PDF static analysis report

Static analysis result for SHA-256 8f9b88a535c1e67c…

SUSPICIOUS

PDF

39.6 KB Created: 2021-04-03 14:34:53 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7) First seen: 2021-09-29
MD5: 72048abc4dd0a0871cb03d2f73fce544 SHA-1: 18aef828a07c609956076da3c553b8809cf4e0cf SHA-256: 8f9b88a535c1e67cf8207a3ef8893ec3efc23662ea3862aa6cabebac4d9a1bf9
42 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF document contains numerous embedded URLs that lead to pages promising game cheats and hacks, indicating a lure for downloading potentially malicious content. The ML classifier also flagged this PDF as malicious. While no scripts were extracted, the presence of external URIs and the document's theme suggest it is designed to trick users into downloading a second-stage payload.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9500

Heuristics 3

  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://gaminggenerator.org/app/431946152/cheat-roblox-booga-booga-2021 PDF link annotation
    • http://agrao.in/images/roblox-ro-ghoul-hack-2021.pdfIn PDF document text
    • http://www.lionel-seppoloni.fr/images/how-to-get-btools-in-roblox-2021-no-hack.pdfIn PDF document text
    • http://www.zdravazena.sk/images/roblox-hack-tool-download-2021.pdfIn PDF document text
    • http://www.nielsen2u.dk/images/free-robux-no-human-verification-jeuxvideocom.pdfIn PDF document text
    • http://learningarabic.co.uk/images/how-to-get-2021000-robux-for-free-in-roblox.pdfIn PDF document text
    • https://www.dierenartsberghman.be/images/roblox-hack-robux-unlimited-free-on-android-ios-100-working.pdfIn PDF document text
    • http://cosver.eu/images/i-got-hacked-in-roblox-lost-robux.pdfIn PDF document text
    • https://verdensbarn.no/images/roblox-how-to-upload-audio-free.pdfIn PDF document text
    • https://accord.kiev.ua/images/how-to-hack-a-roblox-account-to-show-people.pdfIn PDF document text
    • http://www.rezbb.sk/images/roblox-mobile-cheat.pdfIn PDF document text
    • http://www.visiblefilm.com/images/how-to-hack-money-in-roblox-lumber-tycoon-2.pdfIn PDF document text
    • https://fkg.usu.ac.id/images/how-to-hack-walls-in-strucid-roblox.pdfIn PDF document text
    • https://www.albisser.ch/images/roblox-magnet-sim-hack-script.pdfIn PDF document text
    • http://kids-academy.pl/images/roblox-exploit-synapse-x-free.pdfIn PDF document text
    • http://ns1.radiofacil.net/images/proxy-hack-roblox.pdfIn PDF document text
    • http://zarinnameh.ir/images/hexus-roblox-hack.pdfIn PDF document text
    • http://echosvoix.ch/images/heavy-clutch-roblox-hack.pdfIn PDF document text
    • http://www.lycee-langevin-wallon.com/images/free-roblox-script-hub.pdfIn PDF document text
    • https://esl.ipb.ac.id/images/free-roblox-rainbow-shirt.pdfIn PDF document text
    • http://www.web.stc-part.co.th/images/roblox-hack-page.pdfIn PDF document text
    • http://www.zdravazena.sk/images/hack-chakra-naruto-final-bond-roblox.pdfIn PDF document text
    • http://www.boic.nl/images/denisdaily-free-robux-website.pdfIn PDF document text
    • http://www.remiauclair.fr/images/hack-full-throttle-roblox.pdfIn PDF document text
    • http://poltekkeskhjogja.ac.id/images/roblox-egghunt-2021-hack.pdfIn PDF document text
    • http://sscclc.edu.ec/images/roblox-one-piece-ocean-voyage-hack.pdfIn PDF document text
    • https://www.air-shop.cz/images/20219-walk-speed-roblox-cheat.pdfIn PDF document text
    • https://kimolos-link.gr/images/roblox-clown-van-hack.pdfIn PDF document text
    • http://escolaarboc.cat/images/roblox-free-robux-codes-2021.pdfIn PDF document text
    • http://www.kalaaliaraq.dk/images/roblox-snow-gentleman-free.pdfIn PDF document text
    • http://www.drent.se/images/game-on-roblox-free-items-on-the-catalog-no-hack.pdfIn PDF document text
    • http://en.wikipedia.org/wiki/MIT_LicenseIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000043b1.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x43B1 23180 bytes
SHA-256: c86fa3f510b2aa30f09759972d6ac5a672d368ed0e36e99abf0a895334123579
font_01_sfnt_off000077d7.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x77D7 18048 bytes
SHA-256: a1307e610fbc58d6f8ae20cf35e84e06dffa6c52473b4b17f6ccedfe4cd29767