PDF static analysis report

Static analysis result for SHA-256 65281ad3166108e4…

SUSPICIOUS

PDF

2.5 KB Created: 2021-04-05 19:44:35 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7) First seen: 2021-11-03
MD5: 0d1fee287fb8dfdd7c9f8ce9773cefe3 SHA-1: 9744c7bc89a5c1a7903819f3fdb7602a1e20ebaa SHA-256: 65281ad3166108e4ebad30981ffba85492f1cb54e22e6f04d802c864203dbd2f
34 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF file contains an embedded URI pointing to a website that claims to offer free Robux, a common lure for phishing or malware distribution. The ML classifier strongly flagged this PDF as malicious. While no scripts were explicitly extracted, the PDF structure and embedded URI suggest an attempt to redirect the user to a potentially harmful external resource.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9740

Heuristics 2

  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://gaminggenerator.org/app/431946152/andi-robux-free PDF link annotation