PDF static analysis report

Static analysis result for SHA-256 a8b307b65c6c3c5b…

SUSPICIOUS

PDF

54.3 KB Created: 2021-06-04 00:14:10 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7) First seen: 2021-09-16
MD5: 97c42b25e41605e2cc8ec602345fc4b3 SHA-1: 185eedb75c77b799234d78414fe1bf7432438224 SHA-256: a8b307b65c6c3c5bdb64c4492fa82d4456578955c04afab74594bff5aa0aa273
42 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains an embedded URL pointing to a resource that appears to be a download link for game hacks. The presence of a 'download button' heuristic further supports the idea that this document is designed to trick users into downloading potentially malicious content. The ML classifier also flagged this PDF as malicious, increasing confidence in its suspicious nature.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9491

Heuristics 3

  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://netcdn.online/app/431946152/roblox-arsenal-hack-script-pastebin-game-hack PDF link annotation
    • https://library.iuli.ac.id/repository/free-minecraft-realm-codes_GM479516143.pdfIn PDF document text
    • https://library.iuli.ac.id/repository/coin-master-free-spins-and-free-coins_GM406889139.pdfIn PDF document text
    • https://library.iuli.ac.id/repository/i-want-free-robux_GM431946152.pdfIn PDF document text
    • https://library.iuli.ac.id/repository/free-spins-coin-master-no-human-verification_GM406889139.pdfIn PDF document text
    • https://library.iuli.ac.id/repository/free-robux-on-ipad_GM431946152.pdfIn PDF document text
    • https://library.iuli.ac.id/repository/minecraft-116-apk-download_GM479516143.pdfIn PDF document text
    • https://library.iuli.ac.id/repository/free-robux-no-human-verification-or-survey-or-download-2021_GM431946152.pdfIn PDF document text
    • https://library.iuli.ac.id/repository/coin-master-hack-without-verification-2021_GM406889139.pdfIn PDF document text
    • https://library.iuli.ac.id/repository/minecraft-on-computer-free_GM479516143.pdfIn PDF document text
    • https://library.iuli.ac.id/repository/coin-master-hack-2021-app-download_GM406889139.pdfIn PDF document text
    • https://library.iuli.ac.id/repository/get-free-spins-coin-master-2021_GM406889139.pdfIn PDF document text
    • https://library.iuli.ac.id/repository/free-tiktok-likes-without-verification_GM835599320.pdfIn PDF document text
    • https://library.iuli.ac.id/repository/free-robux-without-verification-2021_GM431946152.pdfIn PDF document text
    • https://library.iuli.ac.id/repository/coin-master-heaven-daily-free-spins_GM406889139.pdfIn PDF document text
    • https://library.iuli.ac.id/repository/free-robux-games-that-actually-work-2021_GM431946152.pdfIn PDF document text
    • https://library.iuli.ac.id/repository/how-do-you-get-free-robux-without-doing-anything_GM431946152.pdfIn PDF document text
    • https://library.iuli.ac.id/repository/coin-master-free-spins-daily-2021_GM406889139.pdfIn PDF document text
    • https://library.iuli.ac.id/repository/twitter-coin-master-free-spins_GM406889139.pdfIn PDF document text
    • https://library.iuli.ac.id/repository/roblox-free-clothes-hack_GM431946152.pdfIn PDF document text
    • https://library.iuli.ac.id/repository/how-to-get-free-robux-gift-cards_GM431946152.pdfIn PDF document text
    • http://en.wikipedia.org/wiki/MIT_LicenseIn PDF document text

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_004_off0000523c.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x523C 27832 bytes
SHA-256: 674ca871dfe89031e6a256c3f34566f67f7cf4755b930bcf4859453e59a8e945
font_01_sfnt_off00009034.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x9034 5764 bytes
SHA-256: 81536dfb6a739917d95f48a9a261cc6371794711a4da1a9ac19377646d730d32
font_02_sfnt_off0000a362.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xA362 5596 bytes
SHA-256: 9a13c2580265a78e8a7257496a31ee0055738af7e20a5661c2902efe4bf05ce5
font_03_sfnt_off0000b00a.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xB00A 18736 bytes
SHA-256: 7de8619ef554dfe1f2192c4aca90399aa0815846f6a8f71df992d0e349aeb038