Malicious PDF — malware analysis report

Static analysis result for SHA-256 df714f6bc2c91660…

MALICIOUS

PDF

55.0 KB Created: 2021-04-07 03:04:37 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7) First seen: 2021-09-17
MD5: a30dde4e24c05756f1230c083f4a0783 SHA-1: d86aea1453855f99c8736f308364cc6fde6f873c SHA-256: df714f6bc2c91660635f2e783bef15ef52bdb793e0e4efb35768a44f0b8af59b
122 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains multiple heuristics indicating a lure for game hacks, specifically targeting Roblox. The primary URL, https://enigmagenerator.com/app/431946152/roblox-game-hack, is directly linked to a 'free generator / game hack' lure. The document body, though heavily corrupted, contains references to this URL and mentions 'wkhtmltopdf', suggesting it was generated by a tool rather than authored directly. The presence of numerous embedded URLs pointing to similar hack-related content reinforces the malicious intent.

Machine Learning

  • Nyx PDF Classifier malicious score 0.6397

Heuristics 5

  • PDF links to a 'free generator / game hack' redirector high PDF_GAME_HACK_REDIRECT_LURE
    PDF's clickable action targets a redirector of the form /app/<id>/<slug>-game-hack — the landing-page shape of a large SEO 'free spins / generator / game hack' lure family that funnels victims through rotating disposable hosts to a malware/scam payload. The multi-link variants also trip ML/link-farm rules; this catches the single-link variants that otherwise score clean.
  • Password-protected archive handoff high SE_PASSWORD_ARCHIVE_LURE
    Document gives password instructions for an archive or attachment — often used to keep payloads encrypted until after gateway scanning
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://enigmagenerator.com/app/431946152/roblox-game-hack PDF link annotation
    • http://armatrutz.de/images/how-to-cheat-roblox-mad-city.pdfIn PDF document text
    • http://www.friendshiptransport.net/images/yt-how-to-hack-roblox-2021.pdfIn PDF document text
    • http://ruksnaitis.com/images/how-to-get-50-robux-for-free-2021.pdfIn PDF document text
    • http://eastwestmacrobiotics.com/images/how-to-get-free-roblox-avatar-items.pdfIn PDF document text
    • https://www.gvandenakker.nl/images/imperium-hack-roblox.pdfIn PDF document text
    • http://www.fluidtech.hu/images/all-roblox-hack-scripts.pdfIn PDF document text
    • http://svadba-moda.kg/images/roblox-skin-free.pdfIn PDF document text
    • http://gvtssp.org/images/promocodes-roblox-free.pdfIn PDF document text
    • http://jenne-technik.de/images/how-to-tell-if-your-roblox-account-is-hacked.pdfIn PDF document text
    • https://schaefer-rechtsanwaelte.com/images/hack-desert-treasure-quest-roblox.pdfIn PDF document text
    • http://genialica.de/images/descargar-blackberry-roblox-hack.pdfIn PDF document text
    • http://playmoorecello.com/images/hacked-version-of-parkour-roblox.pdfIn PDF document text
    • http://halitbayramoglu.com.tr/images/how-to-get-free-diamonds-on-royale-high-roblox.pdfIn PDF document text
    • http://dorfgaragethalwil.ch/images/roblox-hack-with-no-human-verification.pdfIn PDF document text
    • http://nosocomium.rv.ua/images/free-red-shirt-in-roblox.pdfIn PDF document text
    • http://sscclc.edu.ec/images/how-to-make-a-shirt-in-roblox-free-2021.pdfIn PDF document text
    • http://eddegrootassurantien.nl/images/free-unlimitted-robux-generator.pdfIn PDF document text
    • https://www.accessoriperdisabili.com/images/free-robux-with-synapse.pdfIn PDF document text
    • http://nevesomost.by/images/cheat-engine-noclip-roblox-download.pdfIn PDF document text
    • https://www.coriglianocalabro.it/images/roblox-hack-no-human-verification-2021.pdfIn PDF document text
    • http://www.pro-futuro.eu/images/free-robux-2021-code.pdfIn PDF document text
    • https://www.saisystem.it/images/join-the-group-for-a-free-sword-roblox.pdfIn PDF document text
    • https://happypipers.ch/images/free-roblox-codes-2021-not-expired.pdfIn PDF document text
    • http://solidkom.ch/images/get-free-roblox-game-plays.pdfIn PDF document text
    • http://iricamidelcuore.it/images/free-roblox-no-sign-up.pdfIn PDF document text
    • http://cmfd.nl/images/roblox-r2da-hacks.pdfIn PDF document text
    • https://inspective.nl/images/well-hack-net-roblox.pdfIn PDF document text
    • http://beer-holzhaus.ch/images/free-robux-tycoon.pdfIn PDF document text
    • http://rivas-treuhand.ch/images/roblox-fling-hack.pdfIn PDF document text
    • https://www.audipec.com.br/images/hack-to-get-money-on-bloxburg-roblox.pdfIn PDF document text
    • http://cosver.eu/images/roblox-hack-robot-animation-script.pdfIn PDF document text
    • http://sscclc.edu.ec/images/how-to-be-vip-in-roblox-for-free.pdfIn PDF document text
    • http://www.fluidtech.hu/images/roblox-kick-off-hacks.pdfIn PDF document text
    • http://ns1.radiofacil.net/images/free-robux-roblox-online-generator.pdfIn PDF document text
    • http://cmme.it/images/give-badge-hack-roblox.pdfIn PDF document text
    • http://jkcoaching.nl/images/roblox-all-clothes-free.pdfIn PDF document text
    • http://agritrade-ukraine.com/images/roblox-slurp-hack-download.pdfIn PDF document text
    • http://dieter-sauter.com/images/accessory-wings-roblox-free.pdfIn PDF document text
    • https://gigbagwinkel.nl/images/roblox-groups-with-free-clothes.pdfIn PDF document text
    • http://greasley.online/images/3oblox-free-robux-hack-obc-99m-working-ios-pc-android.pdfIn PDF document text
    • http://nalmpantistractors.gr/images/how-to-hack-roblox-games-2021.pdfIn PDF document text
    • http://wattkit.com/images/how-to-be-an-admin-on-roblox-for-free.pdfIn PDF document text
    • http://baah.ca/images/free-roblox-loot-bags.pdfIn PDF document text
    • http://cadcam.no/images/how-to-get-2021-robux-for-free-2021.pdfIn PDF document text
    • http://kids-academy.pl/images/how-to-look-like-a-hacker-in-roblox-for-free.pdfIn PDF document text
    • http://b6-neu.de/images/roblox-cheats-doawnload.pdfIn PDF document text
    • http://safwafurniture.com/images/free-roblox-supreme-pants.pdfIn PDF document text
    • http://www.drent.se/images/roblox-superhero-package-free.pdfIn PDF document text
    • http://alcomet.ru/images/entry-point-hacks-roblox.pdfIn PDF document text
    +15 more URL(s)

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_003_off00006ee3.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x6EE3 25052 bytes
SHA-256: fc327e2993caaa5527d07a02e116cf664339f535dbb332047061cce9615eccb3
font_01_sfnt_off0000a8f9.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xA8F9 2832 bytes
SHA-256: 77ae1c4cffa647a8fd533dfa4102e94364989f9e80b9cd131876e9d1005899a2
font_02_sfnt_off0000b2aa.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xB2AA 18364 bytes
SHA-256: c27e253841b11418444a5c2f1b767416db84b552cdbfbd0f5f72674fadef6985