Malicious PDF — malware analysis report

Static analysis result for SHA-256 ed2446382e9968a1…

MALICIOUS

PDF

53.5 KB Created: 2021-04-07 05:55:12 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7) First seen: 2021-09-29
MD5: 4318af196403874d8f279c0a71dd4cde SHA-1: 1a353306bfeabb4e6c790924ba72d9c3b07d76f1 SHA-256: ed2446382e9968a1e0af6f0de8e8d6bdeb5807fcdbf1718171cab93de178c66f
82 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF document contains multiple embedded links and a call-to-action phrase, luring users towards a "free Robux generator" or "game hack". The primary link, https://enigmagenerator.com/app/431946152/roblox-game-hack, is a known malicious redirector. While no scripts were explicitly extracted, the PDF structure and heuristic firings indicate a social engineering attempt to drive traffic to potentially malicious sites, likely as part of a phishing or scam campaign.

Machine Learning

  • Nyx PDF Classifier malicious score 0.8721

Heuristics 4

  • PDF links to a 'free generator / game hack' redirector high PDF_GAME_HACK_REDIRECT_LURE
    PDF's clickable action targets a redirector of the form /app/<id>/<slug>-game-hack — the landing-page shape of a large SEO 'free spins / generator / game hack' lure family that funnels victims through rotating disposable hosts to a malware/scam payload. The multi-link variants also trip ML/link-farm rules; this catches the single-link variants that otherwise score clean.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://enigmagenerator.com/app/431946152/roblox-game-hack PDF link annotation
    • http://arkivthy.dk/images/free-robux-with-verification.pdfIn PDF document text
    • https://www.millatgears.com/images/how-to-get-free-robux-on-windows-10-2021.pdfIn PDF document text
    • http://miriammcconnonart.com/images/get-free-robux-by-playing-games.pdfIn PDF document text
    • http://www.visiblefilm.com/images/assassin-2-roblox-hack-khnif.pdfIn PDF document text
    • http://wsit.at/images/asshurt-roblox-multitool-free.pdfIn PDF document text
    • http://www.habitas.it/images/roblox-transparent-shirt-free-shipping.pdfIn PDF document text
    • http://pizzeria-rosso.pl/images/kill-all-roblox-hack-script.pdfIn PDF document text
    • https://www.nema.go.ke/images/can-i-build-for-free-on-roblox.pdfIn PDF document text
    • http://sdservicesrl.it/images/free-robux-in-robolx.pdfIn PDF document text
    • http://prodajalec.si/images/free-robux-generator-no-verification-no-survey.pdfIn PDF document text
    • http://www.pleiadisrl.it/images/hack-ro-ghoul-roblox.pdfIn PDF document text
    • https://bancroftandsons.com/images/como-tener-ropa-en-roblox-sin-hacks-ni-robux-hack.pdfIn PDF document text
    • http://auto-mankel.de/images/http-hack-roblox.pdfIn PDF document text
    • https://rincondelentrenador.com/images/el-pacmero-hack-roblox-robux-pastebin.pdfIn PDF document text
    • http://pandaplast.com/images/cheat-roblox-strucid.pdfIn PDF document text
    • https://treeconsult.de/images/roblox-free-robox-dite.pdfIn PDF document text
    • http://libertad74.com/images/im-gonna-hack-roblox.pdfIn PDF document text
    • https://amatq.ca/images/creators-on-roblox-that-have-free-clothing.pdfIn PDF document text
    • https://fkg.usu.ac.id/images/roblox-louie-vuitton-free.pdfIn PDF document text
    • http://batterikongen.no/images/better-trains-jalbreak-roblox-hack.pdfIn PDF document text
    • http://jaeger-bauplanung.de/images/free-roblox-catalog-clothes.pdfIn PDF document text
    • http://dahluniver.ru/images/roblox-password-hacker.pdfIn PDF document text
    • http://standart-lab.ru/images/roblox-egg-hunt-2021-hack-script.pdfIn PDF document text
    • https://www.knxuk.org/images/how-to-hack-into-robloxs-top-model.pdfIn PDF document text
    • https://reggieslockandkey.com/images/appbounty-robux-hack-without-human-verification.pdfIn PDF document text
    • http://gops.pruszczgdanski.pl/images/league-of-roblox-hack.pdfIn PDF document text
    • http://yogaschooldecypres.be/images/cheat-roblox-granny.pdfIn PDF document text
    • http://www.hhls.com.au/images/roblox-free-group-funds.pdfIn PDF document text
    • http://www.beantownlimo.com/images/como-jugqr-roblox-free.pdfIn PDF document text
    • http://inertportal.ru/images/roblox-free-download-pc-windows7.pdfIn PDF document text
    • http://instrumenttut.by/images/free-robux-apps-for-window-only.pdfIn PDF document text
    • https://www.appartamenticroazia24.com/images/how-to-get-free-robux-on-roblox-with-proof.pdfIn PDF document text
    • http://grupodin.com.br/images/roblox-ripull-hacking.pdfIn PDF document text
    • http://kulturhusbabberich.nl/images/roblox-money-cheat-ipad.pdfIn PDF document text
    • http://bishopdiego.org/images/how-to-get-robux-for-free-no-hacks-2021.pdfIn PDF document text
    • https://www.tsdb.com.au/images/hacks-admin-roblox.pdfIn PDF document text
    • http://kruiz21.ru/images/roblox-redvalk-free-code.pdfIn PDF document text
    • https://www.inova-cuisine.fr/images/how-to-get-free-bucks-in-adopt-me-roblox.pdfIn PDF document text
    • https://cdu-lengerich.de/images/free-stuff-in-roblox-catalog-2021.pdfIn PDF document text
    • https://www.knxuk.org/images/roblox-frost-guard-general-free.pdfIn PDF document text
    • https://www.porthos.it/images/shirt-template-roblox-free-shipping.pdfIn PDF document text
    • http://logisticgroup.co/images/free-games-to-play-like-roblox.pdfIn PDF document text
    • http://magicmichl.de/images/pokediger1-free-robux.pdfIn PDF document text
    • https://www.romedia.gr/images/i-just-got-free-robux-from-roblox.pdfIn PDF document text
    • http://dream-house.de/images/how-do-you-get-the-hacker-cat-roblox.pdfIn PDF document text
    • http://maestriadental.com/images/free-robux-gift-card-giveaway-live.pdfIn PDF document text
    • http://ecoleduchat-grenoble.fr/images/speed-hack-roblox-jailbreak-2021.pdfIn PDF document text
    • https://www.mvp.co.nz/images/how-to-hack-in-roblox-accounts.pdfIn PDF document text
    • http://energotestcontrol.ru/images/easy-cheat-codes-for-roblox.pdfIn PDF document text
    +10 more URL(s)

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_003_off00006e9f.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x6E9F 26056 bytes
SHA-256: 3486696f4b152ab0bf5124b094c98e1ef433bc9c7fad15d5a92b313ff76eafef
font_01_sfnt_off0000aac1.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xAAC1 19220 bytes
SHA-256: 484da387bcc81140ceed819cfd39fee7223beae118ccabbfda6cf06297aa1ee0