Malicious PDF — malware analysis report

Static analysis result for SHA-256 35e730b85d6cb13d…

MALICIOUS

PDF

34.6 KB Created: 2021-07-03 15:20:49 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: faee76ee72cac2300354bf3f4aa93010 SHA-1: cfbf8d6034a9785b14c09575ada8fb53912ef1f2 SHA-256: 35e730b85d6cb13d78cd7cea0dc99d62197178b0572288db4c1433c19dc03356
62 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The document contains lures for free Robux and game hacks, directing users to download potentially malicious files from external URLs. The ML classifier strongly flagged this PDF as malicious, and the presence of embedded URLs further supports a phishing or malware distribution attempt. No scripts were extracted, but the overall pattern suggests a phishing campaign aiming to deliver a second-stage payload.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9980

Heuristics 4

  • Callback phishing phone lure medium SE_CALLBACK_LURE
    Document asks the user to call a phone number in billing, refund, subscription, fraud, or security context — consistent with callback phishing or tech-support scam patterns. Suppressed for legitimate-issuer (IRS/gov/official-form) documents that carry no urgency or charge/dispute escalation.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://netcdn.tw/app/431946152/robux-fun-hack-game-hack
    • http://perpustakaan.pn-tapaktuan.go.id/repository/how-to-hack-roblox-accounts-on-phone_GM431946152.pdf
    • http://perpustakaan.pn-tapaktuan.go.id/repository/what-is-a-robux_GM431946152.pdf
    • http://perpustakaan.pn-tapaktuan.go.id/repository/como-hackear-coin-master-en-espaol_GM406889139.pdf
    • http://perpustakaan.pn-tapaktuan.go.id/repository/free-robux-2021_GM431946152.pdf
    • http://perpustakaan.pn-tapaktuan.go.id/repository/best-legit-free-robux_GM431946152.pdf
    • http://perpustakaan.pn-tapaktuan.go.id/repository/games-wich-you-can-hack-on-roblox_GM431946152.pdf
    • http://perpustakaan.pn-tapaktuan.go.id/repository/how-to-hack-roblox-for-billions-robux_GM431946152.pdf
    • http://perpustakaan.pn-tapaktuan.go.id/repository/comment-hacks-roblox-2021-download_GM431946152.pdf
    • http://perpustakaan.pn-tapaktuan.go.id/repository/coin-master-2021-free-spins_GM406889139.pdf
    • http://perpustakaan.pn-tapaktuan.go.id/repository/https-web-roblox-com-hack_GM431946152.pdf
    • http://perpustakaan.pn-tapaktuan.go.id/repository/how-to-get-minecraft-for-free-on-mac_GM479516143.pdf
    • http://perpustakaan.pn-tapaktuan.go.id/repository/free-roblox-promo-codescom_GM431946152.pdf
    • http://perpustakaan.pn-tapaktuan.go.id/repository/meepcity-roblox-hack_GM431946152.pdf
    • http://perpustakaan.pn-tapaktuan.go.id/repository/roblox-btools-hack-2021-download_GM431946152.pdf
    • http://perpustakaan.pn-tapaktuan.go.id/repository/roblox-zall-site-free-robux_GM431946152.pdf
    • http://perpustakaan.pn-tapaktuan.go.id/repository/how-to-get-free-robux-without-having-to-do-anything_GM431946152.pdf
    • http://perpustakaan.pn-tapaktuan.go.id/repository/how-to-get-free-audio-uin-roblox-2021_GM431946152.pdf
    • http://perpustakaan.pn-tapaktuan.go.id/repository/robux-hack-no-verification-no-survey_GM431946152.pdf
    • http://perpustakaan.pn-tapaktuan.go.id/repository/admin-hacks-roblox-ban-pll_GM431946152.pdf
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00002f70.bin
e6525ff23de632c2fccf235338b4a36d3792e2611ad9c72caec3de2d8abab089
pdf-font-stream PDF embedded font (sfnt) at offset 0x2F70 22780 bytes
font_01_sfnt_off000062c3.bin
c1015eee087a13dc62c4aba5d792f044bb527228a7c6867863e8b6cb34361f4d
pdf-font-stream PDF embedded font (sfnt) at offset 0x62C3 18884 bytes