Malware usually goes to some trouble to look boring. It dresses up as a font installer, a delivery notification, or a routine software update. Incident 408 skipped all of that. It announced what it was, stated its preferred working conditions, and included operating instructions, all in the filename.
Nobody at the customer was targeted. Somebody just wanted to edit a PDF without paying for the software, found a free copy online, and unzipped it. StrongKeep blocked the file on the device before it ran.
At a Glance
- Incident: 408
- Customer: a Singapore SME (anonymised)
- Threat: a licence cracking tool bundled inside a pirated PDF editor
- How it arrived: downloaded by a staff member and extracted to disk using Windows File Explorer, the normal file browsing program
- What StrongKeep did: blocked the file on the endpoint before it was run
- Outcome: the crack never executed, no administrator rights were granted, and the device was cleaned
The Filename Was the Entire Warning
The file landed here, in the Downloads folder of a standard user account:
C:\Users\user\Downloads\WINDOWS PDF.2025 v25.001\WIN PDF 2025\第二步crack(右键以管理员运行).exe
For anyone who does not read Chinese, that translates to roughly "step two crack (right-click to run as administrator)". Two things are worth sitting with. The first is "step two", which implies a step one that had already happened and a step three that was still to come. The second is that the file asks, by name, for the highest level of access on the machine.
The same file has been seen elsewhere under an English name, and whoever chose it was not hiding anything either:
"STEP 2 CRACK PLEASE DISABLE ANTIVIRUS BEFORE EXTRACTING THIS.exe"
The actual filename, capital letters and allThis is the part that deserves a moment of respect. The attacker did not need a zero-day, a phishing email, or a clever lure. They simply asked people to turn off their security software, and enough people do it that the technique keeps paying.
What the File Actually Was
Thirty-one of seventy security vendors flagged the sample as malicious, and its community score sat at -12. The behavioural tags attached to it tell a consistent story:
- peexe confirms it is a Windows executable, not the document or utility a user might assume they had downloaded.
- calls-wmi means it reaches into a management interface that is built into every copy of Windows. Attackers like it because it is already installed, already trusted, and already permitted to make changes.
- detect-debug-environment means the file checks whether it is being watched by an analyst before deciding how to behave. Legitimate software has no reason to care.
- overlay means extra data has been bolted onto the end of the file, a common way to smuggle a second payload inside something that still looks like one program.
A tool whose only advertised job is patching a licence check does not need to evade analysts or hide a second payload. The crack was the bait. Whatever was in the overlay was the business model.
If you want to check this sample against your own tooling, or search your estate for it, the SHA-256 is:
c44b70655b22bce392a0b29ba7ddf4fcf39976fdad8ba0c6cd6585b2e11a059d
How It Got There
There was no exploit and no compromised website pushing files onto the machine. StrongKeep recorded that the file was written to disk by Windows File Explorer, which is the ordinary program people use to browse folders. That detail matters, because it tells us exactly what happened in human terms: a member of staff downloaded a folder of PDF editing software, opened it, and extracted the contents.
Windows did precisely what it was told. So did the person. This is the uncomfortable truth about most SME incidents. They are not sophisticated. They are somebody trying to get their job done with the tools they could find.
How StrongKeep Blocked It
StrongKeep's endpoint protection identified the file as malicious as it landed on disk and blocked it there. The crack was never executed, so it never got the administrator rights its own filename was asking for, and "step three" never arrived.
Worth noting what did not have to happen. Nobody had to spot the Chinese filename. Nobody had to recognise that a free PDF editor with a bundled crack was a bad idea. Nobody had to resist the instruction to disable their antivirus, which was the one instruction the whole attack depended on. The protection held at the point where human judgement had already been overtaken by the desire to finish a document.
"If a program asks you to switch off your antivirus before you open it, it has already told you what it is."
StrongKeep Security TeamWhy the Free Version Is Rarely Free
Cracks are unusually effective delivery vehicles, for reasons that have nothing to do with technical skill:
- They come with permission to disable your defences. No other category of software can ask this and be taken seriously. A crack can, because users expect a false positive.
- They need administrator rights by design. Patching a licence check means writing to protected files, so anything riding along inherits full control of the machine.
- Nobody reports them. If the PDF editor works, the user assumes it went fine. If something feels off afterwards, admitting it means admitting to installing pirated software.
There is a second bill, too. Unlicensed software on a company device is a compliance problem in its own right. Cyber Essentials, most customer security questionnaires, and any serious procurement review will ask whether your software is licensed and supported. "One of the team found a free copy" is not an answer that survives contact with an auditor or a client.
What to Do Instead
- Check what you already own. Most PDF work at an SME is filling, signing, merging and converting. Microsoft Edge and most modern browsers handle a lot of that, and Word will open and edit a PDF directly. The paid editor is often solving a problem nobody actually has.
- Take administrator rights off day-to-day accounts. A standard user cannot install a crack even if they want to, which removes the decision from the moment of temptation.
- Run endpoint protection that stops the file, not just the website. This one arrived inside a folder a user had already downloaded and unzipped. Blocking it needed something watching the device itself.
- Make it easy to ask. Staff go looking for cracked software when buying the real thing is slow or awkward. A clear route to request a licence, answered in days, is a cheaper security control than most tools you can buy.
The employee in this case was not careless or reckless. They had a document to finish and found something that promised to help. That is going to keep happening, in every business, forever. The job of security is to make sure it stays a wasted afternoon instead of an incident.