MALICIOUS
82
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1204.001 User Execution: Malicious Link
The PDF document contains a lure for "free Roblox hacks" and impersonates the Facebook brand, directing users to a suspicious URL. The ML classifier also flagged this PDF as malicious. The embedded URLs are likely used to deliver a second-stage payload or facilitate credential phishing.
Machine Learning
- Nyx PDF Classifier malicious score 0.6193
Heuristics 4
-
Brand-impersonation credential phishing lure high SE_BRAND_CREDENTIAL_PHISHDocument impersonates a well-known consumer brand and uses account-security / verification language ('unusual activity', 'account on hold', 'verify your account') to steer the reader to a credential-harvesting link. Corroborated by: call-to-action link host does not match the impersonated brand: http://gaminggenerator.org/app/431946152/glitch-hacks-free-roblox.
-
Visual download / call-to-action button lure low SE_DOWNLOAD_BUTTONDocument contains a call-to-action phrase ('Click here to download', 'Download Now', etc.) — low-signal unless other findings point to a malicious workflow
-
External URI info PDF_URIPDF contains an external URL action
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL http://gaminggenerator.org/app/431946152/glitch-hacks-free-roblox PDF link annotation
- http://www.sapaengineering.kz/images/free-roblox-t-shirt-templates.pdfIn PDF document text
- http://korporacjaroma.pl/images/free-robux-sign.pdfIn PDF document text
- http://ecoleduchat-grenoble.fr/images/how-to-get-free-robux-iphone-7.pdfIn PDF document text
- http://babbibooth.com/images/furky-safe-and-free-roblox-hacks.pdfIn PDF document text
- https://www.seeingindependence.org/images/a-discord-server-that-gives-free-robux.pdfIn PDF document text
- http://seniornetwanganui.org.nz/images/roblox-hack-apk-download-pc.pdfIn PDF document text
- https://www.linzgau-kjh.de/images/free-robux-xbox-1.pdfIn PDF document text
- http://techmobil.pl/images/fashion-frenzy-roblox-game-free-download.pdfIn PDF document text
- http://wireprod.net/images/hack-100-robux.pdfIn PDF document text
- http://www.rezbb.sk/images/comment-hacker-roblox-accesoir.pdfIn PDF document text
- http://www.torvet11.dk/images/roblox-cheat-engine-swordburst-online.pdfIn PDF document text
- https://www.tsdb.com.au/images/hacker-names-on-roblox.pdfIn PDF document text
- http://www.marambio.com.ar/images/sparereborn-roblox-hacks.pdfIn PDF document text
- http://www.vktzunami.cz/images/pin-roblox-card-free.pdfIn PDF document text
- http://www.colledellaselva.it/images/roblox-escape-school-online-free.pdfIn PDF document text
- http://alexanderautos.co/images/free-robux-generator-no-survey-2021.pdfIn PDF document text
- https://accord.kiev.ua/images/roblox-promo-codes-free-robux.pdfIn PDF document text
- http://hoqueijmj.eu/images/icepprof-roblox-hacks.pdfIn PDF document text
- https://bancroftandsons.com/images/free-roblox-gear.pdfIn PDF document text
- http://www.torvet11.dk/images/roblox-hack-admin-script.pdfIn PDF document text
- http://webstan.be/images/how-2-get-free-robux-working-2021.pdfIn PDF document text
- http://svadba-moda.kg/images/roblox-20-torso-free.pdfIn PDF document text
- http://lakeshistory.com/images/free-wins-in-anarchy-roblox.pdfIn PDF document text
- http://petarda.hu/images/roblox-hacked-client-buy.pdfIn PDF document text
- http://grupodin.com.br/images/nascar-17-roblox-cheats.pdfIn PDF document text
- http://www.torvet11.dk/images/roblox-hack-2021-online.pdfIn PDF document text
- http://hardbit.cn/images/free-roblox-codes-2021.pdfIn PDF document text
- http://ghegamethu.vn/images/roblox-free-skin-robuxed.pdfIn PDF document text
- https://lesegais.ru/images/comandos-de-hacker-roblox.pdfIn PDF document text
- http://lillysonthelake.com/images/how-to-get-free-wings-in-roblox-2021.pdfIn PDF document text
- http://www.arredifunebri.com/images/roblox-lumber-tycoon-2-cheats-money.pdfIn PDF document text
- http://dermaceutic.co.uk/images/free-supreme-shirts-roblox.pdfIn PDF document text
- https://www.albisser.ch/images/roblox-work-at-a-pizza-place-manager-hack.pdfIn PDF document text
- http://brandyourbody.com/images/install-roblox-free-online.pdfIn PDF document text
- https://amatq.ca/images/how-to-hack-jailbreak-on-roblox.pdfIn PDF document text
- http://lichtdrukkerijwijchen.nl/images/cringe-trying-to-have-free-robux.pdfIn PDF document text
- http://eventgo.fr/images/free-robux-on-iphone.pdfIn PDF document text
- http://escolaarboc.cat/images/dinosaur-simulator-roblox-hack.pdfIn PDF document text
- http://bit-sky.com/images/cant-play-any-game-roblox-gor-hacked.pdfIn PDF document text
- http://chehovchanka-info.ru/images/comment-hacker-phantom-force-roblox.pdfIn PDF document text
- https://www.elevage-chiot.fr/images/roblox-pastbin-hack.pdfIn PDF document text
- https://www.hotschool.com.au/images/roblox-no-clip-hack-download-2021.pdfIn PDF document text
- http://traveltrucks.com.au/images/dragon-ball-rage-roblox-cheat-engine-hack.pdfIn PDF document text
- http://amtabor2.at/images/roblox-life-free-robux.pdfIn PDF document text
- https://www.foodsafety.cz/images/robux-hacks-without-human-verification-2021.pdfIn PDF document text
- http://uctovnictvosnv.sk/images/roblox-hack-twisted-murderer.pdfIn PDF document text
- https://www.acoustiguard.com/images/money-hack-urbis-roblox.pdfIn PDF document text
- http://origamiperu.com/images/roblox-com-toys-free-codes.pdfIn PDF document text
- http://ivalor.fr/images/uirbx-club-roblox-hack.pdfIn PDF document text
+8 more URL(s)
Extracted artifacts 3
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off00008270.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0x8270 | 24904 bytes |
SHA-256: d9f4b6f0f2e58d33f8ef9bcc3cc2f9b8b9f5fe086446cda959947b5104a7bad2 |
|||
font_01_sfnt_off0000bbe1.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xBBE1 | 3364 bytes |
SHA-256: a0ac3b7e10e95e750ff4ddb8a943747768e19226b9b370296d9a97841f1b59a3 |
|||
font_02_sfnt_off0000c772.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xC772 | 18300 bytes |
SHA-256: 92bf373b6514262f4de6500d6dba4ccae5fd8f3f49be6bb2fafaff29a165accc |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.