PDF static analysis report

Static analysis result for SHA-256 6ba669cce2576761…

SUSPICIOUS

PDF

61.6 KB Created: 2021-04-05 22:52:50 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7) First seen: 2021-10-01
MD5: b289c5ff0fc63eb869d6c67743521c06 SHA-1: 2201562a804238415165e8ce31cc4ce24f27f1ba SHA-256: 6ba669cce25767613bd40298b5d48935ece8c27473119e67c10fe871ee63ef83
42 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

This PDF document was flagged as suspicious by an ML classifier. The file presents a deceptive download button. Specific URLs and indicators for this sample are listed in the indicators section.

Machine Learning

  • Nyx PDF Classifier malicious score 0.6193

Heuristics 3

  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://gaminggenerator.org/app/431946152/hackear-prison-life-roblox-2021-pc-dansploit PDF link annotation
    • https://www.mrsz.ir/images/how-to-get-free-robux-dount-shop.pdfIn PDF document text
    • http://pia2000.net/images/how-to-hack-a-roblox-account-no-inspect-element.pdfIn PDF document text
    • http://safeandsecurelocksmith.ca/images/hahow-to-hack-roblox-fly-on-sky-ward.pdfIn PDF document text
    • http://www.web.stc-part.co.th/images/youtube-roblox-hack-robux.pdfIn PDF document text
    • https://meltonschool.org/images/actual-working-robux-hack.pdfIn PDF document text
    • http://columbuscigar.com/images/free-cod-card-roblox.pdfIn PDF document text
    • http://www.fluidtech.hu/images/roblox-outfits-for-free.pdfIn PDF document text
    • http://kulturlandschaften.eu/images/como-conseguir-robux-gratis-en-roblox-2021-hack.pdfIn PDF document text
    • https://www.cnte.org.br/images/roblox-how-to-change-your-name-with-cheat-engine.pdfIn PDF document text
    • http://codicicolori.com/images/ex7-roblox-free.pdfIn PDF document text
    • http://kulturhusbabberich.nl/images/free-robux-codes-not-used-2021-july.pdfIn PDF document text
    • http://texnes-plus.gr/images/free-geometry-dash-roblox-odes.pdfIn PDF document text
    • http://cristalysoptic.com/images/roblox-escape-school-online-free.pdfIn PDF document text
    • http://ferienwohnung-walker.de/images/roblox-r45-rig-hack.pdfIn PDF document text
    • https://www.wildpark-johannismuehle.de/images/games-to-get-free-robux-2021.pdfIn PDF document text
    • http://bkd1.balikpapan.go.id/images/roblox-hex-hack.pdfIn PDF document text
    • http://www.nielsen2u.dk/images/roblox-shorts-free.pdfIn PDF document text
    • http://www.malonmalon.com.ar/images/free-redeemable-roblox-cards-2021.pdfIn PDF document text
    • http://uctovnictvosnv.sk/images/how-to-hack-roblox-no-files.pdfIn PDF document text
    • https://www.ergolight.at/images/roblox-rc7-free.pdfIn PDF document text
    • http://elllanorestaurants.com/images/cheat-engine-roblox-jailbreak-noclip.pdfIn PDF document text
    • https://bapalaye.org/images/how-to-get-a-free-membership-on-roblox.pdfIn PDF document text
    • http://centuriatus.com/images/easiest-character-to-make-an-roblox-account-for-free.pdfIn PDF document text
    • http://safeandsecurelocksmith.ca/images/how-to-hack-death-run-roblox-cheat-engine-2021.pdfIn PDF document text
    • http://www.peterdejonge.nl/images/free-robux-no-survey-xbox-one.pdfIn PDF document text
    • http://bkd1.balikpapan.go.id/images/robux-code-2021-free.pdfIn PDF document text
    • http://www.torvet11.dk/images/how-to-counter-hack-a-hacker-on-roblox.pdfIn PDF document text
    • http://www.lycee-langevin-wallon.com/images/free-roblox-prizes.pdfIn PDF document text
    • https://www.academiaanticorrupcion.org/images/roblox-robux-codes-hack-download-pc.pdfIn PDF document text
    • http://aeroclub-kaernten.at/images/robux-generater-hack.pdfIn PDF document text
    • http://domaizdereva24.ru/images/roblox-hack-enginesaa.pdfIn PDF document text
    • http://ekaterinakorneva.com/images/roblox-cash-free.pdfIn PDF document text
    • http://garrisonjazz.com/images/3-ways-to-get-free-robux.pdfIn PDF document text
    • https://www.elevage-chiot.fr/images/can-you-get-hack-in-roblox.pdfIn PDF document text
    • https://www.foodsafety.cz/images/free-robux-legal-easy-and-fast.pdfIn PDF document text
    • http://serviio.org/images/roblox-assassin-hack-generator.pdfIn PDF document text
    • https://www.audipec.com.br/images/roblox-apk-hack-2021.pdfIn PDF document text
    • http://sid3r.com/images/free-roblox-games-that-you-can-play.pdfIn PDF document text
    • http://iluvlocalplaces.com/images/how-to-hack-to-get-free-robux-easy.pdfIn PDF document text
    • http://babbibooth.com/images/free-earned-roblox.pdfIn PDF document text
    • http://dos.most.gov.la/images/roblox-apocalypse-rising-how-to-get-into-hardocre-free.pdfIn PDF document text
    • http://uctovnictvosnv.sk/images/roblox-free-robux-player.pdfIn PDF document text
    • https://ghpa.ru/images/kill-hack-roblox-work-at-a-pizza-place.pdfIn PDF document text
    • https://gomsa.nl/images/free-geaar-roblox.pdfIn PDF document text
    • http://www.remiauclair.fr/images/vide-hacking-for-roblox.pdfIn PDF document text
    • http://armportal.co.uk/images/speed-hack-roblox-wild-revolvers.pdfIn PDF document text
    • http://www.eurologistiki.gr/images/roblox-old-guest-shirt-free.pdfIn PDF document text
    • http://sscclc.edu.ec/images/free-robux-without-verification-code.pdfIn PDF document text
    • http://iluvlocalplaces.com/images/i-want-to-break-free-roblox-music-video.pdfIn PDF document text
    +16 more URL(s)

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_003_off000083ee.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x83EE 26720 bytes
SHA-256: 13524f04157224c05412586960d6126560888fa7038c8fa7e5bf3f16d6e0f0c0
font_01_sfnt_off0000c09b.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xC09B 2832 bytes
SHA-256: 77ae1c4cffa647a8fd533dfa4102e94364989f9e80b9cd131876e9d1005899a2
font_02_sfnt_off0000ca4b.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xCA4B 19192 bytes
SHA-256: f8f7f1e0c15aefee7965d575da10e5ec74e63cb38473ca6f38ef8f87660553d8