Malicious PDF — malware analysis report

Static analysis result for SHA-256 85dc5069774b57a7…

MALICIOUS

PDF

35.1 KB Created: 2021-07-05 14:15:53 +07:00 Authoring application: wkhtmltopdf 0.12.6 (via Qt 4.8.7)
MD5: 384fa7bd444828a7e142bc88c2cb3788 SHA-1: adb3d6677d3f697b072b9978d62bf92761f1610c SHA-256: 85dc5069774b57a786d3b5098f98dd1c558a178b135cad3bf8675435e8b2ba13
82 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious File

The PDF document contains a clear lure for a 'Roblox Password Cracker' and an embedded URI pointing to a download URL. The presence of a 'password-protected archive' heuristic suggests the document is designed to trick users into downloading an encrypted payload, likely the password cracker itself. The ML classifier also strongly flagged this PDF as malicious.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9980

Heuristics 4

  • Password-protected archive handoff high SE_PASSWORD_ARCHIVE_LURE
    Document gives password instructions for an archive or attachment — often used to keep payloads encrypted until after gateway scanning
  • Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTON
    Document contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
  • External URI info PDF_URI
    PDF contains an external URL action
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://netcdn.tw/app/431946152/roblox-password-cracker-free-download-game-hack
    • https://pasca.unisba.ac.id/elibrary/repository/how-to-get-free-builders-club-on-roblox-mobile_GM431946152.pdf
    • https://pasca.unisba.ac.id/elibrary/repository/robux-money_GM431946152.pdf
    • https://pasca.unisba.ac.id/elibrary/repository/free-robux-for-kids-no-verification_GM431946152.pdf
    • https://pasca.unisba.ac.id/elibrary/repository/roblox-how-to-get-any-gamepass-for-free-2021_GM431946152.pdf
    • https://pasca.unisba.ac.id/elibrary/repository/free-robux-no-human-verification-no-survey-2021-no-password_GM431946152.pdf
    • https://pasca.unisba.ac.id/elibrary/repository/best-free-roblox-items-2021_GM431946152.pdf
    • https://pasca.unisba.ac.id/elibrary/repository/get-a-free-dominus-from-roblox-toy_GM431946152.pdf
    • https://pasca.unisba.ac.id/elibrary/repository/comment-cheater-sur-flach-ticoon-roblox_GM431946152.pdf
    • https://pasca.unisba.ac.id/elibrary/repository/free-robux-codes-no-verification_GM431946152.pdf
    • https://pasca.unisba.ac.id/elibrary/repository/free-roblox-player-download_GM431946152.pdf
    • https://pasca.unisba.ac.id/elibrary/repository/urban-420-network-how-to-get-free-robux_GM431946152.pdf
    • https://pasca.unisba.ac.id/elibrary/repository/roblox-cheats-how-to-get-free-stuff_GM431946152.pdf
    • https://pasca.unisba.ac.id/elibrary/repository/hacks-para-roblox-sin-virus_GM431946152.pdf
    • https://pasca.unisba.ac.id/elibrary/repository/free-spin-link-for-coin-master-game_GM406889139.pdf
    • https://pasca.unisba.ac.id/elibrary/repository/completely-free-robux_GM431946152.pdf
    • https://pasca.unisba.ac.id/elibrary/repository/free-coin-master-spins-2021_GM406889139.pdf
    • https://pasca.unisba.ac.id/elibrary/repository/cool-roblox-high-school-cheats_GM431946152.pdf
    • https://pasca.unisba.ac.id/elibrary/repository/noclip-hack-download-for-roblox_GM431946152.pdf
    • https://pasca.unisba.ac.id/elibrary/repository/blogspot-free-spins-coin-master_GM406889139.pdf
    • https://pasca.unisba.ac.id/elibrary/repository/6-ways-to-get-free-robux_GM431946152.pdf
    • http://en.wikipedia.org/wiki/MIT_License

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00003183.bin
250f090919f8bda50040fbffb3d01aefb874363254208b2c12c35851ebc83072
pdf-font-stream PDF embedded font (sfnt) at offset 0x3183 22420 bytes
font_01_sfnt_off0000637c.bin
2b5ad4d6766727758a08286a3e58e7f6bd8ad14508fcf48a7c240b6c02ef57f1
pdf-font-stream PDF embedded font (sfnt) at offset 0x637C 19296 bytes