MALICIOUS
90
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1204.002 Malicious File
This PDF document was flagged as malicious by an ML classifier. It uses brand-impersonation credential phishing and an urgency-based lure. The file presents a deceptive download button. Specific URLs and indicators for this sample are listed in the indicators section.
Machine Learning
- Nyx PDF Classifier malicious score 0.7795
Heuristics 5
-
Brand-impersonation credential phishing lure high SE_BRAND_CREDENTIAL_PHISHDocument impersonates a well-known consumer brand and uses account-security / verification language ('unusual activity', 'account on hold', 'verify your account') to steer the reader to a credential-harvesting link. Corroborated by: call-to-action link host does not match the impersonated brand: http://gaminggenerator.org/app/431946152/roblox-galaxy-arcade-resourcen-cheats.
-
Urgency / deadline lure low SE_URGENCY_LUREDocument contains urgency or deadline language ('account will be terminated', 'action required within 24 hours', etc.) — useful context, but low-signal without other findings
-
Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTONDocument contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
-
External URI info PDF_URIPDF contains an external URL action
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL http://gaminggenerator.org/app/431946152/roblox-galaxy-arcade-resourcen-cheats PDF link annotation
- https://www.vacationrentalsincroatia.com/images/site-hack-roblox.pdfIn PDF document text
- http://www.apocalissedigesucristo.com/images/roblox-hack-2021-free-robux-pastebin.pdfIn PDF document text
- https://datavoiz.com/images/ui-pack-roblox-free.pdfIn PDF document text
- http://biccairo.com/images/hoodie-t-shirt-roblox-free.pdfIn PDF document text
- http://businessmart.ro/images/roblox-mad-murderer-hack.pdfIn PDF document text
- http://www.peterdejonge.nl/images/free-robux-with-proof.pdfIn PDF document text
- http://www.hawler.in/images/roblox-fallen-hack.pdfIn PDF document text
- http://energotestcontrol.ru/images/how-to-get-a-free-gamepass-on-roblox.pdfIn PDF document text
- http://ff-obertraun.at/images/cheats-roblox-tickets.pdfIn PDF document text
- https://www.coriglianocalabro.it/images/roblox-creeper-chaos-hack.pdfIn PDF document text
- http://www.gongoff.com/images/hack-someone-account-roblox.pdfIn PDF document text
- http://vedrachemicals.ro/images/hacks-forbee-swarm-simulator-roblox.pdfIn PDF document text
- https://gabrieliassociati.com/images/how-to-use-cheat-codes-in-roblox.pdfIn PDF document text
- https://www.bmta.co.uk/images/robux-hack-2021-no-survey.pdfIn PDF document text
- http://firstaidacademy.be/images/hey-you-yes-you-do-you-want-free-unlimted-robux.pdfIn PDF document text
- http://rafaelmontesinos.com/images/how-to-download-roblox-jailbreak-hack-cranberry.pdfIn PDF document text
- https://europainstitut.hu/images/comment-hacker-pour-avoir-des-robux-2021.pdfIn PDF document text
- http://depilhome-fr.fr/images/roblox-mm2-godly-hack.pdfIn PDF document text
- http://ghegamethu.vn/images/roblox-dominus-frigidus-free.pdfIn PDF document text
- http://biljartenbarendrecht.nl/images/hack-roblox-admin-tool.pdfIn PDF document text
- http://bilhetim.com.br/images/download-a-free-gater-for-robux-generator.pdfIn PDF document text
- http://abqwinair.com/images/free-robux-using-inspect-2021.pdfIn PDF document text
- http://jdlrelocation.com/images/roblox-free-robux-generator-download.pdfIn PDF document text
- http://dshikr.ru/images/get-roblox-games-for-free.pdfIn PDF document text
- http://nevesomost.by/images/free-robux-win-2021.pdfIn PDF document text
- https://www.albisser.ch/images/2021-roblox-robux-hack.pdfIn PDF document text
- http://huananhai.net/images/roblox-hack-to-hack-accounts.pdfIn PDF document text
- http://dygmotors.com.py/images/robux-hack-2021-download.pdfIn PDF document text
- https://www.dierenartsberghman.be/images/mobile-roblox-hack-download.pdfIn PDF document text
- http://asandawireless.co.za/images/free-and-easy-robux.pdfIn PDF document text
- http://www.bripi.pl/images/hacks-para-roblox-descargar-gratis.pdfIn PDF document text
- http://wattkit.com/images/free-robux-no-downloads-2021-real.pdfIn PDF document text
- https://www.lomrad.go.th/images/roblox-best-free-models.pdfIn PDF document text
- http://goosesscuba.com/images/free-robux-melissa.pdfIn PDF document text
- http://unilin21.ru/images/cheated-on-roblox-girlfriend.pdfIn PDF document text
- http://solidcommunication.ch/images/roblox-hack-for-free-obc.pdfIn PDF document text
- http://eventgo.fr/images/roblox-team-switch-hack.pdfIn PDF document text
- http://www.centromedicoaurora.it/images/cheat-roblox-jailbreak-tembus.pdfIn PDF document text
- https://domoticaaplicada.com/images/roblox-hack-accounts-password-2021.pdfIn PDF document text
- http://vagency.us/images/roblox-free-paint.pdfIn PDF document text
- http://cmme.it/images/free-robux-generator-with-color-combination.pdfIn PDF document text
- http://rosadent.com/images/roblox-how-to-get-free-dominus-2021.pdfIn PDF document text
- https://grovehilloutfitters.com/images/roblox-cheats-devloper-console.pdfIn PDF document text
- http://www.lycee-langevin-wallon.com/images/dbz-rage-roblox-hack.pdfIn PDF document text
- https://pa-pangkalpinang.go.id/images/free-robux-lgit.pdfIn PDF document text
- https://grovehilloutfitters.com/images/roblox-pet-simulator-hack-script.pdfIn PDF document text
- https://www.utalii.ac.ke/images/roblox-free-flying-practice-place.pdfIn PDF document text
- https://lobergetart.se/images/free-promo-codes-for-roblox-2021.pdfIn PDF document text
- https://consorziocsa-asicaivano.it/images/roblox-pet-sim-free-vip-server.pdfIn PDF document text
+5 more URL(s)
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
stream_003_off000081f9.bin |
decompressed-pdf-stream | PDF FlateDecoded stream at offset 0x81F9 | 25756 bytes |
SHA-256: 5326e07b0a7b7eae25cfad23bb0213955069325a6a192885fd035307b2beb49b |
|||
font_01_sfnt_off0000bd93.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xBD93 | 18504 bytes |
SHA-256: a05f6b863228e7dabac35fba49d386af2f861b441abb473807403ae09cfacc70 |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.