PDF static analysis report

Static analysis result for SHA-256 037b07b8d0abc64a…

SUSPICIOUS

PDF

44.2 KB Created: 2021-05-15 08:46:39 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7) First seen: 2021-09-17
MD5: 8756f93397ac69073bd9a4468b583489 SHA-1: 86a6ebab4ed27697024bb3a2063c0331cbf62056 SHA-256: 037b07b8d0abc64a0595f66cdb2c5f0f2637b62fb8f97db9652ae85cc4ea41bf
42 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The document contains a lure for free Robux, a common theme in phishing and scam campaigns. It embeds external URLs pointing to potentially malicious content, and the ML classifier strongly indicates maliciousness. While no scripts were explicitly extracted, the presence of embedded URLs and the document's theme suggest it is designed to redirect users to a malicious site or download a payload.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9648

Heuristics 3

  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://netcdn.xyz/app/431946152/how-you-get-free-robux-game-hack PDF link annotation
    • http://amtabor2.at/images/free-robux-codes-2021-not-used_GM431946152.pdfIn PDF document text
    • http://amtabor2.at/images/fan-page-coin-master_GM406889139.pdfIn PDF document text
    • http://amtabor2.at/images/how-to-get-free-robux-on-roblox-2021_GM431946152.pdfIn PDF document text
    • http://amtabor2.at/images/www-roblox-com-free-robux_GM431946152.pdfIn PDF document text
    • http://amtabor2.at/images/grab-points-login_GM431946152.pdfIn PDF document text
    • http://amtabor2.at/images/coin-master-free-spin-and-coin_GM406889139.pdfIn PDF document text
    • http://amtabor2.at/images/roblox-redeem-codes-free_GM431946152.pdfIn PDF document text
    • http://amtabor2.at/images/haktuts-coin-master-free-spins_GM406889139.pdfIn PDF document text
    • http://amtabor2.at/images/free-minecraft-java-edition_GM479516143.pdfIn PDF document text
    • http://amtabor2.at/images/coin-master-vip-hack_GM406889139.pdfIn PDF document text
    • http://amtabor2.at/images/coin-master-links-for-free-spins_GM406889139.pdfIn PDF document text
    • http://amtabor2.at/images/free-robux-games_GM431946152.pdfIn PDF document text
    • http://amtabor2.at/images/free-op-minecraft-servers_GM479516143.pdfIn PDF document text
    • http://amtabor2.at/images/free-daily-spins-coin-master-2021_GM406889139.pdfIn PDF document text
    • http://amtabor2.at/images/descargar-hack-coin-master_GM406889139.pdfIn PDF document text
    • http://amtabor2.at/images/how-to-get-free-robux-no-survey_GM431946152.pdfIn PDF document text
    • http://amtabor2.at/images/coin-master-free-spin-ml_GM406889139.pdfIn PDF document text
    • http://amtabor2.at/images/free-spins-for-coin-master_GM406889139.pdfIn PDF document text
    • http://amtabor2.at/images/coin-master-free-coins-2021_GM406889139.pdfIn PDF document text
    • http://amtabor2.at/images/coin-master-free-2021-spin-link_GM406889139.pdfIn PDF document text
    • http://en.wikipedia.org/wiki/MIT_LicenseIn PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_003_off00004802.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x4802 24248 bytes
SHA-256: 417aabc511178c4a33df8cab5eedf33fb82c137e7d77d88517c5a67b400692bc
font_01_sfnt_off00007f8b.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x7F8B 2912 bytes
SHA-256: 02b35010e2614e3cc95ac6414c49295350c91fdfcc4b4cad27ffdbc10e80df7f
font_02_sfnt_off00008987.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x8987 18444 bytes
SHA-256: d3aeb47c5138bb2f7afdc1cd1986e008461219f841fd4d3ae6acb877e9db5a0e