PDF static analysis report

Static analysis result for SHA-256 66c82aa61b4e9f6b…

SUSPICIOUS

PDF

52.8 KB Created: 2021-05-17 11:10:31 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7) First seen: 2021-09-27
MD5: 2d8434b9e8251a755ba8d81d94cf915f SHA-1: c3daec2995127a306afa5be764df347b242c8c4d SHA-256: 66c82aa61b4e9f6bf8363965c0fc5b1bc9c50643c1c3832f9048b59accd24701
42 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF document contains a lure for free Robux, a virtual currency for the game Roblox, and includes an external URI pointing to a suspicious URL. The ML classifier also flagged this PDF as malicious. While no scripts were extracted, the presence of external URIs and the lure suggest an attempt to trick the user into downloading a malicious payload.

Machine Learning

  • Nyx PDF Classifier malicious score 0.8788

Heuristics 3

  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://netcdn.xyz/app/431946152/how-can-u-get-free-robux-game-hack PDF link annotation
    • http://aessentia.com/images/how-to-hack-people-on-roblox_GM431946152.pdfIn PDF document text
    • http://aessentia.com/images/ultimate-free-spins-coin-master_GM406889139.pdfIn PDF document text
    • http://aessentia.com/images/how-to-hack-someones-roblox-account_GM431946152.pdfIn PDF document text
    • http://aessentia.com/images/coin-master-hack-apk_GM406889139.pdfIn PDF document text
    • http://aessentia.com/images/free-minecraft-hacks_GM479516143.pdfIn PDF document text
    • http://aessentia.com/images/synapse-roblox-free-download_GM431946152.pdfIn PDF document text
    • http://aessentia.com/images/roblox-inappropriate_GM431946152.pdfIn PDF document text
    • http://aessentia.com/images/roblox-login-hack_GM431946152.pdfIn PDF document text
    • http://aessentia.com/images/how-to-earn-free-robux_GM431946152.pdfIn PDF document text
    • http://aessentia.com/images/my-roblox-account-was-hacked_GM431946152.pdfIn PDF document text
    • http://aessentia.com/images/coin-master-free-spins-link-blogspot_GM406889139.pdfIn PDF document text
    • http://aessentia.com/images/www-robux-us_GM431946152.pdfIn PDF document text
    • http://aessentia.com/images/how-to-get-free-roebucks-in-roblox_GM431946152.pdfIn PDF document text
    • http://aessentia.com/images/how-to-make-clothes-on-roblox-for-free_GM431946152.pdfIn PDF document text
    • http://aessentia.com/images/coin-master-spins-free-2021_GM406889139.pdfIn PDF document text
    • http://aessentia.com/images/coin-master-vip-hack_GM406889139.pdfIn PDF document text
    • http://aessentia.com/images/how-to-get-free-robux-on-computer_GM431946152.pdfIn PDF document text
    • http://aessentia.com/images/roblox-jailbreak-hack-download_GM431946152.pdfIn PDF document text
    • http://aessentia.com/images/coin-master-free-spins-app_GM406889139.pdfIn PDF document text
    • http://aessentia.com/images/coin-master-rewards_GM406889139.pdfIn PDF document text
    • http://en.wikipedia.org/wiki/MIT_LicenseIn PDF document text

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_003_off00004843.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x4843 33924 bytes
SHA-256: 841d4ae9a89bc20a5e86a7a04b0b911e49a31124ab763730537536ce01a62455
font_01_sfnt_off000093c4.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x93C4 2844 bytes
SHA-256: baad2f3f6808f4af03fa9398e38c580c8d846f7f773a947d8cc1f39b2753d31a
font_02_sfnt_off00009d81.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x9D81 5696 bytes
SHA-256: 450e3ee45915afe13702bf1d587eb8b9ad88a8d2113419ac9f2fd116a828e139
font_03_sfnt_off0000aa92.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xAA92 18696 bytes
SHA-256: 6d387a6157482ae5d4424ea2a1b018d5f079fe6dbc45eeb2149446a5bd008250