Malicious PDF — malware analysis report

Static analysis result for SHA-256 f660026a112a3ffb…

MALICIOUS

PDF

60.4 KB Created: 2021-04-06 06:44:54 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7) First seen: 2021-09-29
MD5: 7f641f82aa622a55179bc9bbd2e14b7b SHA-1: 013449f13ca6f1c693a31b7a6aa5b7451ca6ab71 SHA-256: f660026a112a3ffb8376fb8e6896131f12c51f6e090c40fdccaf3d33a8a71dfe
82 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF document contains multiple heuristics indicating a lure for game hacks, specifically targeting Roblox. The embedded URL 'http://enigmagenerator.com/app/431946152/roblox-game-hack' is a strong indicator of malicious intent, likely leading to a malicious download or phishing page. The document body, though partially corrupted, also contains this URL and other similar links, reinforcing the lure.

Machine Learning

  • Nyx PDF Classifier malicious score 0.7795

Heuristics 4

  • PDF links to a 'free generator / game hack' redirector high PDF_GAME_HACK_REDIRECT_LURE
    PDF's clickable action targets a redirector of the form /app/<id>/<slug>-game-hack — the landing-page shape of a large SEO 'free spins / generator / game hack' lure family that funnels victims through rotating disposable hosts to a malware/scam payload. The multi-link variants also trip ML/link-farm rules; this catches the single-link variants that otherwise score clean.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://enigmagenerator.com/app/431946152/roblox-game-hack PDF link annotation
    • http://www.hawler.in/images/free-builders-club-roblox-2021.pdfIn PDF document text
    • https://www.europap.cz/images/roblox-prison-life-hack-202.pdfIn PDF document text
    • http://www.kalaaliaraq.dk/images/cheated-roblox-gun.pdfIn PDF document text
    • https://hassel-event.de/images/free-robux-codes.pdfIn PDF document text
    • http://naturschutzgossau-zh.ch/images/roblox-make-shirt-for-free.pdfIn PDF document text
    • http://gaeconsultores.cl/images/walk-through-walls-hack-roblox.pdfIn PDF document text
    • http://nevesomost.by/images/free-wins-in-anarchy-roblox.pdfIn PDF document text
    • https://rietenwinkel.nl/images/roblox-knife-simulator-hack.pdfIn PDF document text
    • http://www.ntc.edu.za/images/insta-kill-any-player-roblox-hack.pdfIn PDF document text
    • http://www.torvet11.dk/images/do-you-want-free-robux-get-unlimited-robux.pdfIn PDF document text
    • http://fa-deco.com/images/roblox-weight-champion-hack.pdfIn PDF document text
    • http://condit-pack.com/images/roblox-free-lua-executor.pdfIn PDF document text
    • https://semanasantacehegin.com/images/robux-promode-hack-2021.pdfIn PDF document text
    • https://piscinasmundoacuatico.com/images/free-roblox-template-shirt.pdfIn PDF document text
    • http://www.guidaturisticaverona.it/images/comment-hacker-roblox-macbook-pro-franais.pdfIn PDF document text
    • http://ofthalmiatrosthess.gr/images/how-to-get-robux-free-sin-pastebin-2021-con-jugar.pdfIn PDF document text
    • http://lekarinfo.mk/images/roblox-hack-no-scam-robloxian.pdfIn PDF document text
    • https://www.europap.cz/images/roblox-free-exploit-that-support-fireclickdetector.pdfIn PDF document text
    • https://laconce.com/images/como-tener-cosas-gratis-en-roblox-hack.pdfIn PDF document text
    • http://www.anies.eu/images/hack-de-roblox-counter-blox.pdfIn PDF document text
    • http://kfz-werkstatt-etp.de/images/roblox-explorer-hack.pdfIn PDF document text
    • http://www.eurologistiki.gr/images/dragon-ball-af-roblox-cheat-engine.pdfIn PDF document text
    • http://homequeen.de/images/free-robux-no-human-verification-2021-pc.pdfIn PDF document text
    • https://amatq.ca/images/hacker-group-roblox.pdfIn PDF document text
    • http://uptodate.az/images/blue-banded-tophat-gives-you-free-robux.pdfIn PDF document text
    • http://safwafurniture.com/images/cheat-engine-63-roblox-jailbreak.pdfIn PDF document text
    • http://smart-pro.co.uk/images/how-to-get-free-animations-on-roblox-2021.pdfIn PDF document text
    • https://gestionpatrimonial.net/images/roblox-robux-codes-hack-download-pc.pdfIn PDF document text
    • https://www.appartamenticroazia24.com/images/roblox-code-for-break-free.pdfIn PDF document text
    • http://enjoybabelisland.com/images/all-roblox-commands-cheats.pdfIn PDF document text
    • http://fotoflas.gr/images/how-to-get-free-diamonds-on-royale-high-roblox.pdfIn PDF document text
    • http://stitchingart.com/images/free-robux-august-2021.pdfIn PDF document text
    • https://ccej.lviv.ua/images/email-scammer-claiming-to-be-hacker-in-roblox.pdfIn PDF document text
    • http://columbuscigar.com/images/hack-work-at-a-pizza-place-roblox.pdfIn PDF document text
    • http://feuerwehr-rheinau.de/images/how-to-hack-roblox-games-mac.pdfIn PDF document text
    • https://www.sitiwebjoomla.it/images/free-shirts-templates-non-copyrighted-roblox.pdfIn PDF document text
    • http://tegeler-segler.de/images/roblox-dead-winter-infinity-hack.pdfIn PDF document text
    • http://moto98.com/images/roblox-serious-face-free.pdfIn PDF document text
    • http://centralbasinroofing.com/images/free-robux-no-buying-stuff.pdfIn PDF document text
    • https://www.hbproducts.dk/images/how-to-get-free-robux-video-no-hacking.pdfIn PDF document text
    • http://reisebild.eu/images/hack-para-trails-simon-says-roblox.pdfIn PDF document text
    • http://gaeconsultores.cl/images/roblox-robux-hack-1-easy-step.pdfIn PDF document text
    • http://pdia.de/images/hacker-tycoon-roblox.pdfIn PDF document text
    • https://hbln.org.au/images/roblox-i-want-to-break-free.pdfIn PDF document text
    • http://ns1.radiofacil.net/images/how-to-get-free-robux-glitch-easy.pdfIn PDF document text
    • http://dos.most.gov.la/images/get-free-robux-on-roblox-using-no-downloads.pdfIn PDF document text
    • https://koeltotaal.com/images/roblox-2021-download-free.pdfIn PDF document text
    • http://www.centromedicoaurora.it/images/free-robux-no-human-verification-and-no-tasks.pdfIn PDF document text
    • http://biljartenbarendrecht.nl/images/free-nike-roblox-shirts.pdfIn PDF document text
    +19 more URL(s)

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_003_off00008681.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x8681 28964 bytes
SHA-256: 0404ba3deb3d1b96e6f074371fa00c5623849a16a0275035b33fadea11c8d1d7
font_01_sfnt_off0000c821.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xC821 18528 bytes
SHA-256: bb67ee2681ec7a760c53daa5ab67291dfeec2b708a87d50604db127157dc26b5