PDF static analysis report

Static analysis result for SHA-256 b75cc29584855fa0…

SUSPICIOUS

PDF

47.3 KB Created: 2021-06-08 16:58:17 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7) First seen: 2021-09-27
MD5: 6813b5b651342f6df521f37b4598b612 SHA-1: 56a2768fc032603ddc32487664600f45865958d3 SHA-256: b75cc29584855fa0251af339b3e5af4aa38d0b5bf17be8c5b39d3451e06218f0
42 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF document contains embedded URLs and a visual call-to-action button, strongly suggesting a phishing or social engineering attempt. The ML classifier also flagged the PDF as malicious. The primary goal appears to be directing the user to download potentially harmful files related to game cheats or hacks from the provided URLs.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9769

Heuristics 3

  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://netcdn.tw/app/431946152/free-headphones-roblox-game-hack PDF link annotation
    • http://sbm-nn.ru/images/get-free-robux-today_GM431946152.pdfIn PDF document text
    • http://sbm-nn.ru/images/free-robux-codes-2021_GM431946152.pdfIn PDF document text
    • http://sbm-nn.ru/images/pokemon-go-no-free-box_GM1094591345.pdfIn PDF document text
    • http://sbm-nn.ru/images/get-free-minecraft-account_GM479516143.pdfIn PDF document text
    • http://sbm-nn.ru/images/norwegian-resort-music-roblox-hack_GM431946152.pdfIn PDF document text
    • http://sbm-nn.ru/images/free-robuxs-free_GM431946152.pdfIn PDF document text
    • http://sbm-nn.ru/images/coin-master-daily-free-spins-link-today-blogspot_GM406889139.pdfIn PDF document text
    • http://sbm-nn.ru/images/coin-master-hack-no-survey_GM406889139.pdfIn PDF document text
    • http://sbm-nn.ru/images/monttechscom-coin-master-free-spins_GM406889139.pdfIn PDF document text
    • http://sbm-nn.ru/images/roblox-generator_GM431946152.pdfIn PDF document text
    • http://sbm-nn.ru/images/best-way-to-get-robux_GM431946152.pdfIn PDF document text
    • http://sbm-nn.ru/images/get-free-robux-without-human-verification_GM431946152.pdfIn PDF document text
    • http://sbm-nn.ru/images/minecraft-java-edition-code-free_GM479516143.pdfIn PDF document text
    • http://sbm-nn.ru/images/farming-simulator-hack-roblox-script_GM431946152.pdfIn PDF document text
    • http://sbm-nn.ru/images/coin-master-hack-version-download_GM406889139.pdfIn PDF document text
    • http://sbm-nn.ru/images/coin-master-free-spins-link-today-new-2021_GM406889139.pdfIn PDF document text
    • http://sbm-nn.ru/images/coin-master-hack-ios-no-verification_GM406889139.pdfIn PDF document text
    • http://sbm-nn.ru/images/free-robux-com-roblox_GM431946152.pdfIn PDF document text
    • http://sbm-nn.ru/images/coin-master-tips_GM406889139.pdfIn PDF document text
    • http://sbm-nn.ru/images/coin-master-cheats_GM406889139.pdfIn PDF document text
    • http://wolfzscriptsIn PDF document text
    • http://en.wikipedia.org/wiki/MIT_LicenseIn PDF document text

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_004_off00004f8e.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x4F8E 26240 bytes
SHA-256: 403a9416828c15548b3500aa912defdd043ec51d6309fd68ca2608958dd683f3
font_01_sfnt_off00008b08.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x8B08 2892 bytes
SHA-256: 514441e3a61c7cc138b3cbbe184afd2860f6700b5711ffaa39edf87d0986d11e
font_02_sfnt_off000094fd.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x94FD 18692 bytes
SHA-256: 3626bbaddedb5307335491d5f0511300c460a9df61cb010271ef3275ee4e7a28