Malicious PDF — malware analysis report

Static analysis result for SHA-256 f7a832e021c142f9…

MALICIOUS

PDF

53.1 KB Created: 2021-04-06 17:16:31 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7) First seen: 2021-09-29
MD5: c83af0273f3909f256cceb9eadfc8e2b SHA-1: 1ebc20d962f44751699ee21b487b50dad6d41d4c SHA-256: f7a832e021c142f98b8226981c0fe3f684a6dc2b27cac53285635ca03e64f1d2
90 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

This PDF document employs a lure related to game hacks and cheats, specifically mentioning Roblox, to entice users to click embedded links. The primary link identified is 'https://enigmagenerator.com/app/431946152/roblox-game-hack', which is likely a gateway to malicious content or a phishing page. The document body contains fragmented text related to game hacking tools and the PDF's creation details, further supporting the malicious intent.

Machine Learning

  • Nyx PDF Classifier malicious score 0.8721

Heuristics 5

  • PDF links to a 'free generator / game hack' redirector high PDF_GAME_HACK_REDIRECT_LURE
    PDF's clickable action targets a redirector of the form /app/<id>/<slug>-game-hack — the landing-page shape of a large SEO 'free spins / generator / game hack' lure family that funnels victims through rotating disposable hosts to a malware/scam payload. The multi-link variants also trip ML/link-farm rules; this catches the single-link variants that otherwise score clean.
  • Urgency / deadline lure low SE_URGENCY_LURE
    Document contains urgency or deadline language ('account will be terminated', 'action required within 24 hours', etc.) — useful context, but low-signal without other findings
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://enigmagenerator.com/app/431946152/roblox-game-hack PDF link annotation
    • http://drozle.lt/images/roblox-apocalypse-rising-2-cheats.pdfIn PDF document text
    • http://www.agri-tech.com.au/images/easy-hacks-for-robux-2021.pdfIn PDF document text
    • https://verdensbarn.no/images/nathorix-free-robux.pdfIn PDF document text
    • https://www.academiaanticorrupcion.org/images/free-candy-song-roblox-id.pdfIn PDF document text
    • http://dermaceutic.co.uk/images/free-roblox-account-username-and-password-2021.pdfIn PDF document text
    • http://dos.most.gov.la/images/how-to-hack-into-unicorn-dream-queen-12-on-roblox.pdfIn PDF document text
    • http://beagle-cindy.de/images/tix-factory-tycoon-roblox-cheat.pdfIn PDF document text
    • http://agrupamentoescolas-alfredo-da-silva.com/images/roblox-robux-hack-2021-download.pdfIn PDF document text
    • https://belixconstructions.com.au/images/how-to-hack-acc-on-roblox.pdfIn PDF document text
    • http://www.fabbrotorino.eu/images/roblox-console-hack-2021.pdfIn PDF document text
    • http://kruiz21.ru/images/gideon-the-streets-roblox-hack.pdfIn PDF document text
    • https://www.stayon.no/images/how-to-hack-somebody-on-roblox-with-editthiscookie.pdfIn PDF document text
    • http://only1you.ru/images/roblox-hack-no-virus.pdfIn PDF document text
    • https://www.ghknights.org/images/free-robux-ohne-verify.pdfIn PDF document text
    • http://www.awakeningtruth.org/images/ships-free-roblox.pdfIn PDF document text
    • http://kids-academy.pl/images/kazuin-how-to-hack-in-roblox.pdfIn PDF document text
    • http://felmerihomes.com.au/images/free-robux-only-works-today.pdfIn PDF document text
    • http://svp-steinmaur.ch/images/roblox-games-with-free-vip.pdfIn PDF document text
    • http://energotestcontrol.ru/images/3-roblox-hacks-you-need-to-know.pdfIn PDF document text
    • http://www.barsa.it/images/mobile-roblox-hack-download.pdfIn PDF document text
    • http://horsa18.ru/images/how-to-hack-on-roblox-plates-of-fate.pdfIn PDF document text
    • https://www.stkdb.cz/images/how-to-get-free-codes-in-roblox.pdfIn PDF document text
    • http://brandyourbody.com/images/roblox-free-robux-online-no-survey.pdfIn PDF document text
    • http://www.marambio.com.ar/images/roblox-hack-init.pdfIn PDF document text
    • http://news123.it/images/download-cheats-roblox.pdfIn PDF document text
    • http://unionmusicaldebenidorm.com/images/cch-hack-skin-trong-roblox.pdfIn PDF document text
    • http://danielkleiboemer.de/images/how-do-you-get-free-robux-on-roblox-on-android.pdfIn PDF document text
    • http://www.web.stc-part.co.th/images/earn-free-robux-for-roblox-without-adblock.pdfIn PDF document text
    • http://io24.com.ar/images/free-account-in-roblox-biz.pdfIn PDF document text
    • http://cmme.it/images/cool-roblox-avatars-for-free.pdfIn PDF document text
    • https://www.devries-group.de/images/best-free-things-to-get-in-roblox.pdfIn PDF document text
    • http://petarda.hu/images/cheat-cashed-v3-download-roblox.pdfIn PDF document text
    • http://safwafurniture.com/images/roblox-hack-new-dtfb-test.pdfIn PDF document text
    • http://ghegamethu.vn/images/dantdm-roblox-shirt-free.pdfIn PDF document text
    • http://pdapanache.com/images/how-to-get-free-horses-on-roblox-horse-valley.pdfIn PDF document text
    • http://techmobil.pl/images/how-to-get-roblox-bc-for-free.pdfIn PDF document text
    • http://escolaarboc.cat/images/where-do-you-send-roblox-vidoe-proof-of-someone-hacking.pdfIn PDF document text
    • http://lakomat.by/images/cool-free-roblox-items.pdfIn PDF document text
    • http://saip.ws/images/roblox-robux-secret-hacks.pdfIn PDF document text
    • http://alexandrion.com/images/roblox-hack-anti-ban-2021.pdfIn PDF document text
    • http://sscclc.edu.ec/images/how-to-hack-and-get-robux.pdfIn PDF document text
    • http://sexythings.gr/images/how-to-get-free-robux-robux-generator.pdfIn PDF document text
    • http://androidthai.in.th/images/free-roblox-mad-city.pdfIn PDF document text
    • http://pourvosvacances.com/images/flood-escape-2-infinite-jump-roblox-hack.pdfIn PDF document text
    • http://www.centromedicoaurora.it/images/robloxs-got-talent-hack.pdfIn PDF document text
    • http://www.hawler.in/images/roblox-games-money-hack.pdfIn PDF document text
    • http://micromegamondo.com/images/free-robux-pastebin-hack-2021.pdfIn PDF document text
    • http://ilijakom.com/images/roblox-free-admin-how-spawn-monster.pdfIn PDF document text
    • http://www.evaplast.by/images/how-to-get-free-robux-and-bc-2021-legit.pdfIn PDF document text
    +10 more URL(s)

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_003_off00006e62.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x6E62 26200 bytes
SHA-256: f5819c90db0292bc93bb33d042dd6033aaac96cd2c49f9b8f3f879fa5567c190
font_01_sfnt_off0000a96e.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xA96E 19164 bytes
SHA-256: f9251e036466752492d20291e07a74f900a30d5e739511ef90671a17090c2c75