PDF static analysis report

Static analysis result for SHA-256 20940f35b002d17b…

SUSPICIOUS

PDF

59.7 KB Created: 2021-04-05 22:38:31 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7) First seen: 2021-09-29
MD5: b750c9070508832ede763d4f5d969ea9 SHA-1: 9866bcde7edcb6b7b5a2064fc6b2c539b70e2f48 SHA-256: 20940f35b002d17bbc1a1a2a6279c712158df1f83465d07ae2853355eb12e179
42 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

This PDF document was flagged as suspicious by an ML classifier. The file presents a deceptive download button. Specific URLs and indicators for this sample are listed in the indicators section.

Machine Learning

  • Nyx PDF Classifier malicious score 0.7795

Heuristics 3

  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://gaminggenerator.org/app/431946152/roblox-hack-gamer PDF link annotation
    • https://www.europap.cz/images/rbx-boots-earn-free-robux.pdfIn PDF document text
    • http://www.gongoff.com/images/free-roblox-accounts-2021-august.pdfIn PDF document text
    • https://www.udivadlahotel.cz/images/how-2-hack-roblox-accounts.pdfIn PDF document text
    • http://cosver.eu/images/how-to-cheat-in-roblox-jailbreak.pdfIn PDF document text
    • http://lanoblaie.fr/images/how-to-hack-rich-old-roblox-accounts.pdfIn PDF document text
    • https://www.iadh.bi/images/google-how-do-you-get-free-robux.pdfIn PDF document text
    • http://ce-tsv-nantes.fr/images/roblox-cheats-cbro.pdfIn PDF document text
    • http://bagna.pl/images/when-will-roblox-liberty-county-be-free.pdfIn PDF document text
    • http://brokermortgages.com/images/cool-accessories-in-roblox-for-free.pdfIn PDF document text
    • http://depelem.fr/images/how-to-hack-somone-roblox-account.pdfIn PDF document text
    • http://britishcomics.com/images/is-it-possible-to-get-free-robux-on-roblox.pdfIn PDF document text
    • https://estalagemmonteverde.com.br/images/roblox-scripts-free.pdfIn PDF document text
    • http://lillysonthelake.com/images/how-to-hack-jailbreak-roblox.pdfIn PDF document text
    • http://www.eurologistiki.gr/images/how-to-get-free-robux-2021-easy-no-download.pdfIn PDF document text
    • http://jugendfeuerwehr-scheinfeld.de/images/hacker-programm-roblox.pdfIn PDF document text
    • https://www.udivadlahotel.cz/images/free-copy-hack-roblox.pdfIn PDF document text
    • http://farwesterndistrict.org/images/free-robux-generator-2021-no-verification-or-survey.pdfIn PDF document text
    • https://tokunfome.com.br/images/como-hackear-ropa-en-roblox-2021.pdfIn PDF document text
    • https://eleganceautospa.ca/images/free-robux-games-that-work-2021.pdfIn PDF document text
    • http://elllanorestaurants.com/images/cheat-engine-2021-roblox.pdfIn PDF document text
    • https://bgescc.com/images/free-10-robux.pdfIn PDF document text
    • https://gabrieliassociati.com/images/how-use-cheat-on-roblox.pdfIn PDF document text
    • http://ghhs.com.my/images/roblox-synapse-free-download-2021.pdfIn PDF document text
    • http://sid3r.com/images/roblox-lua-script-hacks-gui.pdfIn PDF document text
    • http://s-punkt-objects.de/images/roblox-thunami-hack.pdfIn PDF document text
    • https://bancroftandsons.com/images/roblox-hacks-phantom-forces-2021-regedit.pdfIn PDF document text
    • http://www.thecoffeebaron.co.za/images/bux-land-free-robux.pdfIn PDF document text
    • https://enpav.it/images/free-robux-no-verification-no-email.pdfIn PDF document text
    • https://www.inova-cuisine.fr/images/como-tener-robux-gratis-hacks-2021-mayo.pdfIn PDF document text
    • http://www.lycee-langevin-wallon.com/images/roblox-joined-hack-script.pdfIn PDF document text
    • http://kundentest.de/images/how-to-hack-roblox-with-kali-linux-virtualbox.pdfIn PDF document text
    • http://bwharrisalumniusa.org/images/roblox-hack-init-roblox-hack-addrobux-20212021000.pdfIn PDF document text
    • http://www.occquimica.com.br/images/how-do-you-earn-robux-on-roblox-for-free.pdfIn PDF document text
    • http://texnes-plus.gr/images/robux-generator-2021-free.pdfIn PDF document text
    • http://daksz.hu/images/assassin-roblox-how-to-get-free-exotics.pdfIn PDF document text
    • http://osteonad.com/images/roblox-jailbreak-robux-hack.pdfIn PDF document text
    • http://garrisonjazz.com/images/how-to-get-free-robux-by-using-cookies.pdfIn PDF document text
    • https://www.academiaanticorrupcion.org/images/hack-compt-roblox.pdfIn PDF document text
    • https://osk-sibir.ru/images/roblox-hacks-tower-of-hell.pdfIn PDF document text
    • http://www.adravietnam.org/images/roblox-adopt-me-how-to-get-free-bucks.pdfIn PDF document text
    • http://technologicalsc.com/images/roblox-heroes-online-free.pdfIn PDF document text
    • http://www.exikom.com.ua/images/roblox-twitter-free-shirt-templates-roblox.pdfIn PDF document text
    • https://arcasict.nl/images/how-to-change-roblox-game-name-with-hacks.pdfIn PDF document text
    • http://fratellimazzoleni.it/images/money-hack-western-frontier-roblox.pdfIn PDF document text
    • http://elsenorcafe.com.co/images/cheat-engine-money-hack-roblox.pdfIn PDF document text
    • https://www.hotschool.com.au/images/cheat-engine-roblox-this-game-has-shut-down.pdfIn PDF document text
    • http://cristalysoptic.com/images/how-to-create-a-roblox-hack-in-2021.pdfIn PDF document text
    • https://verdensbarn.no/images/roblox-cheat-script-auto-farm-super-power-training-simulator.pdfIn PDF document text
    • http://onlinemusicsolutions.com.au/images/how-to-get-free-vip-servers-roblox.pdfIn PDF document text
    +17 more URL(s)

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_003_off00008305.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x8305 30932 bytes
SHA-256: a10261c75cca7d82ac8413647e9ee6a19ecd1be868c7fdb7bd517e53dc01aaeb
font_01_sfnt_off0000c761.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xC761 17812 bytes
SHA-256: 7824daca0894b2f44aac96e8eb2663decf22e21a901cc2b6f8de78aba3401032