PDF static analysis report

Static analysis result for SHA-256 bf5f32085c5ebf0f…

SUSPICIOUS

PDF

57.9 KB Created: 2021-04-05 21:44:26 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7) First seen: 2021-09-23
MD5: f4350b83e33a11fb506248ac8e326185 SHA-1: 4c34066e7f815876616a3411958fcb408e85b915 SHA-256: bf5f32085c5ebf0f884bea8233f3dd89af3189f78a200706add8f26b197e58fd
42 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

This PDF document was flagged as suspicious by an ML classifier. The file presents a deceptive download button. Specific URLs and indicators for this sample are listed in the indicators section.

Machine Learning

  • Nyx PDF Classifier malicious score 0.8202

Heuristics 3

  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://gaminggenerator.org/app/431946152/free-robux-without-kack PDF link annotation
    • http://szekelymozes.ro/images/free-team-deathmatch-map-roblox.pdfIn PDF document text
    • https://ogm-goettingen.de/images/roblox-exploit-for-free-download.pdfIn PDF document text
    • http://pa-tanjungselor.go.id/images/free-robux-generator-without-human-verification-without-tix.pdfIn PDF document text
    • https://www.najeebqasmi.com/images/how-to-get-2-000-robux-for-free.pdfIn PDF document text
    • http://www.evaplast.by/images/roblox-cheats-for-mac.pdfIn PDF document text
    • https://www.udivadlahotel.cz/images/how-to-instal-roblox-hack.pdfIn PDF document text
    • http://learningarabic.co.uk/images/free-robux-with-no-games.pdfIn PDF document text
    • http://www.occquimica.com.br/images/was-roblox-hacked-2021.pdfIn PDF document text
    • http://peche-madagascar.com/images/how-to-get-roblox-free-aventures.pdfIn PDF document text
    • http://shahriyarclimb.com/images/hacks-in-roblox-jailbreak-2021.pdfIn PDF document text
    • http://bi-bordtennis.dk/images/new-free-items-on-roblox-promocode-november-2021.pdfIn PDF document text
    • http://harmonygardens.ca/images/how-to-hack-accounts-in-roblox-2021.pdfIn PDF document text
    • http://ecoleduchat-grenoble.fr/images/roblox-vehihicle-simulaot-hacks.pdfIn PDF document text
    • http://escolaarboc.cat/images/hack-acounts-roblox-site.pdfIn PDF document text
    • https://www.utalii.ac.ke/images/roblox-robux-hack-apk-2021.pdfIn PDF document text
    • https://www.brainpads.com/images/free-swat-roblox-jailbreak-pastebin.pdfIn PDF document text
    • http://acktivities.com/images/prisonbreaker-hack-script-roblox.pdfIn PDF document text
    • https://www.air-shop.cz/images/roblox-bee-swarm-simulator-hack-script-pastebin.pdfIn PDF document text
    • http://zarinnameh.ir/images/free-robux-no-verification-or-survey-2021.pdfIn PDF document text
    • http://www.peterdejonge.nl/images/robux-free-no-human-verification-2021.pdfIn PDF document text
    • https://yarburservices.ru/images/roblox-hack-ulimited-robux.pdfIn PDF document text
    • https://icefuture.ru/images/how-to-get-free-easy-robux-vortexx.pdfIn PDF document text
    • https://bancroftandsons.com/images/how-to-hack-any-roblox-games-unlimited-health.pdfIn PDF document text
    • http://hotel-buta.by/images/counter-blox-roblox-hack-2021.pdfIn PDF document text
    • http://safari-crimea.com/images/how-to-use-an-illuminati-skybox-hack-on-roblox.pdfIn PDF document text
    • https://www.ferienhausdirektkroatien.de/images/ultimate-driving-roblox-cheat-speeding.pdfIn PDF document text
    • https://gomsa.nl/images/how-to-hack-roblox-games-with-scripts.pdfIn PDF document text
    • http://jobsy.com.sg/images/free-clothes-for-roblox-2021-youtube.pdfIn PDF document text
    • http://androidthai.in.th/images/free-robux-no-pass-or-survey.pdfIn PDF document text
    • http://properteez.com/images/roblox-working-robux-hack-2021.pdfIn PDF document text
    • http://modlingua.com/images/comment-hacker-les-map-roblox.pdfIn PDF document text
    • http://zarinnameh.ir/images/how-to-speedhack-roblox-without-cheat-engine.pdfIn PDF document text
    • http://legs11.co.za/images/free-robux-card-codes-for-kids.pdfIn PDF document text
    • http://energyline.co/images/free-robux-web-site-2021.pdfIn PDF document text
    • http://condit-pack.com/images/roblox-hack-2021-robux-2021-pc.pdfIn PDF document text
    • http://www.exikom.com.ua/images/the-hack-spot-how-to-get-free-robux-on-roblox.pdfIn PDF document text
    • http://prohsa.com/images/good-free-stuff-on-roblox.pdfIn PDF document text
    • http://learningarabic.co.uk/images/arrest-me-and-get-free-robux-roblox-jailbreak-roblox-live.pdfIn PDF document text
    • https://www.cj-aircons.co.za/images/how-to-noclip-in-roblox-no-hack-2021.pdfIn PDF document text
    • http://www.mjclautrec.fr/images/how-to-hack-surf-leaderboard-roblox.pdfIn PDF document text
    • http://www.comitatoiseo.org/images/roblox-free-auto-clicker.pdfIn PDF document text
    • http://panaceafamilymedicine.com/images/site-de-hack-roblox-xbox.pdfIn PDF document text
    • http://posterprintshop.nl/images/cheat-in-roblox-jailbreak-money.pdfIn PDF document text
    • https://www.gvandenakker.nl/images/roblox-how-to-get-rid-of-the-anti-cheat.pdfIn PDF document text
    • http://prodent.com.ua/images/hack-roblox-robux-gratuit.pdfIn PDF document text
    • http://hotel-buta.by/images/hacker-tycoon-roblox.pdfIn PDF document text
    • http://androidthai.in.th/images/youtube-hack-any-roblox-account-no-loading.pdfIn PDF document text
    • http://gestibrok.com/images/roblox-fight-the-monsters-cheats.pdfIn PDF document text
    • https://arcasict.nl/images/hack-para-atravesar-paredes-en-roblox.pdfIn PDF document text
    +15 more URL(s)

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_003_off000083a0.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x83A0 25776 bytes
SHA-256: 86c4c8bd15082724a476263143880fd33d3759a1a8b38ee6f1c2fcdbb20859ec
font_01_sfnt_off0000bea5.bin pdf-font-stream PDF embedded font (sfnt) at offset 0xBEA5 18372 bytes
SHA-256: ea0d4d197316d7dcdbe966ca9c072a234ddb7ff2dc0c914f315a673e9c89fb14