Malicious PDF — malware analysis report

Static analysis result for SHA-256 ef84048315e6b956…

MALICIOUS

PDF

52.7 KB Created: 2021-04-06 16:58:56 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7) First seen: 2021-11-24
MD5: 0979cf88bbd457c6f3815df918165de7 SHA-1: fe34e2793f19a479273d628cc3b232e2ae944ac0 SHA-256: ef84048315e6b95696f5604ebc594e40519019b4bcf33fa2f67e6d773d7e99f1
102 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF document contains a prominent link disguised as a 'free Roblox game hack' lure, directing users to `https://enigmagenerator.com/app/431946152/roblox-game-hack`. This URL, along with numerous other suspicious PDF links found within the document, suggests a phishing or social engineering attempt to redirect users to potentially malicious sites. The ML classifier also flagged this PDF as malicious.

Machine Learning

  • Nyx PDF Classifier malicious score 0.8852

Heuristics 4

  • PDF links to a 'free generator / game hack' redirector critical PDF_GAME_HACK_REDIRECT_LURE
    PDF's clickable action targets a redirector of the form /app/<id>/<slug>-game-hack — the landing-page shape of a large SEO 'free spins / generator / game hack' lure family that funnels victims through rotating disposable hosts to a malware/scam payload. The multi-link variants also trip ML/link-farm rules; this catches the single-link variants that otherwise score clean. CRITICAL on its own: the /app/<id>/<slug>-game-hack path shape is unambiguous scam infra, and the host rotates so a host-list match can't be relied on.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://enigmagenerator.com/app/431946152/roblox-game-hack PDF link annotation
    • http://www.campiresine.it/images/how-to-get-free-robux-on-iphone.pdfIn PDF document text
    • http://villazeus.eu/images/code-card-roblox-free.pdfIn PDF document text
    • http://elllanorestaurants.com/images/free-roblox-hack-script.pdfIn PDF document text
    • http://bau-lk.de/images/roblox-free-online-demo.pdfIn PDF document text
    • http://www.anies.eu/images/furky-safe-free-roblox-exploits.pdfIn PDF document text
    • http://apartstmichel.com.ar/images/free-roblox-exploits-no-virus.pdfIn PDF document text
    • http://xn----7sbq6amdnuk.xn--p1ai/images/app-hack-game-roblox.pdfIn PDF document text
    • https://bancroftandsons.com/images/shadowrun-cheat-codes-roblox.pdfIn PDF document text
    • http://eau-petit-pont.com/images/bloxburg-roblox-how-to-get-multiple-floor-free.pdfIn PDF document text
    • https://kimolos-link.gr/images/how-to-hack-roblox-groups.pdfIn PDF document text
    • http://stroybelan.ru/images/hacking-into-a-roblox-account2021.pdfIn PDF document text
    • http://www.centromedicoaurora.it/images/roblox-free-things-list.pdfIn PDF document text
    • http://www.malonmalon.com.ar/images/roblox-obby-gives-free-robux.pdfIn PDF document text
    • http://www.bernerpupping.at/images/how-to-get-free-robux-2021-no-download.pdfIn PDF document text
    • http://gvtssp.org/images/how-to-get-free-robux-script.pdfIn PDF document text
    • http://www.bernerpupping.at/images/robuxian-tutorials-free-robux-code-generator.pdfIn PDF document text
    • http://legs11.co.za/images/free-100-robux.pdfIn PDF document text
    • https://sitam.co.in/images/robux-hack-2021-real-no-human-vertification.pdfIn PDF document text
    • http://www.bbnest.it/images/how-to-hack-2021-acc-roblox.pdfIn PDF document text
    • http://www.sapaengineering.kz/images/roblox-chat-hacks-script.pdfIn PDF document text
    • http://legs11.co.za/images/roblox-bluestacks-hack.pdfIn PDF document text
    • https://grovehilloutfitters.com/images/free-robux-code-generator-tool.pdfIn PDF document text
    • https://digitalsenseafrica.com.ng/images/roblox-jailbreak-redboy-hack.pdfIn PDF document text
    • http://dubwar.pl/images/get-free-bc-tbc-obc-roblox.pdfIn PDF document text
    • http://energotestcontrol.ru/images/roblox-dashing-simulator-hack.pdfIn PDF document text
    • http://serviio.org/images/can-you-get-roblox-studio-free.pdfIn PDF document text
    • http://petarda.hu/images/roblox-magitan-hack.pdfIn PDF document text
    • https://www.utalii.ac.ke/images/free-robux-hack-site-youtubecom.pdfIn PDF document text
    • https://www.banhngoncaocap.com/images/join-this-roblox-group-for-free-robux.pdfIn PDF document text
    • http://haertetechnik-steinbach.de/images/apocalypse-rising-roblox-mac-hack.pdfIn PDF document text
    • https://estalagemmonteverde.com.br/images/cheat-engine-lua-roblox-scripts.pdfIn PDF document text
    • http://medimacs.eu/images/hacks-for-roblox-script-reader.pdfIn PDF document text
    • https://www.cosmosdawn.net/images/roblox-group-free-robux-2021.pdfIn PDF document text
    • http://bibliotheque-perrigny-les-dijon.fr/images/how-to-get-free-clothes-no-robux-of-friends.pdfIn PDF document text
    • http://brandyourbody.com/images/robuxian-free-robux-code-generator.pdfIn PDF document text
    • https://servotecnica.com/images/byfanatics-co-free-robux.pdfIn PDF document text
    • http://escolaarboc.cat/images/roblox-phantom-forces-cheats-aimbot.pdfIn PDF document text
    • https://www.anagoria.com/images/roblox-free-shirts-2021.pdfIn PDF document text
    • http://hocquaux.fr/images/roblox-hack-install.pdfIn PDF document text
    • https://sanjoseelectricians.net/images/how-to-get-unlimited-robux-for-free-with-copying-notes.pdfIn PDF document text
    • http://www.equistop.it/images/hack-peoples-phones-for-money-on-roblox.pdfIn PDF document text
    • http://www.lionel-seppoloni.fr/images/roblox-hack-without-human-verification-and-survey.pdfIn PDF document text
    • http://xn----7sbq6amdnuk.xn--p1ai/images/roblox-free-giveaway.pdfIn PDF document text
    • http://verenacrow.at/images/how-to-get-free-robux-and-obc-by-xdaniel.pdfIn PDF document text
    • https://reggieslockandkey.com/images/how-to-hack-games-on-roblox-2021.pdfIn PDF document text
    • http://vibrato.fr/images/que-hacer-cuando-te-hackean-la-cuenta-de-roblox.pdfIn PDF document text
    • http://beer-holzhaus.ch/images/how-to-get-free-robux-no-hack-or-glitch.pdfIn PDF document text
    • http://subarulegacy.com/images/roblox-bank-tycoon-money-cheats.pdfIn PDF document text
    • https://www.foodsafety.cz/images/super-power-training-simulator-roblox-script-hack-pastebin.pdfIn PDF document text
    +10 more URL(s)

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_003_off000071f3.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x71F3 25196 bytes
SHA-256: d3f1d7590a1a434096229e15bc3c0130aca758d294acb1c1c41c1fee223c3a9b
font_01_sfnt_off0000ab70.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xAB70 17860 bytes
SHA-256: 802b22d783a65672ffec7ce4c2ad4555237c21bd9919c7def333c5d6d4630115