Malicious PDF — malware analysis report

Static analysis result for SHA-256 7000b73165730856…

MALICIOUS

PDF

34.5 KB Created: 2021-06-28 05:22:22 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: eb952cac53c85beb47d58127eae2c883 SHA-1: 253c72f8af30c29f3f1f9afd1b55206f9b861865 SHA-256: 7000b73165730856e8a0e1f43906869084f8f31619dcf84eacd4a5ef51c2f6d7
62 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The document body and embedded URLs indicate a lure related to hacking the Roblox game, likely to trick users into downloading malware or providing credentials. The ML classifier strongly flagged this PDF as malicious, and the presence of external URIs suggests a download attempt. No scripts were extracted from this sample, limiting the ability to determine specific execution methods.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9980

Heuristics 4

  • Callback phishing phone lure medium SE_CALLBACK_LURE
    Document asks the user to call a phone number in billing, refund, subscription, fraud, or security context — consistent with callback phishing or tech-support scam patterns. Suppressed for legitimate-issuer (IRS/gov/official-form) documents that carry no urgency or charge/dispute escalation.
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://netcdn.co/app/431946152/how-to-hack-roblox-account-on-phone-game-hack
    • https://sanjoseelectricians.net/images/roblox-hack-god-mode-phantom-forces_GM431946152.pdf
    • https://sanjoseelectricians.net/images/how-to-make-free-shirts-on-roblox-without-bc-2021_GM431946152.pdf
    • https://sanjoseelectricians.net/images/robloxcheatnewcom-hack_GM431946152.pdf
    • https://sanjoseelectricians.net/images/cheat-engine-roblox-money_GM431946152.pdf
    • https://sanjoseelectricians.net/images/roblox-free-games-without-downloading_GM431946152.pdf
    • https://sanjoseelectricians.net/images/robux-gratis-hack-2021-android_GM431946152.pdf
    • https://sanjoseelectricians.net/images/roblox-hacks-for-robux-free-2021_GM431946152.pdf
    • https://sanjoseelectricians.net/images/free-robux-rbxboost_GM431946152.pdf
    • https://sanjoseelectricians.net/images/free-roblox-outfits-2021_GM431946152.pdf
    • https://sanjoseelectricians.net/images/join-roblox-players-game-hack_GM431946152.pdf
    • https://sanjoseelectricians.net/images/free-robux-hack-2021-august_GM431946152.pdf
    • https://sanjoseelectricians.net/images/how-to-hack-robux-on-roblox-2021_GM431946152.pdf
    • https://sanjoseelectricians.net/images/best-roblox-hacks-for-unfiltered-games_GM431946152.pdf
    • https://sanjoseelectricians.net/images/roblox-hack-accounts-online_GM431946152.pdf
    • https://sanjoseelectricians.net/images/free-stuff-hack-roblox_GM431946152.pdf
    • https://sanjoseelectricians.net/images/how-to-get-free-obc-on-roblox-2021_GM431946152.pdf
    • https://sanjoseelectricians.net/images/character-hacks-for-robloxian-highschool-roblox_GM431946152.pdf
    • https://sanjoseelectricians.net/images/free-robux-secret-video-to-get-free-robux_GM431946152.pdf
    • https://sanjoseelectricians.net/images/free-sdcript-executer-for-roblox_GM431946152.pdf
    • https://sanjoseelectricians.net/images/how-to-get-free-robux-without-tix_GM431946152.pdf
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00002f25.bin
524594494f12639f5c14f0e54281617d322459e670f9d974eb8248408b416e2b
pdf-font-stream PDF embedded font (sfnt) at offset 0x2F25 22264 bytes
font_01_sfnt_off000060af.bin
4709d47658b6af8bc287a44896f227d4bb5cf91da3ed8a5084c87588a72db071
pdf-font-stream PDF embedded font (sfnt) at offset 0x60AF 19384 bytes