MALICIOUS
82
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1204.002 Malicious Link
The document exhibits characteristics of a ClickFix social engineering attack, instructing the user to execute a command or click a link. The embedded URL and numerous other URLs point to sites offering free game currency or cheats, indicating a lure to download a secondary payload. No scripts were extracted, but the presence of external URIs and social engineering tactics strongly suggests a malicious intent to trick the user into downloading further malware.
Machine Learning
- Nyx PDF Classifier malicious score 0.9971
Heuristics 4
-
ClickFix social engineering attack high SE_CLICKFIXDocument instructs the user to press Win+R or paste a command into a terminal — consistent with ClickFix attacks that bypass macro restrictions by tricking users into running malicious commands directly
-
Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTONDocument contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
-
External URI info PDF_URIPDF contains an external URL action
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://netcdn.xyz/app/479516143/is-minecraft-vr-free-game-hack
- https://www.e-learningmin10jakarta.com/__statics/gudangsoal/files/coin-master-free-spins-without-human-verification_GM406889139.pdf
- https://e-learningmin10jakarta.com/__statics/gudangsoal/files/free-robux-generator-without-human-verification_GM431946152.pdf
- https://www.e-learningmin10jakarta.com/__statics/gudangsoal/files/roblox-robux-generator-http-freerobuxgenerator-xyz_GM431946152.pdf
- https://www.e-learningmin10jakarta.com/__statics/gudangsoal/files/free-roblox-card_GM431946152.pdf
- https://www.e-learningmin10jakarta.com/__statics/gudangsoal/files/lastrick-com-coin-master-hack_GM406889139.pdf
- https://e-learningmin10jakarta.com/__statics/gudangsoal/files/microsoft-rewards-roblox_GM431946152.pdf
- https://www.e-learningmin10jakarta.com/__statics/gudangsoal/files/coin-master-free-link-spin_GM406889139.pdf
- https://www.e-learningmin10jakarta.com/__statics/gudangsoal/files/how-do-we-get-free-robux_GM431946152.pdf
- https://e-learningmin10jakarta.com/__statics/gudangsoal/files/what-do-points-do-in-roblox_GM431946152.pdf
- https://e-learningmin10jakarta.com/__statics/gudangsoal/files/minecraft-mods-download-free_GM479516143.pdf
- https://e-learningmin10jakarta.com/__statics/gudangsoal/files/free-robux-without-verification-or-survey_GM431946152.pdf
- https://e-learningmin10jakarta.com/__statics/gudangsoal/files/coin-master-hack-no-verification_GM406889139.pdf
- https://e-learningmin10jakarta.com/__statics/gudangsoal/files/coin-master-hack-quora_GM406889139.pdf
- https://www.e-learningmin10jakarta.com/__statics/gudangsoal/files/roblox-hack-ios_GM431946152.pdf
- https://e-learningmin10jakarta.com/__statics/gudangsoal/files/woman-roblox_GM431946152.pdf
- https://e-learningmin10jakarta.com/__statics/gudangsoal/files/free-group-roblox_GM431946152.pdf
- https://www.e-learningmin10jakarta.com/__statics/gudangsoal/files/roblox-demon_GM431946152.pdf
- https://www.e-learningmin10jakarta.com/__statics/gudangsoal/files/free-spin-coin-master-2021-link_GM406889139.pdf
- https://www.e-learningmin10jakarta.com/__statics/gudangsoal/files/coin-master-daily-free-spins-link-today-twitter_GM406889139.pdf
- https://e-learningmin10jakarta.com/__statics/gudangsoal/files/coin-master-free-spins-link-download-hack_GM406889139.pdf
- http://en.wikipedia.org/wiki/MIT_License
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
stream_003_off00004cba.bin5fff441946eb54708d949195f00e11e77c852d07cc03bac3c2390e13d6fdd7fe |
decompressed-pdf-stream | PDF FlateDecoded stream at offset 0x4CBA | 24980 bytes |
font_01_sfnt_off000085be.bin8bb0636472a21c77c03eb179316ec7672ebaf2fffc2d381e43d3ff9b7c84c5d1 |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x85BE | 17704 bytes |
Open this report in the interactive analyzer, or submit your own file for analysis.