Malicious PDF — malware analysis report

Static analysis result for SHA-256 eb996997a2b30195…

MALICIOUS

PDF

58.4 KB Created: 2021-04-05 21:17:23 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7) First seen: 2021-09-29
MD5: 61f6aaeeda576e08556d0ee4216a236a SHA-1: 090da0d5e30d0684225071e0e5cd1319a948a257 SHA-256: eb996997a2b3019591d7c9e9a609539a2402a3c245ef75e69bb2f0a86ed9774e
82 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1203 Exploitation for Client Execution

This PDF document was flagged as malicious by an ML classifier. It uses a fake-CAPTCHA lure. The file presents a deceptive download button. Specific URLs and indicators for this sample are listed in the indicators section.

Machine Learning

  • Nyx PDF Classifier malicious score 0.7677

Heuristics 4

  • Fake CAPTCHA / human verification prompt high SE_FAKE_CAPTCHA
    Document displays a fake CAPTCHA or human-verification prompt — used to trick users into running commands or pressing keyboard shortcuts
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://gaminggenerator.org/app/431946152/roblox-design-it-cheats PDF link annotation
    • http://uctovnictvosnv.sk/images/free-robux-without-human-verification-or-survey-2021.pdfIn PDF document text
    • http://www.anies.eu/images/counter-roblox-offensive-hacks.pdfIn PDF document text
    • https://hbln.org.au/images/how-to-hack-free-robux-on-pc.pdfIn PDF document text
    • https://www.seeingindependence.org/images/how-to-use-cheat-engine-on-roblox-level.pdfIn PDF document text
    • http://kulturlandschaften.eu/images/robux-hack-with-no-verification.pdfIn PDF document text
    • http://www.gadanie.lv/images/how-to-bypass-cheat-engine-64-on-roblox.pdfIn PDF document text
    • http://halitbayramoglu.com.tr/images/roblox-btools-script-hack-sitev3rmillionnet.pdfIn PDF document text
    • https://corbo.ru/images/roblox-free-pants-catalog.pdfIn PDF document text
    • http://www.homesweethome.pl/images/hacking-galaxykittty2021-on-roblox.pdfIn PDF document text
    • http://www.evaplast.by/images/free-robux-codes-no-download-no-survey.pdfIn PDF document text
    • https://www.stoehr-sauer.de/images/free-promo-code-generator-roblox.pdfIn PDF document text
    • http://www.torvet11.dk/images/free-robux-hackcome.pdfIn PDF document text
    • http://the-specials.ch/images/free-robux-and-bc-roblox.pdfIn PDF document text
    • http://www.fluidtech.hu/images/roblox-buy-for-free.pdfIn PDF document text
    • http://www.learningbydoinglingue.com/images/hack-para-tener-robux-gratis-2021.pdfIn PDF document text
    • http://a1scan3d.com/images/cheats-for-rocitizens-on-roblox.pdfIn PDF document text
    • http://www.boic.nl/images/roblox-free-shop-hose.pdfIn PDF document text
    • http://dorfgaragethalwil.ch/images/free-to-use-roblox-ads.pdfIn PDF document text
    • http://w-i-r.de/images/free-robux-generater-no-survety.pdfIn PDF document text
    • https://cdu-lengerich.de/images/island-royale-roblox-hack-esp-script-pastebin.pdfIn PDF document text
    • http://www.gadanie.lv/images/do-roblox-gift-cards-give-you-free-robux.pdfIn PDF document text
    • http://britishcomics.com/images/free-robux-pastebin-no-wait-no-subscribe.pdfIn PDF document text
    • https://billiekawende.com/images/roblox-shionbi-life-max-lvl-hack-robloxdailt.pdfIn PDF document text
    • http://chartsmart.com.au/images/free-roblox-gift-cards-live.pdfIn PDF document text
    • http://tecnodue.com/images/roblox-robux-hack-download-for-mac.pdfIn PDF document text
    • http://domaizdereva24.ru/images/9-legit-ways-to-get-free-robux.pdfIn PDF document text
    • http://hoqueijmj.eu/images/how-to-get-free-robux-with-pastebin-2021.pdfIn PDF document text
    • http://pdia.de/images/free-stuff-roblox-avatar.pdfIn PDF document text
    • http://www.kalaaliaraq.dk/images/test-all-roblox-gear-hats-and-shirts-free.pdfIn PDF document text
    • http://parkinsononline.com/images/roblox-admin-hack-scropt.pdfIn PDF document text
    • http://agrao.in/images/roblox-flame-exploit-free.pdfIn PDF document text
    • https://verdensbarn.no/images/roblox-adopt-me-pet-hacks.pdfIn PDF document text
    • http://acp-institut.fr/images/paste-hack-roblox.pdfIn PDF document text
    • http://www.eurologistiki.gr/images/roblox-lumber-tycoon-2-hack-script-2021.pdfIn PDF document text
    • http://garrisonjazz.com/images/roblox-money-hack-no-human-verification-works.pdfIn PDF document text
    • http://selectionspdf.fr/images/roblox-hack-2021-download-free.pdfIn PDF document text
    • http://chartsmart.com.au/images/roblox-free-accounts-and-passwords.pdfIn PDF document text
    • http://bestmaids.co.uk/images/colossus-legends-roblox-hack.pdfIn PDF document text
    • http://bibliotheque-perrigny-les-dijon.fr/images/how-to-get-free-animations-on-roblox-2021.pdfIn PDF document text
    • https://www.cfdcnv.com/images/redline-roblox-jailbreak-hack.pdfIn PDF document text
    • http://e-mailservis.cz/images/superhero-free-roblox.pdfIn PDF document text
    • https://www.lavigny.ch/images/auto-runner-roblox-hack.pdfIn PDF document text
    • http://cosver.eu/images/how-to-get-free-robux-flamingo.pdfIn PDF document text
    • http://optsuvenir.by/images/roblox-app-cheat-engine.pdfIn PDF document text
    • http://www.centromedicoaurora.it/images/are-there-any-actual-robux-cheats-reddit.pdfIn PDF document text
    • http://www.inservis.cl/images/roblox-serious-face-free.pdfIn PDF document text
    • https://ghpa.ru/images/roblox-login-hack-password.pdfIn PDF document text
    • http://global-tech-security.be/images/inject-hack-com-roblox-robux.pdfIn PDF document text
    • http://dialine.cz/images/roblox-btools-hack-script.pdfIn PDF document text
    +17 more URL(s)

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_004_off00008882.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x8882 24592 bytes
SHA-256: d81d32b6d68a9b1191935ec4be75094b90c0299a0ae968815c8f7fcf1e3fd890
font_01_sfnt_off0000c083.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xC083 18288 bytes
SHA-256: 265f7466dade66184b157fcc64846e147e0891134b5b7ccaaf8eea01b7bbbd6e