Malicious PDF — malware analysis report

Static analysis result for SHA-256 fffae80896142b86…

MALICIOUS

PDF

63.1 KB Created: 2021-04-05 19:48:00 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7) First seen: 2021-11-24
MD5: 68090f99e74b2c2e21b0de78c80194b7 SHA-1: 6f375fe61df610789694847461a3d4196062b844 SHA-256: fffae80896142b869d76ad7e1fc157c801efee46fe513cbb189f0e4285a7023a
70 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains multiple embedded and repeated links, such as http://gaminggenerator.org/app/431946152/jack-hack-robux.com, designed to trick users into downloading a payload. The document body and heuristics indicate a lure related to game exploits ('Robux hack'), suggesting a social engineering tactic to deliver malware. No scripts were extracted, but the PDF structure and repeated links strongly suggest a malicious download attempt.

Machine Learning

  • Nyx PDF Classifier suspicious score 0.4394

Heuristics 3

  • Invisible/repeated PDF links deliver payload file critical PDF_REPEATED_PAYLOAD_LINK_LURE
    PDF uses invisible link annotations and points to a direct payload download. Repeated invisible links or lure-like payload names such as document/unlock/verify archives match malware-delivery PDF carriers where the page is only a prompt and the real payload is fetched from the linked URL.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://gaminggenerator.org/app/431946152/jack-hack-robux.com In PDF document text
    • http://lakomat.by/images/script-executor-free-download-roblox.pdfIn PDF document text
    • https://gomsa.nl/images/roblox-hack-2021-free-robux.pdfIn PDF document text
    • https://technospektr.com.ua/images/free-robux-app-download.pdfIn PDF document text
    • http://pizzeria-rosso.pl/images/free-roblox-griups.pdfIn PDF document text
    • http://karolinaherrera.com/images/what-is-the-code-for-free-robux.pdfIn PDF document text
    • http://biccairo.com/images/anonymous-hacker-script-roblox.pdfIn PDF document text
    • https://www.lavigny.ch/images/roblox-free-robux-may-2021-codes.pdfIn PDF document text
    • http://sb2m.com.br/images/vechil-simulator-money-hack-roblox.pdfIn PDF document text
    • https://www.sauvonsleclimat.org/images/android-fast-roblox-robux-hack.pdfIn PDF document text
    • http://gremihostaleria.cat/images/robux-generator-robux-cheat-roblox-hack.pdfIn PDF document text
    • https://www.cnte.org.br/images/how-to-find-free-items-on-roblox-mobile.pdfIn PDF document text
    • http://cdescolapios.org/images/roblox-crc7-hack-admin-code.pdfIn PDF document text
    • http://julo-it.net/images/base-wars-health-hack-roblox.pdfIn PDF document text
    • http://rose-mari.com.ua/images/cheat-roblox-rs-2021.pdfIn PDF document text
    • https://beejekorf.nl/images/free-roblox-hacks-pasldfopasfksofmnj.pdfIn PDF document text
    • http://halitbayramoglu.com.tr/images/roblox-hack-robux-2021-zn-francais.pdfIn PDF document text
    • http://gremihostaleria.cat/images/free-horror-games-multiplayer-roblox.pdfIn PDF document text
    • http://domaizdereva24.ru/images/roblox-cheat-engine-online.pdfIn PDF document text
    • https://www.porthos.it/images/free-robux-need-password.pdfIn PDF document text
    • https://www.kambati.co.za/images/how-to-get-a-robux-hack.pdfIn PDF document text
    • http://brusivojimi.com/images/free-acc-to-roblox.pdfIn PDF document text
    • https://zsdunajskaluzna.sk/images/hacks-para-roblox-sin-inyectores.pdfIn PDF document text
    • http://www.vktzunami.cz/images/tower-of-hell-roblox-hack.pdfIn PDF document text
    • http://aiyta.com/images/free-robux-offerwalls.pdfIn PDF document text
    • http://www.evaplast.by/images/roblox-catalog-free-2021.pdfIn PDF document text
    • http://biccairo.com/images/hack-774-roblox.pdfIn PDF document text
    • https://www.cpnf.ch/images/free-robux-card-codes-february-18-2021.pdfIn PDF document text
    • https://pneukalousek.cz/images/how-do-you-get-free-robux-2021.pdfIn PDF document text
    • https://www.stoehr-sauer.de/images/roblox-jailbreak-infinite-fire-truck-hack-farm.pdfIn PDF document text
    • http://elllanorestaurants.com/images/how-to-hack-roblox-places.pdfIn PDF document text
    • https://gaj.rs/images/script-for-hacking-roblox-phantom-forces.pdfIn PDF document text
    • http://joshherman.com/images/how-to-get-roblox-hair-for-free.pdfIn PDF document text
    • http://safetin.ru/images/roblox-noclip-hacks.pdfIn PDF document text
    • http://techmobil.pl/images/how-to-get-roblox-bc-for-free.pdfIn PDF document text
    • https://centraltravel.com/images/how-to-get-free-robux-not-scam.pdfIn PDF document text
    • https://my-private-intendant.com/images/twitter-free-robux-codes.pdfIn PDF document text
    • http://evro-okna.net/images/how-to-get-free-shirts-roblox-2021.pdfIn PDF document text
    • https://fkg.usu.ac.id/images/free-redeem-codes-robux.pdfIn PDF document text
    • http://www.maakherumusic.net/images/free-roblox-accounts-with-obc-lifetime-2021.pdfIn PDF document text
    • http://www.kalaaliaraq.dk/images/how-to-get-free-robux-pastebin-2021.pdfIn PDF document text
    • https://luminouswisdom.org/images/free-free-roblox-gift-cards.pdfIn PDF document text
    • http://www.thecoffeebaron.co.za/images/free-roblox-dominus-november-2021.pdfIn PDF document text
    • http://www.homesweethome.pl/images/roblox-hack-dark-devs.pdfIn PDF document text
    • https://www.arquetopia.org/images/roblox-free-doge-hat.pdfIn PDF document text
    • http://escolaarboc.cat/images/free-robux-cheat-download.pdfIn PDF document text
    • https://www.mrsz.ir/images/where-can-you-get-free-robux.pdfIn PDF document text
    • http://racunari.in.rs/images/roblox-dashing-simulator-hack.pdfIn PDF document text
    • http://www.lionel-seppoloni.fr/images/city-architect-roblox-cheats.pdfIn PDF document text
    • http://condit-pack.com/images/roblox-goku-hair-free.pdfIn PDF document text
    +12 more URL(s)

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_003_off00007f88.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x7F88 25624 bytes
SHA-256: 60361c5010fca61ea28a94d3ec37b271e9b6062b8562d73709c48aafff252c36
font_01_sfnt_off0000b97a.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xB97A 11440 bytes
SHA-256: 154d59d1680f2d1e38ccb783d6997f344290d121007e51df331726de4128c12e
font_02_sfnt_off0000d49b.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xD49B 17828 bytes
SHA-256: e4573a9ec749256067187c87e78e3d851d13d38aae37b84f37dac98f476a0adc