Malicious PDF — malware analysis report

Static analysis result for SHA-256 e29e568c1bfc8876…

MALICIOUS

PDF

59.9 KB Created: 2021-04-05 23:39:24 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7) First seen: 2021-10-07
MD5: 3a71d69ecbbb53764a9f2c55c042ee11 SHA-1: 249ed257dacf7b829dd40035cfa0a810325e1eab SHA-256: e29e568c1bfc8876bf80d1796a54492d4c0830f8e45cfd271d4d1ba1157d9300
82 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.001 PowerShell

The PDF document contains a lure for free Robux, directing users to a URL that likely hosts a malicious script. It also includes heuristics indicating a command execution lure, instructing users to paste content into a shell, suggesting the execution of downloaded payloads via PowerShell or cmd.exe.

Machine Learning

  • Nyx PDF Classifier malicious score 0.6193

Heuristics 4

  • Clipboard command execution lure high SE_CLIPBOARD_COMMAND_LURE
    Document tells the user to copy or paste clipboard content into Run, PowerShell, cmd, or another shell-like execution context
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://gaminggenerator.org/app/431946152/script-to-free-robux PDF link annotation
    • http://www.equistop.it/images/what-to-do-if-your-roblox-acc-has-been-hacked.pdfIn PDF document text
    • http://www.visiblefilm.com/images/swiftbucks-hack-roblox.pdfIn PDF document text
    • https://www.lomrad.go.th/images/roblox-gift-card-hack-100-working-free-robux.pdfIn PDF document text
    • http://techmobil.pl/images/claim-box-free-robux.pdfIn PDF document text
    • https://www.iadh.bi/images/roblox-cheat-engine-2021.pdfIn PDF document text
    • https://fkg.usu.ac.id/images/is-friending-a-roblox-hacker-bad.pdfIn PDF document text
    • http://huananhai.net/images/how-to-hack-roblox-accounts-without-inspect-element.pdfIn PDF document text
    • http://modlingua.com/images/donate-free-robux.pdfIn PDF document text
    • https://verdensbarn.no/images/hack-script-roblox-tuto.pdfIn PDF document text
    • http://www.danzamaniapergine.it/images/how-to-make-john-cena-in-roblox-free.pdfIn PDF document text
    • http://panaceafamilymedicine.com/images/rc7-roblox-hack.pdfIn PDF document text
    • http://gvtssp.org/images/roblox-pet-ranch-simulator-hack.pdfIn PDF document text
    • https://www.ghknights.org/images/roblox-vermillion-free-level-7-site-v3rmillionnet.pdfIn PDF document text
    • http://gods-own.org/images/how-to-get-free-robux-new.pdfIn PDF document text
    • http://techmobil.pl/images/roblox-ninja-animation-free.pdfIn PDF document text
    • https://photographygroupofbunbury.com/images/free-robux-roblox-hack-swirl-candy-girl.pdfIn PDF document text
    • https://www.hotel-forsthaus.com/images/www-roblox-hack-com.pdfIn PDF document text
    • https://vtvvaals.nl/images/comment-hack-sur-roblox-strucid.pdfIn PDF document text
    • http://eddegrootassurantien.nl/images/roblox-my-girlfriend-cheated-on-me.pdfIn PDF document text
    • http://solidkom.ch/images/roblox-free-draw-bot.pdfIn PDF document text
    • http://vokna.by/images/descargar-blackberry-roblox-hack.pdfIn PDF document text
    • http://grabmyinfo.com/images/free-robux-free-download.pdfIn PDF document text
    • http://domaizdereva24.ru/images/free-mobile-360-free-robux.pdfIn PDF document text
    • https://ghpa.ru/images/draw-it-roblox-cheat.pdfIn PDF document text
    • https://www.ferienhausdirektkroatien.de/images/fluxx-free-robux.pdfIn PDF document text
    • http://bertaluzorganiccosmetics.com/images/how-to-get-free-robux-on-roblox-october-2021.pdfIn PDF document text
    • http://eltisstudio.sk/images/counter-blox-roblox-hack-2021.pdfIn PDF document text
    • https://verdensbarn.no/images/comment-hacker-roblox-sans-logiciel-youtube.pdfIn PDF document text
    • http://hotel-buta.by/images/how-to-hack-robux-on-roblox-2021.pdfIn PDF document text
    • http://www.eurosan1.ba/images/chaosity-roblox-hack.pdfIn PDF document text
    • https://www.academiaanticorrupcion.org/images/how-to-hack-roblox-game-money.pdfIn PDF document text
    • https://wandersuechtig.de/images/free-robux-hack-2021-no-download.pdfIn PDF document text
    • http://escolaarboc.cat/images/free-roblox-photoshop-apps.pdfIn PDF document text
    • http://iedarelief.us/images/how-to-hack-roblox-with-cheat-engine-561.pdfIn PDF document text
    • http://www.zdravazena.sk/images/how-to-hack-using-roblox-client.pdfIn PDF document text
    • https://studentcareerinfo.com/images/free-roblox-accounts-november-2021.pdfIn PDF document text
    • http://uctovnictvosnv.sk/images/what-would-noobs-do-with-free-robux.pdfIn PDF document text
    • https://www.elevage-chiot.fr/images/synapse-roblox-hack-ddl.pdfIn PDF document text
    • http://ff-obertraun.at/images/free-robux-websites-no-scam.pdfIn PDF document text
    • http://www.metanoiaconsultantsglobal.com/images/how-to-get-free-shards-without-robux-on-shard-seekers.pdfIn PDF document text
    • https://www.coriglianocalabro.it/images/how-to-fly-hack-in-roblox-2021.pdfIn PDF document text
    • http://www.maakherumusic.net/images/hack-para-shinobi-life-roblox-2021.pdfIn PDF document text
    • http://hk-kan.org/images/roblox-catalog-free-robux.pdfIn PDF document text
    • https://www.millatgears.com/images/funny-roblox-avatar-ideas-free.pdfIn PDF document text
    • http://kaleasm.org/images/how-to-use-cheat-engine-63-on-roblox-speed-hack.pdfIn PDF document text
    • https://www.cnte.org.br/images/promo-codes-for-free-robux-on-roblox.pdfIn PDF document text
    • https://www.milewood.co.uk/images/robux-hack-dowbload.pdfIn PDF document text
    • http://www.comitatoiseo.org/images/real-free-robux-hack.pdfIn PDF document text
    • http://immo360grad.com/images/roblox-phantom-forces-free-exploit-2021.pdfIn PDF document text
    +18 more URL(s)

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_003_off000084b0.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x84B0 25336 bytes
SHA-256: 820cec49dfacbaf64d7da77e8a842b76d79da8687dc20b5f5ed0bd2ef9e5538b
font_01_sfnt_off0000be4a.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xBE4A 2844 bytes
SHA-256: baad2f3f6808f4af03fa9398e38c580c8d846f7f773a947d8cc1f39b2753d31a
font_02_sfnt_off0000c80b.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xC80B 17788 bytes
SHA-256: 25dacdf91cf445002789dc9b35fed22a4d5297eff289b766a825311e0238c7c9