Malicious PDF — malware analysis report

Static analysis result for SHA-256 2545b91ca7a0036d…

MALICIOUS

PDF

38.5 KB Created: 2021-05-12 15:31:07 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: 2d283f9dab99d94460021bac5dad7b2c SHA-1: 79bddeade56c0f873eaf447774f368206dcb73af SHA-256: 2545b91ca7a0036db56edd733a1d1d014f39cbe1dc2ecf5d1696372496529aab
72 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF document contains a lure related to hacking Roblox for Robux and explicitly requests sensitive recovery information, indicating a phishing attempt. It also contains an embedded URI pointing to a suspicious domain, likely intended to host a malicious payload or phishing page. No scripts were extracted from this sample, but the document structure and embedded URI suggest a phishing attack.

Machine Learning

  • Nyx PDF Classifier clean score 0.0334

Heuristics 4

  • Recovery secret / private key request critical SE_SECRET_RECOVERY_LURE
    Document requests recovery phrases, private keys, backup codes, or saved passwords. Requests for these secrets in a document are high-risk.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://netcdn.xyz/app/431946152/how-to-hack-roblox-for-robux-game-hack
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
stream_003_off000035a6.bin
e237d12e277c7803dfc48ff52faa7094b0c9e8fc10c981844238596a2501872d
decompressed-pdf-stream PDF FlateDecoded stream at offset 0x35A6 27376 bytes
font_01_sfnt_off0000741c.bin
7689b6731d47fc176aef925fc5194a10a34d162e90d7014a3ccea13949bcaf7e
pdf-font-stream PDF embedded font (sfnt) at offset 0x741C 18648 bytes