MALICIOUS
90
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1204.002 Malicious Link
The PDF document uses social engineering tactics, specifically a lure for free Robux, to trick users into clicking embedded links. The heuristic 'SE_BROWSER_INSTALL_LURE' indicates the document likely prompts the user to install a browser extension or plugin, which is a common method for delivering malware or stealing credentials. The presence of numerous external URLs further supports the malicious intent of directing users to potentially harmful sites.
Machine Learning
- Nyx PDF Classifier malicious score 0.6397
Heuristics 5
-
Browser extension / update installation lure high SE_BROWSER_INSTALL_LUREDocument tells the user to install a browser extension, plugin, viewer, or browser update to view content — a common social-engineering path for credential theft and malware installation
-
Urgency / deadline lure low SE_URGENCY_LUREDocument contains urgency or deadline language ('account will be terminated', 'action required within 24 hours', etc.) — useful context, but low-signal without other findings
-
Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTONDocument contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
-
External URI info PDF_URIPDF contains an external URL action
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL http://gaminggenerator.org/app/431946152/robux-roblox-free-robux PDF link annotation
- http://mydevice.com.au/images/free-robux-codes-generator-works.pdfIn PDF document text
- https://www.stkdb.cz/images/00-hacker-roblox.pdfIn PDF document text
- https://socialvalue.gr/images/hack-de-roblox-robux-gratis.pdfIn PDF document text
- http://medimacs.eu/images/how-to-get-free-robux-no-survey-no-human-verification.pdfIn PDF document text
- https://www.hbproducts.dk/images/hack-avec-les-code-promo-roblox.pdfIn PDF document text
- http://act.gr/images/how-to-get-free-robux-in-roblox-pastebin-2021.pdfIn PDF document text
- http://www.art-concept.gr/images/free-100-robux-gift-card-codes-2021.pdfIn PDF document text
- http://engelum.com/images/weapon-hack-roblox-pastebin.pdfIn PDF document text
- http://naturschutzgossau-zh.ch/images/bit-slicer-speed-hack-roblox.pdfIn PDF document text
- http://picuruta.com.br/images/jane-doe-roblox-hack.pdfIn PDF document text
- http://wokbaarlo.nl/images/free-ways-to-get-xbox-only-things-on-roblox.pdfIn PDF document text
- https://www.tsdb.com.au/images/roblox-vampire-hunters-2-hack.pdfIn PDF document text
- http://cadcam.no/images/jeux-de-hacking-sur-roblox.pdfIn PDF document text
- https://www.albisser.ch/images/roblox-what-do-you-do-when-your-account-gets-hacked.pdfIn PDF document text
- http://www.gadanie.lv/images/free-roblox-robux-codes-2021.pdfIn PDF document text
- https://pa-waingapu.go.id/images/how-to-have-the-gamepass-for-pet-simulator-roblox-free.pdfIn PDF document text
- https://pemadamapi.net/images/free-robux-obby-husky.pdfIn PDF document text
- http://osteonad.com/images/roblox-cheats-for-laptop.pdfIn PDF document text
- https://rincondelentrenador.com/images/how-to-hack-money-roblox-jailbreak.pdfIn PDF document text
- http://zarinnameh.ir/images/f-free-robux.pdfIn PDF document text
- https://www.fenews.co.uk/images/roblox-cheat-engine-wallhack.pdfIn PDF document text
- http://www.mikramarine.gr/images/roblox-free-sword-gear.pdfIn PDF document text
- http://horsa18.ru/images/roblox-hack-download-unlimited-robux.pdfIn PDF document text
- http://getthelook-bkk.com/images/best-roblox-hack-scripts-paste-bin.pdfIn PDF document text
- https://gomsa.nl/images/free-working-robux.pdfIn PDF document text
- http://arcnjournals.org/images/where-to-find-roblox-hacks.pdfIn PDF document text
- https://kimolos-link.gr/images/how-to-make-a-free-model-roblox-2021.pdfIn PDF document text
- https://stroyzakazremont.ru/images/cheat-engine-roblox-2021.pdfIn PDF document text
- http://www.gearestauri.it/images/safe-roblox-hacks.pdfIn PDF document text
- https://www.cosmosdawn.net/images/poki-roblox-free.pdfIn PDF document text
- http://www.bripi.pl/images/10-euro-roblox-karte-free.pdfIn PDF document text
- http://auto-mankel.de/images/how-to-get-free-robux-hack-inspect-element.pdfIn PDF document text
- http://wireprod.net/images/roblox-cheat-speed-run.pdfIn PDF document text
- http://ivalor.fr/images/codes-for-free-clothing-on-roblox.pdfIn PDF document text
- https://www.cnte.org.br/images/dfield-free-robux.pdfIn PDF document text
- https://www.lomrad.go.th/images/roblox-r2d-money-hack.pdfIn PDF document text
- http://amtabor2.at/images/how-to-get-offsale-stuff-on-roblox-free.pdfIn PDF document text
- http://www.isril.it/images/free-roblox-accounts-discord-bot.pdfIn PDF document text
- http://salantiskis.lt/images/roblox-freenet.pdfIn PDF document text
- http://sbm-nn.ru/images/how-to-change-your-roblox-name-for-free-2021.pdfIn PDF document text
- http://lamascheradiferro.dk/images/qtx-roblox-hack.pdfIn PDF document text
- https://www.sitiwebjoomla.it/images/how-to-hack-someone-in-roblox-2021.pdfIn PDF document text
- http://www.cosver.nl/images/roblox-hack-fame-simulator-explication.pdfIn PDF document text
- http://kruiz21.ru/images/speed-city-roblox-hack.pdfIn PDF document text
- https://www.hbproducts.dk/images/face-png-roblox-free-face-q-se-queda-para-siempre.pdfIn PDF document text
- http://intrasservices.com/images/how-to-get-free-roblox-gear-2021.pdfIn PDF document text
- http://www.homesweethome.pl/images/how-to-hack-ninja-assassin-roblox.pdfIn PDF document text
- https://verdensbarn.no/images/obby-co-nf-free-robux.pdfIn PDF document text
- http://abqwinair.com/images/roblox-jailbreak-cheat-codes-pc.pdfIn PDF document text
+14 more URL(s)
Extracted artifacts 3
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
stream_003_off00007ed9.bin |
decompressed-pdf-stream | PDF FlateDecoded stream at offset 0x7ED9 | 26128 bytes |
SHA-256: 3637816751c1af3cc04ebfdfaecbfa32290556a2884cb9de03da8e76118c06a1 |
|||
font_01_sfnt_off0000b824.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xB824 | 3884 bytes |
SHA-256: 40b61f8938bd710dc29dc58ba3fde91c245a6a69596ec569b4d27c769ca417cf |
|||
font_02_sfnt_off0000c4cb.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xC4CB | 17320 bytes |
SHA-256: a38b7d60f2935bb1078fa0f9617684c7563f3097c1b89b6958d445bfc3784ded |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.