000c800.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xC800 17496 bytes
SHA-256: 8b83c923139afe7a6253801a2d7ac740d6cbff375e2111aeb0c61b091aa8d7b9