PDF static analysis report

Static analysis result for SHA-256 334da3a3fb7d7798…

SUSPICIOUS

PDF

35.5 KB Created: 2021-06-22 22:15:42 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7) First seen: 2021-09-27
MD5: 73bb785e119400c732994ac55c023dbd SHA-1: 301edc4f7371097d9311c95a2aac16dea5ca7bd4 SHA-256: 334da3a3fb7d779851a3717d2f6524bf6d237d25f9c12f98ec07371896f35694
42 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF document contains lures for game cheats and hacks, directing users to download files from external URLs. The ML classifier strongly flagged this PDF as malicious, and the presence of embedded URLs further supports a malicious intent to deliver a payload. No scripts were extracted, but the overall pattern suggests a phishing or malware distribution attempt.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9980

Heuristics 3

  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://netcdn.co/app/431946152/cheat-roblox-tire-dans-les-mur-sur-phantom-forces-game-hack PDF link annotation
    • https://surpetgarut-tmcollection.com/ckfinder/userfiles/files/free-tiktok-likes-no-human-verification-or-downloading-apps_GM835599320.pdfIn PDF document text
    • https://surpetgarut-tmcollection.com/ckfinder/userfiles/files/114-hacks_GM479516143.pdfIn PDF document text
    • https://surpetgarut-tmcollection.com/ckfinder/userfiles/files/coin-master-game-free-play-online_GM406889139.pdfIn PDF document text
    • https://surpetgarut-tmcollection.com/ckfinder/userfiles/files/coin-master-hack-android-2021_GM406889139.pdfIn PDF document text
    • https://surpetgarut-tmcollection.com/ckfinder/userfiles/files/coin-master-free-spins-for-today_GM406889139.pdfIn PDF document text
    • https://surpetgarut-tmcollection.com/ckfinder/userfiles/files/free-robux-website-growbux_GM431946152.pdfIn PDF document text
    • https://surpetgarut-tmcollection.com/ckfinder/userfiles/files/get-free-robux-today_GM431946152.pdfIn PDF document text
    • https://surpetgarut-tmcollection.com/ckfinder/userfiles/files/how-to-get-minecraft-windows-10-for-free-with-java_GM479516143.pdfIn PDF document text
    • https://surpetgarut-tmcollection.com/ckfinder/userfiles/files/how-to-make-your-own-dominus-in-roblox-free_GM431946152.pdfIn PDF document text
    • https://surpetgarut-tmcollection.com/ckfinder/userfiles/files/how-to-get-any-hat-on-roblox-for-free-2021_GM431946152.pdfIn PDF document text
    • https://surpetgarut-tmcollection.com/ckfinder/userfiles/files/free-robux-youtube_GM431946152.pdfIn PDF document text
    • https://surpetgarut-tmcollection.com/ckfinder/userfiles/files/robloxcom-free-kkk-k-k_GM431946152.pdfIn PDF document text
    • https://surpetgarut-tmcollection.com/ckfinder/userfiles/files/roblox-account-hacking-device_GM431946152.pdfIn PDF document text
    • https://surpetgarut-tmcollection.com/ckfinder/userfiles/files/coin-master-villages_GM406889139.pdfIn PDF document text
    • https://surpetgarut-tmcollection.com/ckfinder/userfiles/files/gamehunters-club-coin-master_GM406889139.pdfIn PDF document text
    • https://surpetgarut-tmcollection.com/ckfinder/userfiles/files/coin-master-links-free-spins_GM406889139.pdfIn PDF document text
    • https://surpetgarut-tmcollection.com/ckfinder/userfiles/files/free-robux-pastebin-no-subscribe-2021_GM431946152.pdfIn PDF document text
    • https://surpetgarut-tmcollection.com/ckfinder/userfiles/files/free-robux-exe_GM431946152.pdfIn PDF document text
    • https://surpetgarut-tmcollection.com/ckfinder/userfiles/files/free-robux-survey_GM431946152.pdfIn PDF document text
    • https://surpetgarut-tmcollection.com/ckfinder/userfiles/files/how-to-free-robux_GM431946152.pdfIn PDF document text
    • http://en.wikipedia.org/wiki/MIT_LicenseIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00003118.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x3118 22708 bytes
SHA-256: 9e17f3381a3e8f6b620aad9fe98d0c7469433f9a9b2f65e0d2682c2e17768529
font_01_sfnt_off00006390.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x6390 19960 bytes
SHA-256: a9344789316e3a34f76cbbef21a14aeb489df0345fb79d97baf4463513dff5a8