MALICIOUS
122
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
The document contains numerous URLs related to 'Robux' and 'Roblox' hacks, suggesting a lure for game-related exploits. It explicitly instructs the user to copy or paste content into command-line interfaces like 'cmd.pdf', indicating an attempt to trick the user into executing malicious commands. The ML classifier also flagged this PDF as malicious.
Machine Learning
- Nyx PDF Classifier malicious score 0.6193
Heuristics 5
-
Clipboard command execution lure high SE_CLIPBOARD_COMMAND_LUREDocument tells the user to copy or paste clipboard content into Run, PowerShell, cmd, or another shell-like execution context
-
LOLBin token sequence in document text high SE_LOLBIN_RUN_COMMANDExtracted document text contains a Windows script/execution tool name (PowerShell, mshta, cmd, rundll32, regsvr32, …) within 220 characters of a dangerous flag, command verb, or URL. This is a visible 'run this' instruction in HTML/PDF/RTF lure bodies, or — in macro-laden Office files — the macro's own string-pool entries appearing adjacent in extracted text.
-
Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTONDocument contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
-
External URI info PDF_URIPDF contains an external URL action
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL http://gaminggenerator.org/app/431946152/free-robux-patch PDF link annotation
- http://garrisonjazz.com/images/how-do-you-hack-roblox-robux.pdfIn PDF document text
- http://www.drent.se/images/free-walking-animation-for-roblox.pdfIn PDF document text
- http://www.cuniv-naama.dz/images/cheat-boku-no-roblox.pdfIn PDF document text
- http://www.copoint.co.uk/images/free-accounts-for-work-scam-roblox.pdfIn PDF document text
- http://kids-academy.pl/images/wall-hack-csgo-roblox.pdfIn PDF document text
- https://www.hbproducts.dk/images/how-to-speed-hack-on-roblox-with-out-shutdown.pdfIn PDF document text
- http://bressanassessoria.com.br/images/free-robux-generator-2.pdfIn PDF document text
- http://gbp-trabkiwielkie.pl/images/roblox-redeem-codes-2021-free.pdfIn PDF document text
- http://bolsaycapital.com/images/free-dominus-roblox-catalog.pdfIn PDF document text
- http://internetdeputy.com/images/roblox-pitch-black-shirt-free.pdfIn PDF document text
- http://www.evaplast.by/images/blakberry-hack-roblox.pdfIn PDF document text
- http://finalstand.org/images/how-to-hack-accounts-on-roblox-with-cmd.pdfIn PDF document text
- https://www.manmed.info:443/images/free-robux-no-human-verification-generator.pdfIn PDF document text
- https://www.cnte.org.br/images/roblox-cheats-cbro.pdfIn macro / runtime command snippet
- https://www.ukrtrans.biz/images/roblox-noclip-jailbreak-hack.pdfIn macro / runtime command snippet
- http://bilhetim.com.br/images/jj-hacks-roblox.pdfIn PDF document text
- http://horsa18.ru/images/free-dumb-roblox-accounts.pdfIn PDF document text
- http://www.marambio.com.ar/images/how-to-annoy-roblox-server-hack.pdfIn PDF document text
- https://jdlgroup.ca/images/pet-simulator-roblox-hack.pdfIn PDF document text
- https://www.dierenartsberghman.be/images/roblox-free-builders-club-hack-2021.pdfIn PDF document text
- https://www.fenews.co.uk/images/how-to-get-free-clothes-on-roblox-without-bc-2021.pdfIn PDF document text
- http://alexanderautos.co/images/free-robux-gift-card-codes-unused-2021.pdfIn PDF document text
- http://www.evaplast.by/images/free-gift-cars-for-roblox.pdfIn PDF document text
- https://www.devries-group.de/images/roblox-com-cheats-for-tix.pdfIn PDF document text
- http://fotoflas.gr/images/how-to-get-a-roblox-hack.pdfIn PDF document text
- http://nalmpantistractors.gr/images/free-auto-key-presser-for-roblox.pdfIn PDF document text
- http://magistrinfo.ru/images/free-robux-promo-codes-2021-not-used.pdfIn PDF document text
- http://pia2000.net/images/roblox-invisible-hack-download.pdfIn PDF document text
- http://mycounty.com.ua/images/free-robux-generator-op.pdfIn PDF document text
- https://www.udivadlahotel.cz/images/how-to-get-free-robux-using-cmd.pdfIn PDF document text
- http://learningarabic.co.uk/images/can-i-hack-roblox.pdfIn PDF document text
- http://www.htc.edu.au/images/ww-robux-hack-me.pdfIn PDF document text
- http://www.eurosan1.ba/images/hack-roblox-espaol-elements.pdfIn PDF document text
- http://www.pacoestrada.it/images/how-to-get-50-robux-free-2021.pdfIn PDF document text
- http://ff-klaffenbach.de/images/how-to-get-roblox-for-free-on-xbox-one.pdfIn PDF document text
- https://www.tsdb.com.au/images/skater-hacks-roblox.pdfIn PDF document text
- https://www.dierenartsberghman.be/images/wearedevs-roblox-hack.pdfIn PDF document text
- https://newenglandafs.com/images/roblox-account-hacker-apk.pdfIn PDF document text
- https://www.audipec.com.br/images/free-pins-for-robux.pdfIn PDF document text
- http://behsanroshd.com/images/how-to-get-robux-for-free-no-scam.pdfIn PDF document text
- https://gabrieliassociati.com/images/free-bc-roblox-2021.pdfIn PDF document text
- http://reggieslockandkey.com/images/free-candy-van-roblox-script.pdfIn PDF document text
- https://www.flexcable.com/images/roblox-jailbreak-hack-noclip-zip-file-download.pdfIn PDF document text
- http://kids-academy.pl/images/free-roblox-friends.pdfIn PDF document text
- http://hemmet-strand.dk/images/free-robux-without-password-or-email.pdfIn PDF document text
- http://wireprod.net/images/free-roblox-codes-hack.pdfIn PDF document text
- http://iluvlocalplaces.com/images/how-to-get-btools-in-roblox-2021-no-hack.pdfIn PDF document text
- http://cdescolapios.org/images/cheat-engine-roblox-infinite-health.pdfIn PDF document text
- http://caraless.com/images/roblox-police-car-free.pdfIn PDF document text
+9 more URL(s)
Extracted artifacts 3
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
stream_003_off00007ee1.bin |
decompressed-pdf-stream | PDF FlateDecoded stream at offset 0x7EE1 | 26372 bytes |
SHA-256: 409e5546018ccc980017d3a06f591659b7073f816aee0082d99cbeffff70679a |
|||
font_01_sfnt_off0000bb86.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xBB86 | 3364 bytes |
SHA-256: 89df7fc185968942a825e6a661318db9907d93066376f37106431d788f149efc |
|||
font_02_sfnt_off0000c716.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xC716 | 18036 bytes |
SHA-256: c566eb850909a051df1c17a974355de55320efc50c05933b5165f7350657d993 |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.