Malicious PDF — malware analysis report

Static analysis result for SHA-256 e82becc05fecae69…

MALICIOUS

PDF

58.7 KB Created: 2021-04-05 21:23:31 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7) First seen: 2021-10-14
MD5: 28b71cc88e7339ca71a4a8dd1c5cef62 SHA-1: 999196613537bdab598b39e76db52fa2ba02b237 SHA-256: e82becc05fecae6956fc5d1ac97210108e316b610ad4e987215dc208713b28c1
82 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF document contains numerous URLs and text related to obtaining free Robux or hacks for the Roblox game, acting as a lure. The 'SE_PASSWORD_ARCHIVE_LURE' heuristic suggests the document may be instructing the user to decrypt a password-protected archive, which is a common tactic for evading security scans. The ML classifier also flagged the PDF as malicious, increasing confidence in its malicious intent.

Machine Learning

  • Nyx PDF Classifier malicious score 0.7795

Heuristics 4

  • Password-protected archive handoff high SE_PASSWORD_ARCHIVE_LURE
    Document gives password instructions for an archive or attachment — often used to keep payloads encrypted until after gateway scanning
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://gaminggenerator.org/app/431946152/telecharger-roblox-hack-apk PDF link annotation
    • http://www.art-concept.gr/images/invisible-blue-hack-roblox.pdfIn PDF document text
    • https://www.wadowice24.pl/images/live-free-roblox-card.pdfIn PDF document text
    • http://aistplus.ru/images/how-do-you-get-free-robux-without-downloading-apps.pdfIn PDF document text
    • https://socialvalue.gr/images/how-to-get-free-robux-2021-no-verification.pdfIn PDF document text
    • http://kids-academy.pl/images/dragon-ball-flaming-path-hack-roblox.pdfIn PDF document text
    • http://torkelson.se/images/cheat-codes-for-roblox-android.pdfIn PDF document text
    • http://www.rezbb.sk/images/real-ways-to-get-free-robux.pdfIn PDF document text
    • http://www.eurologistiki.gr/images/roblox-free-sword-fight-game-templates.pdfIn PDF document text
    • https://ballaratcaravans.com.au/images/mask-roblox-free.pdfIn PDF document text
    • https://www.porthos.it/images/hacks-bandit-simulator-roblox.pdfIn PDF document text
    • http://nikabio.com/images/how-to-hack-roblox-prison-life-2021.pdfIn PDF document text
    • http://modenese.net/images/best-apocalypse-hack-roblox.pdfIn PDF document text
    • http://aiyta.com/images/free-roblox-gift-card-no-scam.pdfIn PDF document text
    • http://www.vktzunami.cz/images/how-to-get-robux-fast-free.pdfIn PDF document text
    • http://cosver.eu/images/hack-with-no-virus-roblox.pdfIn PDF document text
    • http://evro-okna.net/images/how-to-hack-and-get-robux-in-roblox.pdfIn PDF document text
    • http://www.hawler.in/images/free-roblox-codes-no-download.pdfIn PDF document text
    • http://m-sv.net/images/how-to-get-free-admin-on-roblox-ios.pdfIn PDF document text
    • https://socialvalue.gr/images/how-to-hack-roblox-dinosaur-simulator.pdfIn PDF document text
    • http://5346000.com/images/how-too-hack-in-murder-mystery-2-roblox.pdfIn PDF document text
    • http://76remont-kvartir.ru/images/free-robux-without-survey.pdfIn PDF document text
    • https://pompesfunebresleveque.fr/images/free-roblox-hacks-no-download.pdfIn PDF document text
    • https://grovehilloutfitters.com/images/free-game-codes-roblox.pdfIn PDF document text
    • https://www.seeingindependence.org/images/fashion-frenzy-game-roblox-free.pdfIn PDF document text
    • http://www.web.stc-part.co.th/images/free-robux-without-human-verification-or-downloads.pdfIn PDF document text
    • https://ballaratcaravans.com.au/images/roblox-hacks-x-ray-2021.pdfIn PDF document text
    • http://garrisonjazz.com/images/discord-free-robux-server.pdfIn PDF document text
    • http://picuruta.com.br/images/roblox-cheats-club.pdfIn PDF document text
    • http://www.exikom.com.ua/images/how-to-hack-unicorn-in-roblox.pdfIn PDF document text
    • http://echosvoix.ch/images/how-to-get-a-free-roblox-necklace.pdfIn PDF document text
    • https://www.hotschool.com.au/images/roblox-game-pass-hack-2021.pdfIn PDF document text
    • http://finalstand.org/images/free-jump-hacks-for-roblox.pdfIn PDF document text
    • http://teknotools.net/images/free-cerberus-roblox.pdfIn PDF document text
    • http://jasperfirstumc.com/images/roblox-virtual-item-codes-free.pdfIn PDF document text
    • http://www.jureclomas.com.ar/images/roblox-watch-ads-for-free-robux.pdfIn PDF document text
    • http://huananhai.net/images/comment-hacker-un-roblox.pdfIn PDF document text
    • http://www.metinadistribuzione.com/images/how-to-get-2021202120219-robux-for-free.pdfIn PDF document text
    • https://www.lomrad.go.th/images/hacks-for-mad-paintball-on-roblox.pdfIn PDF document text
    • http://onlinemusicsolutions.com.au/images/free-robux-hack-2021-october.pdfIn PDF document text
    • https://jsgwertherborgholzhausen.de/images/roblox-hack-no-offers.pdfIn PDF document text
    • http://selectionspdf.fr/images/how-to-get-free-robux-on-roblox-pc.pdfIn PDF document text
    • https://koeltotaal.com/images/da-hood-roblox-hack.pdfIn PDF document text
    • http://cleananddecluttered.com/images/how-to-hack-lucky-blocks-roblox.pdfIn PDF document text
    • https://bancroftandsons.com/images/copy-and-paste-for-free-robux.pdfIn PDF document text
    • https://www.eglihotel.gr/images/pastebin-download-free-robux-2021.pdfIn PDF document text
    • https://www.europap.cz/images/how-to-get-any-hat-in-roblox-for-free.pdfIn PDF document text
    • https://europe-upkl.eu/images/2021-fe-hacks-roblox.pdfIn PDF document text
    • http://www.eurologistiki.gr/images/roblox-rush-com-free-robux.pdfIn PDF document text
    • http://www.inservis.cl/images/roblox-hack-tools-in-all-games.pdfIn PDF document text
    +15 more URL(s)

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_003_off00007f2e.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x7F2E 29420 bytes
SHA-256: 16314cc039337d4b2774ea37a2f568fa8b4aa6c1bde34dc795f38a8169f94cd9
font_01_sfnt_off0000c238.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xC238 18184 bytes
SHA-256: 919e3165b06ba881dae263a171e55d73ec3d8812a46ccac8c2e2301ed2f8b3c3