PDF static analysis report

Static analysis result for SHA-256 83f599a87fd0b05e…

SUSPICIOUS

PDF

35.8 KB Created: 2021-07-04 14:33:29 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7) First seen: 2021-09-16
MD5: 6ede2f2e9eddd41322504159e0f8a2e5 SHA-1: 5d1a2bc4076fffba5644a1208172e7147da58f84 SHA-256: 83f599a87fd0b05ecb990ba4368de31fc300d21af40c87231e51f1fce2958478
42 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF document contains numerous links to external websites, including one that directly advertises a 'Free Robux Generator'. The ML classifier strongly flagged this PDF as malicious, and the presence of these lures suggests an attempt to trick users into visiting malicious sites or downloading further malware. No scripts were extracted, but the embedded URLs are the primary indicators of malicious intent.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9980

Heuristics 3

  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://netcdn.tw/app/431946152/free-robux-generator-com-roblox-hack-game-hack PDF link annotation
    • http://www.technibuild-group.com/uploaded_files/userfiles/files/how-to-get-free-cards-for-coin-master_GM406889139.pdfIn PDF document text
    • http://www.technibuild-group.com/uploaded_files/userfiles/files/free-promo-codes-roblox-for-robux_GM431946152.pdfIn PDF document text
    • http://www.technibuild-group.com/uploaded_files/userfiles/files/coin-master-free-cards_GM406889139.pdfIn PDF document text
    • http://www.technibuild-group.com/uploaded_files/userfiles/files/how-to-get-free-robux-on-computer_GM431946152.pdfIn PDF document text
    • http://www.technibuild-group.com/uploaded_files/userfiles/files/free-spins-on-coin-master-links-2021_GM406889139.pdfIn PDF document text
    • http://www.technibuild-group.com/uploaded_files/userfiles/files/coin-master-daily-free-spin-app_GM406889139.pdfIn PDF document text
    • http://www.technibuild-group.com/uploaded_files/userfiles/files/coinmasterfreespinlink_GM406889139.pdfIn PDF document text
    • http://www.technibuild-group.com/uploaded_files/userfiles/files/free-coins-coin-master-2021_GM406889139.pdfIn PDF document text
    • http://www.technibuild-group.com/uploaded_files/userfiles/files/robloxcom-free-promo-codes_GM431946152.pdfIn PDF document text
    • http://www.technibuild-group.com/uploaded_files/userfiles/files/cheat-engine-roblox-robux-hack_GM431946152.pdfIn PDF document text
    • http://www.technibuild-group.com/uploaded_files/userfiles/files/pubg-uc-redeem-code_GM1330123889.pdfIn PDF document text
    • http://www.technibuild-group.com/uploaded_files/userfiles/files/hack-roblox-lumber-tycoon2_GM431946152.pdfIn PDF document text
    • http://www.technibuild-group.com/uploaded_files/userfiles/files/coin-master-hack-pro-gamers_GM406889139.pdfIn PDF document text
    • http://www.technibuild-group.com/uploaded_files/userfiles/files/hack-robux-into-roblox-account_GM431946152.pdfIn PDF document text
    • http://www.technibuild-group.com/uploaded_files/userfiles/files/get-free-followers-on-tiktok_GM835599320.pdfIn PDF document text
    • http://www.technibuild-group.com/uploaded_files/userfiles/files/free-robux-come_GM431946152.pdfIn PDF document text
    • http://www.technibuild-group.com/uploaded_files/userfiles/files/how-to-hack-roblox-on-mobile_GM431946152.pdfIn PDF document text
    • http://www.technibuild-group.com/uploaded_files/userfiles/files/roblox-hacked-place-database_GM431946152.pdfIn PDF document text
    • http://www.technibuild-group.com/uploaded_files/userfiles/files/minecraft-java-edition-free-download-for-android_GM479516143.pdfIn PDF document text
    • http://www.technibuild-group.com/uploaded_files/userfiles/files/free-spins-promo-code-for-coin-master_GM406889139.pdfIn PDF document text
    • http://en.wikipedia.org/wiki/MIT_LicenseIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00003298.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x3298 22956 bytes
SHA-256: 16a0e0919610e288450d51b3c0a177ba4b2cf8a6071c3bfd1f4903dee8ea3f95
font_01_sfnt_off00006662.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x6662 19324 bytes
SHA-256: b5fe64a349a1260a8bf1e39cb434a35d84e03f20b24c2703f62dd6d7df3547b9