PDF static analysis report

Static analysis result for SHA-256 f1fe47e13d6bad55…

SUSPICIOUS

PDF

39.8 KB Created: 2021-04-03 20:10:40 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7) First seen: 2021-09-16
MD5: 8b231715c8adaa94870fce821a259076 SHA-1: 686a04a90f031e58e5decd4f73b9049a3b3aa47f SHA-256: f1fe47e13d6bad553304a90d18340bf082ee279c0b1f7ac12c9934aa5f138149
42 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF document contains numerous URLs and a prominent external URI pointing to sites offering 'free Roblox hacks' and 'Robux'. The ML classifier flagged this PDF as malicious with high confidence. The document body, though partially garbled, also contains references to these lures and URLs, suggesting an attempt to trick users into visiting malicious sites for in-game currency or cheats. No scripts were extracted, but the presence of external links and the ML detection strongly indicate a phishing or malware distribution attempt.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9500

Heuristics 3

  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://gaminggenerator.org/app/431946152/free-roblox-hacks-net PDF link annotation
    • https://www.sitiwebjoomla.it/images/free-roblox-promo-codes-for-robux.pdf%0AIn PDF document text
    • https://hbln.org.au/images/roblox-redeem-codes-for-free.pdf%0AIn PDF document text
    • https://www.seeingindependence.org/images/roblox-google-shop-for-free.pdf%0AIn PDF document text
    • https://esl.ipb.ac.id/images/roblox-royale-high-hack-club.pdf%0AIn PDF document text
    • http://www.malonmalon.com.ar/images/rainbow-antlerts-free-roblox.pdf%0AIn PDF document text
    • https://esl.ipb.ac.id/images/roblox-free-play-no-download-login.pdf%0AIn PDF document text
    • http://www.torvet11.dk/images/free-headless-horseman-roblox.pdf%0AIn PDF document text
    • http://www.drent.se/images/free-roblox-boy-hair-not-a-model.pdf%0AIn PDF document text
    • http://www.lovecraftiana.com.ar/images/roblox-reach-hack.pdf%0AIn PDF document text
    • https://www.elevage-chiot.fr/images/com-free-robux.pdf%0AIn PDF document text
    • http://kids-academy.pl/images/how-to-change-your-username-in-roblox-for-free-2021.pdf%0AIn PDF document text
    • https://www.osoc.com/images/free-run-roblox.pdf%0AIn PDF document text
    • http://uctovnictvosnv.sk/images/roblox-shirt-girl-free.pdf%0AIn PDF document text
    • https://amatq.ca/images/how-to-hack-on-vehicle-sim-roblox.pdf%0AIn PDF document text
    • https://www.hbproducts.dk/images/hack-roblox-jailbreak-mode.pdf%0AIn PDF document text
    • http://sscclc.edu.ec/images/how-to-teleport-using-cheat-engine-roblox.pdf%0AIn PDF document text
    • https://jdlgroup.ca/images/how-to-call-roblox-for-hacked-account.pdf%0AIn PDF document text
    • https://www.eglihotel.gr/images/download-hacked-fersion-of-roblox.pdf%0AIn PDF document text
    • http://www.eurologistiki.gr/images/cheat-roblox-2021.pdf%0AIn PDF document text
    • http://www.gadanie.lv/images/how-to-get-free-robux-without-doing-anything-2021.pdf%0AIn PDF document text
    • https://amatq.ca/images/hacks-for-roblox-pet-simulator.pdf%0AIn PDF document text
    • http://gops.pruszczgdanski.pl/images/hacker-shirts-roblox.pdf%0AIn PDF document text
    • https://www.dierenartsberghman.be/images/descragr-hack-roblox.pdf%0AIn PDF document text
    • http://nevesomost.by/images/roblox-site-hacks.pdf%0AIn PDF document text
    • http://safeandsecurelocksmith.ca/images/free-admin-roblox-jailbreak.pdf%0AIn PDF document text
    • https://www.hbproducts.dk/images/how-to-use-an-illuminati-skybox-hack-on-roblox.pdf%0AIn PDF document text
    • https://www.udivadlahotel.cz/images/roblox-unlimited-fps-hack.pdf%0AIn PDF document text
    • http://www.lycee-langevin-wallon.com/images/cheats-to-get-cars-in-car-crashers-2-roblox.pdf%0AIn PDF document text
    • https://www.fhccu.com/images/how-to-insert-a-hack-script-into-roblox-game.pdf%0AIn PDF document text
    • http://www.nielsen2u.dk/images/game-test-roblox-free-bc.pdf%0AIn PDF document text
    • http://en.wikipedia.org/wiki/MIT_LicenseIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_003_off000043c1.bin decompressed-pdf-stream PDF FlateDecoded stream at offset 0x43C1 23396 bytes
SHA-256: a5325cf3e6755d80695a2cf8fddc8512fdfc2fc113ee05d087700b5e22444246
font_01_sfnt_off000078b6.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x78B6 18012 bytes
SHA-256: 82bb74be69784d0c19fa6d1bb5b45964a4de0f42ef3c0f62d78a80d3128cd53a