Malicious PDF — malware analysis report

Static analysis result for SHA-256 34f8b542d2ec7afc…

MALICIOUS

PDF

34.3 KB Created: 2021-07-05 18:43:45 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: 40159f27d23ed7f80745512dd05b4b9a SHA-1: 40edd8566a41269a6786d46e0581dcc79d9d22cb SHA-256: 34f8b542d2ec7afcf00b1dd952297626e10d8754bf161ad1f01aff581fd17d01
62 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 User Execution: Malicious File

The document body and extracted URLs indicate a lure for "Free Robux" and game hacks, consistent with phishing or malware distribution. The presence of multiple external URLs suggests an attempt to redirect the user to download malicious content. The ML classifier also flagged this PDF as malicious with high confidence.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9980

Heuristics 4

  • Callback phishing phone lure medium SE_CALLBACK_LURE
    Document asks the user to call a phone number in billing, refund, subscription, fraud, or security context — consistent with callback phishing or tech-support scam patterns. Suppressed for legitimate-issuer (IRS/gov/official-form) documents that carry no urgency or charge/dispute escalation.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://netcdn.tw/app/431946152/free-robux-promo-codes-game-hack
    • http://smkn1salatiga.sch.id/library/repository/descargar-roblox-hack-2391_GM431946152.pdf
    • http://smkn1salatiga.sch.id/library/repository/how-to-hack-on-roblox-on-a-phone_GM431946152.pdf
    • http://smkn1salatiga.sch.id/library/repository/how-to-hack-roblox-accounts-on-phone_GM431946152.pdf
    • http://smkn1salatiga.sch.id/library/repository/roblox-cool-and-free-hat_GM431946152.pdf
    • http://smkn1salatiga.sch.id/library/repository/roblox-cheat-codes-feeling-of-falling_GM431946152.pdf
    • http://smkn1salatiga.sch.id/library/repository/coin-master-hack-without-verification-code_GM406889139.pdf
    • http://smkn1salatiga.sch.id/library/repository/roblox-catalog-free-hair_GM431946152.pdf
    • http://smkn1salatiga.sch.id/library/repository/roblox-script-hack_GM431946152.pdf
    • http://smkn1salatiga.sch.id/library/repository/how-to-hack-anyones-roblox-account-2021_GM431946152.pdf
    • http://smkn1salatiga.sch.id/library/repository/free-robux-websites-2021_GM431946152.pdf
    • http://smkn1salatiga.sch.id/library/repository/free-robux-com-roblox_GM431946152.pdf
    • http://smkn1salatiga.sch.id/library/repository/how-to-get-free-tokens-in-minecraft-ps4_GM479516143.pdf
    • http://smkn1salatiga.sch.id/library/repository/how-to-get-free-robux-in-roblox-on-ipad-2021_GM431946152.pdf
    • http://smkn1salatiga.sch.id/library/repository/free-robux-twitter_GM431946152.pdf
    • http://smkn1salatiga.sch.id/library/repository/roblox-free-robux-hack_GM431946152.pdf
    • http://smkn1salatiga.sch.id/library/repository/coin-master-game-download-free_GM406889139.pdf
    • http://smkn1salatiga.sch.id/library/repository/hackear-prison-life-roblox-2021-pc-dansploit_GM431946152.pdf
    • http://smkn1salatiga.sch.id/library/repository/free-robux-no-human-verification-or-survey_GM431946152.pdf
    • http://smkn1salatiga.sch.id/library/repository/wahoo-gaming-co-free-robux_GM431946152.pdf
    • http://smkn1salatiga.sch.id/library/repository/roblox-hackeado_GM431946152.pdf
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00002ef8.bin
bb2c22c8dfbeb45143169678f6a3e5b064e3240e6eaeb2d3defababb8c946de7
pdf-font-stream PDF embedded font (sfnt) at offset 0x2EF8 22240 bytes
font_01_sfnt_off00006068.bin
b8217d46ff736f49d3e7fbbf4ad016b5c147b05ee0ff1e8951011688dc8d1bae
pdf-font-stream PDF embedded font (sfnt) at offset 0x6068 19304 bytes