PDF static analysis report

Static analysis result for SHA-256 9f1b4ecead4afe5e…

SUSPICIOUS

PDF

45.8 KB Created: 2021-04-02 20:37:24 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7) First seen: 2021-09-17
MD5: c34115cf1d84d757fed4dfb6a398bb6d SHA-1: eaf483d13fb9daf696b0bcf8407f746ee7aa1992 SHA-256: 9f1b4ecead4afe5ee6d47cb2613d7a2af117bfe80ab4016654fef40423b6d17d
42 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious Link

The PDF document contains numerous embedded URLs, many of which are related to game exploits and free in-game currency, suggesting a lure for users interested in such topics. The ML classifier flagged the PDF as malicious with high confidence. The presence of external URIs and the document body's focus on 'free Robux' and 'hacks' indicate an attempt to direct users to potentially harmful external content, likely for malware distribution or phishing.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9434

Heuristics 3

  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://gaminggenerator.org/app/431946152/how-to-play-bloxburg-for-free-no-robux PDF link annotation
    • https://www.iadh.bi/images/roblox-milenario-headphones-free.pdfIn PDF document text
    • http://agrao.in/images/script-roblox-hack-exploits.pdfIn PDF document text
    • http://www.cuniv-naama.dz/images/outwit-roblox-hack.pdfIn PDF document text
    • https://technospektr.com.ua/images/free-robux-no-human-verification-and-no-survey-2021.pdfIn PDF document text
    • https://www.ncscolour.no/images/dll-inject-hacks-roblox.pdfIn PDF document text
    • https://tokunfome.com.br/images/fishing-glitch-gives-free-robux.pdfIn PDF document text
    • http://www.torvet11.dk/images/slx-roblox-hack.pdfIn PDF document text
    • http://nevesomost.by/images/how-to-hack-in-jailbreak-roblox-2021.pdfIn PDF document text
    • http://poltekkeskhjogja.ac.id/images/free-robux-html-pastebin.pdfIn PDF document text
    • https://ballaratcaravans.com.au/images/how-to-hack-stats-in-roblox.pdfIn PDF document text
    • http://www.lycee-langevin-wallon.com/images/free-cool-tshirt-roblox.pdfIn PDF document text
    • http://www.eurologistiki.gr/images/roblox-reaper-simulator-hack.pdfIn PDF document text
    • http://gops.pruszczgdanski.pl/images/get-tons-of-robux-free.pdfIn PDF document text
    • https://www.abrapppe.org.br/images/roblox-pokemon-brick-bronze-cheats.pdfIn PDF document text
    • http://www.pcclawyers.com.au/images/roblox-cheat-god-mode.pdfIn PDF document text
    • https://www.hotschool.com.au/images/cheat-dungeon-quest-roblox-20s.pdfIn PDF document text
    • https://amatq.ca/images/free-robux-codes-2021.pdfIn PDF document text
    • https://www.abrapppe.org.br/images/khaos-how-to-get-free-robux.pdfIn PDF document text
    • http://www.lovecraftiana.com.ar/images/hacking-roblox-items.pdfIn PDF document text
    • http://www.exikom.com.ua/images/roblox-free-robux-obby-2021.pdfIn PDF document text
    • http://pa-tanjungselor.go.id/images/roblox-games-with-no-anti-cheat.pdfIn PDF document text
    • http://www.occquimica.com.br/images/free-robux-cards-pin.pdfIn PDF document text
    • https://www.lomrad.go.th/images/youtube-roblox-hack-elemental-battle-ground.pdfIn PDF document text
    • https://www.dierenartsberghman.be/images/roblox-hack-inspect-element-2021.pdfIn PDF document text
    • https://komakinosite.jp/images/sentinel-hack-roblox.pdfIn PDF document text
    • http://domaizdereva24.ru/images/como-hackear-roblox-con-cheat-engine-robux.pdfIn PDF document text
    • https://www.lomrad.go.th/images/how-to-hack-roblox-high-school-2021.pdfIn PDF document text
    • http://kids-academy.pl/images/how-to-get-free-robux-surveys.pdfIn PDF document text
    • https://www.coriglianocalabro.it/images/roblox-cheat-engine-hacks-2021.pdfIn PDF document text
    • https://www.udivadlahotel.cz/images/how-to-get-free-robux-no-voucher-no-money.pdfIn PDF document text
    • http://www.nielsen2u.dk/images/looking-for-free-roblox-items.pdfIn PDF document text
    • https://accord.kiev.ua/images/free-robux-game-uncopylockedf.pdfIn PDF document text
    • https://accord.kiev.ua/images/robux-cheat-in-roblox.pdfIn PDF document text
    • https://pa-waingapu.go.id/images/how-to-hack-mad-city-roblox.pdfIn PDF document text
    • http://energotestcontrol.ru/images/how-to-do-a-bendy-hack-in-roblox.pdfIn PDF document text
    • http://www.cuniv-naama.dz/images/www-resourcly-ml-free-robux.pdfIn PDF document text
    • http://www.lycee-langevin-wallon.com/images/roblox-dll-hack-file.pdfIn PDF document text
    • http://www.lovecraftiana.com.ar/images/free-item-hack-roblox.pdfIn PDF document text
    • http://www.eurosan1.ba/images/free-roblox-girl-outfit-codes.pdfIn PDF document text
    • https://amatq.ca/images/auto-jump-script-roblox-hack.pdfIn PDF document text
    • http://pa-tanjungselor.go.id/images/how-to-get-free-robux-2021-hack.pdfIn PDF document text
    • https://pa-waingapu.go.id/images/how-to-make-hack-models-in-roblox.pdfIn PDF document text
    • http://www.copoint.co.uk/images/how-to-cheat-in-unboxing-simulator-roblox.pdfIn PDF document text
    • https://komakinosite.jp/images/how-to-get-free-robux-no-scams-no-human-verification.pdfIn PDF document text
    • https://www.lavigny.ch/images/free-robux-obby-roblox-game.pdfIn PDF document text
    • https://sitam.co.in/images/free-robux-codes-2021-working.pdfIn PDF document text
    • https://accord.kiev.ua/images/roblox-free-stuff-codes.pdfIn PDF document text
    • http://www.exikom.com.ua/images/free-stuuf-in-roblox.pdfIn PDF document text
    • http://www.boic.nl/images/how-to-hack-roblox-accounts-with-cheat-engine-64.pdfIn PDF document text
    +2 more URL(s)

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_003_off000056cb.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x56CB 24704 bytes
SHA-256: d2b041955e497e10e34d73288030f7a53e341468ad6b333cb646f582e8eb7867
font_01_sfnt_off00008e9e.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x8E9E 18336 bytes
SHA-256: afb7b60b8560f471db71d87dc8d9dbbc80d56e5658898179150a07a8f824886c