MALICIOUS
82
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
The PDF document contains multiple embedded URLs and a heuristic firing for an external URI, all pointing towards websites offering information on hacking or obtaining in-game currency for Roblox. The ML classifier also flagged this PDF as malicious. While no scripts were extracted, the presence of numerous suspicious URLs and the document's theme suggest a phishing or malware distribution attempt, likely initiated via spearphishing attachment.
Machine Learning
- Nyx PDF Classifier malicious score 0.7795
Heuristics 4
-
Brand-impersonation credential phishing lure high SE_BRAND_CREDENTIAL_PHISHDocument impersonates a well-known consumer brand and uses account-security / verification language ('unusual activity', 'account on hold', 'verify your account') to steer the reader to a credential-harvesting link. Corroborated by: call-to-action link host does not match the impersonated brand: http://gaminggenerator.org/app/431946152/how-to-hack-roblox-wikihow.
-
Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTONDocument contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
-
External URI info PDF_URIPDF contains an external URL action
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL http://gaminggenerator.org/app/431946152/how-to-hack-roblox-wikihow PDF link annotation
- http://hotel-buta.by/images/how-to-bypass-the-roblox-cheat-engine-bypass.pdfIn PDF document text
- http://poltekkeskhjogja.ac.id/images/roblox-highschool-money-cheat.pdfIn PDF document text
- https://www.hbproducts.dk/images/how-to-hack-roblox-jailbreak-on-ios.pdfIn PDF document text
- http://echosvoix.ch/images/free-robux-laptop.pdfIn PDF document text
- http://sscclc.edu.ec/images/how-to-hack-another-player-on-roblox.pdfIn PDF document text
- http://kruiz21.ru/images/free-robux-no-surveys-or-verification.pdfIn PDF document text
- https://stroyzakazremont.ru/images/roblox-shop-free.pdfIn PDF document text
- http://immo360grad.com/images/divines-club-free-robux.pdfIn PDF document text
- http://armportal.co.uk/images/wie-kann-man-ihn-roblox-hacken-um-robaks.pdfIn PDF document text
- http://lawnn.ru/images/comment-avoir-des-roblox-gratuitement-sans-hack.pdfIn PDF document text
- https://www.elevage-chiot.fr/images/dll-hack-for-roblox-2021.pdfIn PDF document text
- http://hindicenter.com/images/how-to-get-free-robux-2021-no-hack.pdfIn PDF document text
- http://florentineholding.com/images/roblox-plane-blueprints-free.pdfIn PDF document text
- http://dermaceutic.co.uk/images/cool-free-things-on-the-catalog-for-roblox.pdfIn PDF document text
- http://kontaktadig.se/images/free-robux-no-survey-no-download-no-human-verification-2021.pdfIn PDF document text
- http://arpinoturismo.it/images/roblox-cheat-codes-no-phone.pdfIn PDF document text
- https://www.ncscolour.no/images/free-robux-admin-codes.pdfIn PDF document text
- http://ce-tsv-nantes.fr/images/how-to-get-free-robux-in-jail-breck.pdfIn PDF document text
- https://rietenwinkel.nl/images/free-robux-codes-2021.pdfIn PDF document text
- http://miriammcconnonart.com/images/anti-hacker-roblox.pdfIn PDF document text
- http://www.eurologistiki.gr/images/new-free-robux-hack-pastebin.pdfIn PDF document text
- http://www.tamogatoweb.hu/images/robux-free-giveaway-2021.pdfIn PDF document text
- http://zarinnameh.ir/images/how-to-hack-roblox-game-apocalypse-rising.pdfIn PDF document text
- https://www.mrsz.ir/images/hack-robux-gratis-pastebin.pdfIn PDF document text
- http://www.torvet11.dk/images/roblox-strucid-hack-download.pdfIn PDF document text
- https://shimony.net/images/how-to-change-your-username-on-roblox-for-free-mobile.pdfIn PDF document text
- https://verdensbarn.no/images/roblox-buisnees-simulator-hack.pdfIn PDF document text
- http://www.evaplast.by/images/free-robux-without-download-apps-or-survey.pdfIn PDF document text
- http://uctovnictvosnv.sk/images/free-robux-no-verification-2021-ios.pdfIn PDF document text
- http://pdapanache.com/images/roblox-cheats-and-hacks-download.pdfIn PDF document text
- http://5346000.com/images/free-to-wear-stuff-roblox.pdfIn PDF document text
- http://svp-steinmaur.ch/images/free-unicorn-stuff-roblox.pdfIn PDF document text
- http://www.zdravazena.sk/images/free-roblox-account-giveaway-2021.pdfIn PDF document text
- http://www.visiblefilm.com/images/how-to-get-free-knife-in-csgo-roblox.pdfIn PDF document text
- http://bilhetim.com.br/images/can-i-make-a-costum-charecter-is-roblox-for-free.pdfIn PDF document text
- http://legs11.co.za/images/free-robux-tix-generator-download.pdfIn PDF document text
- https://gzog.pl/images/how-to-hack-roblox-using-inspect-element.pdfIn PDF document text
- http://www.pacoestrada.it/images/roblox-the-plaza-money-hack.pdfIn PDF document text
- http://www.pro-futuro.eu/images/can-u-actually-get-free-robux.pdfIn PDF document text
- https://www.udivadlahotel.cz/images/roblox-exploit-level-7-free.pdfIn PDF document text
- http://www.eurosan1.ba/images/roblox-black-clover-online-cheat.pdfIn PDF document text
- http://lechia-sedziszow.pl/images/free-roblox-avatar-stuff.pdfIn PDF document text
- http://cmme.it/images/speed-hack-assassin-roblox.pdfIn PDF document text
- http://bassacctaxservices.com/images/hack-para-shinobi-life-roblox-2021.pdfIn PDF document text
- https://grovehilloutfitters.com/images/games-for-free-to-play-fortnite-like-roblox.pdfIn PDF document text
- http://principessalialaofegypt.com/images/hack-robar-cuentas-de-roblox-pastebin.pdfIn PDF document text
- http://www.malonmalon.com.ar/images/roblox-robux-hack-generato.pdfIn PDF document text
- http://ctr74.net/images/roblox-free-robux-ads.pdfIn PDF document text
- http://christiansymbolkits.com/images/5-hacker-fampsos-roblox.pdfIn PDF document text
+15 more URL(s)
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
stream_003_off000080c0.bin |
decompressed-pdf-stream | PDF FlateDecoded stream at offset 0x80C0 | 27024 bytes |
SHA-256: 0999379881324a4cb1150bc6efaceb94f588b66cf9724effa14165c957d66744 |
|||
font_01_sfnt_off0000bdca.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xBDCA | 17920 bytes |
SHA-256: 0e2b46cf194f6c9cb9f72bccd7f72c9d9b1e5901ec9b8bb3a0980d4e0ce1001d |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.