PDF static analysis report

Static analysis result for SHA-256 3958ee1f9bed091c…

SUSPICIOUS

PDF

47.2 KB Created: 2021-05-17 11:34:25 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7) First seen: 2021-09-27
MD5: 1140dbd924c9d9eec004890f376c1ea2 SHA-1: a9ccc95aac535577e48abc5b8805b4d16e25491f SHA-256: 3958ee1f9bed091cd08e2832fa50ef2839af17dc6e03248b6b999e627e637c10
42 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF document contains multiple embedded URLs and a prominent external URI pointing to sites offering game-related cheats and currency, such as 'free Robux'. The ML classifier also flagged this PDF as malicious. While no scripts were explicitly extracted, the presence of numerous links suggests an attempt to redirect users to malicious download sites or phishing pages, likely as part of a social engineering campaign.

Machine Learning

  • Nyx PDF Classifier malicious score 0.8948

Heuristics 3

  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://netcdn.xyz/app/431946152/free-robux-codes-2021-real-game-hack PDF link annotation
    • http://shiny-nn.ru/images/roblox-gift-card-online-free_GM431946152.pdfIn PDF document text
    • http://shiny-nn.ru/images/can-you-get-minecraft-for-free_GM479516143.pdfIn PDF document text
    • http://shiny-nn.ru/images/can-you-still-get-minecraft-windows-10-for-free_GM479516143.pdfIn PDF document text
    • http://shiny-nn.ru/images/coin-master-hack-2021-without-human-verification_GM406889139.pdfIn PDF document text
    • http://shiny-nn.ru/images/roblox-robux-hack_GM431946152.pdfIn PDF document text
    • http://shiny-nn.ru/images/free-daily-spins-from-coin-master_GM406889139.pdfIn PDF document text
    • http://shiny-nn.ru/images/free-robux-app-real_GM431946152.pdfIn PDF document text
    • http://shiny-nn.ru/images/get-minecraft-windows-10-free_GM479516143.pdfIn PDF document text
    • http://shiny-nn.ru/images/coin-master-fan-page-giveaway_GM406889139.pdfIn PDF document text
    • http://shiny-nn.ru/images/free-robux-hack-no-human-verification-or-survey_GM431946152.pdfIn PDF document text
    • http://shiny-nn.ru/images/getrobux-now_GM431946152.pdfIn PDF document text
    • http://shiny-nn.ru/images/coin-master-facebook_GM406889139.pdfIn PDF document text
    • http://shiny-nn.ru/images/https-oprewards-com-roblox_GM431946152.pdfIn PDF document text
    • http://shiny-nn.ru/images/minecraft-free-download-windows_GM479516143.pdfIn PDF document text
    • http://shiny-nn.ru/images/roblox-studio-free_GM431946152.pdfIn PDF document text
    • http://shiny-nn.ru/images/roblox-hack-generator_GM431946152.pdfIn PDF document text
    • http://shiny-nn.ru/images/coin-master-cards_GM406889139.pdfIn PDF document text
    • http://shiny-nn.ru/images/coin-master-spins-free-2021_GM406889139.pdfIn PDF document text
    • http://shiny-nn.ru/images/games-to-get-free-robux_GM431946152.pdfIn PDF document text
    • http://shiny-nn.ru/images/robux-sites_GM431946152.pdfIn PDF document text
    • http://en.wikipedia.org/wiki/MIT_LicenseIn PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_003_off00004719.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x4719 28288 bytes
SHA-256: 738c2228dfc21221508ca58e532934f0b201d6f978be6099af5080d66310d59b
font_01_sfnt_off000086ec.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x86EC 5696 bytes
SHA-256: 450e3ee45915afe13702bf1d587eb8b9ad88a8d2113419ac9f2fd116a828e139
font_02_sfnt_off000093fd.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x93FD 18892 bytes
SHA-256: 79fc292783aafa0d2798f175881928b0c75cb864ff282a378c41953696f75480