MALICIOUS
102
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
The PDF document contains a heuristic firing indicating it links to a game hack lure, specifically directing users to 'enigmagenerator.com'. This URL is likely part of a phishing or malware distribution scheme. The document body and embedded artifacts do not contain executable scripts, but the primary attack vector is the malicious link presented as a game hack. The ML classifier also flagged this PDF as malicious.
Machine Learning
- Nyx PDF Classifier malicious score 0.9070
Heuristics 4
-
PDF links to a 'free generator / game hack' redirector critical PDF_GAME_HACK_REDIRECT_LUREPDF's clickable action targets a redirector of the form /app/<id>/<slug>-game-hack — the landing-page shape of a large SEO 'free spins / generator / game hack' lure family that funnels victims through rotating disposable hosts to a malware/scam payload. The multi-link variants also trip ML/link-farm rules; this catches the single-link variants that otherwise score clean. CRITICAL on its own: the /app/<id>/<slug>-game-hack path shape is unambiguous scam infra, and the host rotates so a host-list match can't be relied on.
-
Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTONDocument contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
-
External URI info PDF_URIPDF contains an external URL action
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://enigmagenerator.com/app/431946152/roblox-game-hack PDF link annotation
- https://www.hotschool.com.au/images/brick-rewards-free-robux.pdfIn PDF document text
- http://nevesomost.by/images/free-private-server-roblox-strucid.pdfIn PDF document text
- http://livebybuddhism.org/images/forts-update-the-northern-frontier-roblox-hack.pdfIn PDF document text
- http://www.eptaviation.com/images/hack-web-for-roblox.pdfIn PDF document text
- https://www.wildpark-johannismuehle.de/images/roblox-elemental-wars-hack-script.pdfIn PDF document text
- http://standart-lab.ru/images/how-to-hack-into-someones-roblox-sever.pdfIn PDF document text
- http://www.htc.edu.au/images/free-roblox-pikachu.pdfIn PDF document text
- https://www.psychotherapie-naturheilpraxis.de/images/free-roblox-clothing-hack.pdfIn PDF document text
- http://giolantapepe.gr/images/a-roblox-hacks.pdfIn PDF document text
- https://www.milewood.co.uk/images/who-do-you-get-free-robux.pdfIn PDF document text
- http://www.mikramarine.gr/images/roblox-dino-simulator-kaiju-skins-for-free.pdfIn PDF document text
- http://fabianslaw.org/images/how-to-get-free-clothes-roblox.pdfIn PDF document text
- http://www.fluidtech.hu/images/cheat-engine-work-on-roblox.pdfIn PDF document text
- http://bestmaids.co.uk/images/natural-disaster-survival-roblox-cheats.pdfIn PDF document text
- http://www.viniperfetti.com/images/free-robux-generator-download-2021.pdfIn PDF document text
- https://sitam.co.in/images/how-to-hack-bed-wars-2-on-roblox.pdfIn PDF document text
- https://ai-appenzell.ch/images/is-roblox-free-on-computer.pdfIn PDF document text
- http://vipservice-bg.com/images/roblox-hacks-account.pdfIn PDF document text
- https://waterpark.by:443/images/pastebin-com-raw-free-robux.pdfIn PDF document text
- https://www.academiaanticorrupcion.org/images/how-to-hack-another-player-on-roblox.pdfIn PDF document text
- http://agritrade-ukraine.com/images/how-to-hack-blox-watch-on-roblox.pdfIn PDF document text
- http://www.mjclautrec.fr/images/roblox-free-promo-codes-vrp-madness.pdfIn PDF document text
- http://evro-okna.net/images/free-robux-generator-password.pdfIn PDF document text
- http://www.guidaturisticaverona.it/images/free-roblox-object-en-vedette.pdfIn PDF document text
- http://archi-z.ru/images/free-robux-hack-game-in-roblox.pdfIn PDF document text
- https://schulzpressetext.de/images/free-robux-website-no-human-verification.pdfIn PDF document text
- http://smart-pro.co.uk/images/roblox-cheats-get-free-robux.pdfIn PDF document text
- http://glaubensfragen.org/images/get-free-robux-offers.pdfIn PDF document text
- http://www.lycee-langevin-wallon.com/images/hack-de-roblox-jailbreak-2021.pdfIn PDF document text
- http://yioipzafeiri.gr/images/robux-card-free-codes.pdfIn PDF document text
- http://asiashop-france.fr/images/is-roblox-free-on-xbox.pdfIn PDF document text
- http://ferienhaus-summt.de/images/free-robux-present-for-roblox.pdfIn PDF document text
- https://inspiration-modellbau.de/images/free-roblox-games-for-geust.pdfIn PDF document text
- https://www.clarence-rockland.com/images/roblox-teleport-hack-2021.pdfIn PDF document text
- http://www.cosver.nl/images/roblox-robux-birthday-hack.pdfIn PDF document text
- https://schulzpressetext.de/images/how-to-no-clip-in-roblox-no-hack.pdfIn PDF document text
- https://technospektr.com.ua/images/how-to-escape-the-labyrinth-roblox-hack.pdfIn PDF document text
- http://artindex.pro/images/roblox-field-of-battle-cheats.pdfIn PDF document text
- http://ernstgloves.co.il/images/robux-free-ap.pdfIn PDF document text
- http://www.ntc.edu.za/images/roblox-piano-music-sheet-megalovania-hack.pdfIn PDF document text
- http://bijbelreizenisrael.nl/images/how-to-speed-hack-in-roblox-2021.pdfIn PDF document text
- https://technospektr.com.ua/images/jailbreak-hack-roblox-money.pdfIn PDF document text
- https://scraperite.com/images/free-robux-roblox-forums.pdfIn PDF document text
- http://genialica.com/images/cheat-roblox-2021-bee-swarm-simulator.pdfIn PDF document text
- https://www.cpnf.ch/images/cheat-roblox-mad-city-kick.pdfIn PDF document text
- https://ogm-goettingen.de/images/synapse-x-roblox-free.pdfIn PDF document text
- https://www.cfdcnv.com/images/how-to-hack-any-roblox-server-no-downloasd.pdfIn PDF document text
- http://www.copoint.co.uk/images/hack-coins-pizzeria-roleplay-remastered-roblox-v3rmillion.pdfIn PDF document text
- https://cintasoeste.com.ar/images/free-robux-no-information-needed.pdfIn PDF document text
+15 more URL(s)
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
stream_003_off00006ca7.bin |
decompressed-pdf-stream | PDF FlateDecoded stream at offset 0x6CA7 | 24016 bytes |
SHA-256: 42b80a536420acb2855110bd522f6bd1b7a0fe9e70feb0e0f77fef6eb955bf66 |
|||
font_01_sfnt_off0000a33d.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xA33D | 17472 bytes |
SHA-256: 744fa0e45967366f35c299a10aab5bc4ecbc64d414b147b48c8af3beb5b91fe0 |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.