PDF static analysis report

Static analysis result for SHA-256 f63122e20610a838…

SUSPICIOUS

PDF

33.8 KB Created: 2021-06-28 14:45:32 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7) First seen: 2021-09-27
MD5: cc0faba419e5bb01af6800c1315f92f1 SHA-1: cc91ac544026e63102b97aa17355af73cefe9496 SHA-256: f63122e20610a8388091867d2ae59bf77ebf86b20f0964b7ce161a7ca3d41fff
42 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The ML classifier strongly indicates maliciousness, and the document body contains multiple URLs promoting game hacks and cheats. The presence of embedded URLs and the document's theme suggest it is designed to trick users into downloading malware disguised as game cheats. No scripts were extracted, but the document's structure and content point towards a phishing or malware distribution attempt.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9980

Heuristics 3

  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://netcdn.co/app/431946152/roblox-hacks-2021-download-game-hack PDF link annotation
    • https://ptun-kupang.go.id/new/public/ckfinder/userfiles/files/top-ten-ways-to-get-free-robux_GM431946152.pdfIn PDF document text
    • https://ptun-kupang.go.id/new/public/ckfinder/userfiles/files/coin-master-daily-free-spins-blogspot_GM406889139.pdfIn PDF document text
    • https://ptun-kupang.go.id/new/public/ckfinder/userfiles/files/free-spin-coin-master-new-link_GM406889139.pdfIn PDF document text
    • https://ptun-kupang.go.id/new/public/ckfinder/userfiles/files/coin-master-free-spin-link-today-50_GM406889139.pdfIn PDF document text
    • https://ptun-kupang.go.id/new/public/ckfinder/userfiles/files/coin-master-hack-link_GM406889139.pdfIn PDF document text
    • https://ptun-kupang.go.id/new/public/ckfinder/userfiles/files/get-free-robux-instantly_GM431946152.pdfIn PDF document text
    • https://ptun-kupang.go.id/new/public/ckfinder/userfiles/files/free4mobile24-roblox-hack_GM431946152.pdfIn PDF document text
    • https://ptun-kupang.go.id/new/public/ckfinder/userfiles/files/free-pet-roblox-pet-simulator_GM431946152.pdfIn PDF document text
    • https://ptun-kupang.go.id/new/public/ckfinder/userfiles/files/2021-roblox-hacks-mac_GM431946152.pdfIn PDF document text
    • https://ptun-kupang.go.id/new/public/ckfinder/userfiles/files/rblx-gg-free-robux_GM431946152.pdfIn PDF document text
    • https://ptun-kupang.go.id/new/public/ckfinder/userfiles/files/free-robux-without-doing-anything_GM431946152.pdfIn PDF document text
    • https://ptun-kupang.go.id/new/public/ckfinder/userfiles/files/roblox-sexually_GM431946152.pdfIn PDF document text
    • https://ptun-kupang.go.id/new/public/ckfinder/userfiles/files/free-headless-head-roblox_GM431946152.pdfIn PDF document text
    • https://ptun-kupang.go.id/new/public/ckfinder/userfiles/files/pokemon-go-free-coins-hack_GM1094591345.pdfIn PDF document text
    • https://ptun-kupang.go.id/new/public/ckfinder/userfiles/files/free-robux-now-com_GM431946152.pdfIn PDF document text
    • https://ptun-kupang.go.id/new/public/ckfinder/userfiles/files/midnight-racing-sur-roblox-free-tier-2-car_GM431946152.pdfIn PDF document text
    • https://ptun-kupang.go.id/new/public/ckfinder/userfiles/files/free-coins-coin-master-link-2021_GM406889139.pdfIn PDF document text
    • https://ptun-kupang.go.id/new/public/ckfinder/userfiles/files/free-robux-website-roblox_GM431946152.pdfIn PDF document text
    • https://ptun-kupang.go.id/new/public/ckfinder/userfiles/files/free-roblox-gift-card_GM431946152.pdfIn PDF document text
    • https://ptun-kupang.go.id/new/public/ckfinder/userfiles/files/free-robux-easy-and-fast_GM431946152.pdfIn PDF document text
    • http://en.wikipedia.org/wiki/MIT_LicenseIn PDF document text

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00002e2e.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x2E2E 21500 bytes
SHA-256: 085308a5308d59fb809c6e599c6e79975c2ffc0e260c055814025c01b5dbe9cb
font_01_sfnt_off00005d00.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x5D00 19564 bytes
SHA-256: c2033b0ac83c3754d68734bc85b38383babbff081d5f5d1175244d7b8cfff6c1