PDF static analysis report

Static analysis result for SHA-256 0bd7f558a1e61630…

SUSPICIOUS

PDF

44.3 KB Created: 2021-06-04 01:24:19 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7) First seen: 2021-09-27
MD5: 3095717f9fdae970012f3a4d8fca881e SHA-1: e0e63267bd7bbdf7a218ee573b4ea4ca36f7ab3d SHA-256: 0bd7f558a1e61630eac7fa73c772e03e630db4e75942c33b0345cc6c4f1f1641
42 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The ML classifier strongly indicates maliciousness, and the document contains an external URI pointing to a download page for game-related hacks. The presence of numerous similar URLs in the document body further supports the lure of downloading potentially unwanted or malicious software. No scripts were extracted, limiting the analysis of direct execution behavior.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9865

Heuristics 3

  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://netcdn.online/app/406889139/free-bling-bling-card-coin-master-game-hack PDF link annotation
    • http://www.elibrary.fl.unud.ac.id/repository/roblox-free-clothes-hack_GM431946152.pdfIn PDF document text
    • http://www.elibrary.fl.unud.ac.id/repository/coin-master-daily-free-spins-2021_GM406889139.pdfIn PDF document text
    • http://elibrary.fl.unud.ac.id/repository/original-roblox_GM431946152.pdfIn PDF document text
    • http://www.elibrary.fl.unud.ac.id/repository/how-to-get-free-robux-instantly_GM431946152.pdfIn PDF document text
    • http://www.elibrary.fl.unud.ac.id/repository/free-roblox-generator-for-roblox_GM431946152.pdfIn PDF document text
    • http://www.elibrary.fl.unud.ac.id/repository/coin-master-free-spins-2021-no-human-verification_GM406889139.pdfIn PDF document text
    • http://www.elibrary.fl.unud.ac.id/repository/coin-master-free-spins-2021-app_GM406889139.pdfIn PDF document text
    • http://elibrary.fl.unud.ac.id/repository/coin-master-70-spin-link-2021_GM406889139.pdfIn PDF document text
    • http://elibrary.fl.unud.ac.id/repository/how-to-get-tiktok-coins-for-free_GM835599320.pdfIn PDF document text
    • http://www.elibrary.fl.unud.ac.id/repository/free-spins-coin-master-links-blogspot_GM406889139.pdfIn PDF document text
    • http://www.elibrary.fl.unud.ac.id/repository/free-spins-on-coin-master-hack_GM406889139.pdfIn PDF document text
    • http://www.elibrary.fl.unud.ac.id/repository/robux_GM431946152.pdfIn PDF document text
    • http://www.elibrary.fl.unud.ac.id/repository/noob-vs-pro-vs-hacker-vs-god-minecraft_GM479516143.pdfIn PDF document text
    • http://elibrary.fl.unud.ac.id/repository/coin-master-free-cards-link_GM406889139.pdfIn PDF document text
    • http://elibrary.fl.unud.ac.id/repository/how-to-get-minecraft-pe-for-free_GM479516143.pdfIn PDF document text
    • http://www.elibrary.fl.unud.ac.id/repository/robux-apk_GM431946152.pdfIn PDF document text
    • http://elibrary.fl.unud.ac.id/repository/free-spins-and-coins-coin-master-2021-link_GM406889139.pdfIn PDF document text
    • http://www.elibrary.fl.unud.ac.id/repository/how-to-get-free-robux-for-free_GM431946152.pdfIn PDF document text
    • http://www.elibrary.fl.unud.ac.id/repository/static-moonactive-net-rewards_GM406889139.pdfIn PDF document text
    • http://www.elibrary.fl.unud.ac.id/repository/coin-master-daily-spin-link_GM406889139.pdfIn PDF document text
    • http://en.wikipedia.org/wiki/MIT_LicenseIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_004_off000050f5.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x50F5 25216 bytes
SHA-256: d963b3b81f6073ac8112a89da0f04588e18ac3b9523c45d3065b67548ece2241
font_01_sfnt_off00008a24.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x8A24 18464 bytes
SHA-256: badeae9d55bf39d9f494a82973880599056e8fc325ea5045f08d6a1cb132f119