SUSPICIOUS — coin-master-hack-xyz-download_GM406889139.pdf
SUSPICIOUS — coin-master-hack-xyz-download_GM406889139.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 4 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
1d76ce33834ef01b9afa72482c10df66ccdf3e37d2aef0a2a5226c51a5bbd0b1 - SHA-1:
26b05d54472218bfdf60f5ab55f836d4ac8a8742 - MD5:
5b1142d3608f12864291f07bc8d43a7b - ssdeep:
384:Xt7Qo2mth+3GZsvSHyty9no48n9dk3M2TvQOUQc+ZkR6dL8a+CUSEbvopTf+uZrF:d7QoJ/svmKy2UMg+nR1dfb8Wu5UQ2s - TLSH:
T18C2F6DF750D7DD4C75864F0765FB206DA089D284A162EA5051E8ABBCE07C5FE3F20922 - Submitted as: coin-master-hack-xyz-download_GM406889139.pdf
- File type: pdf · Size: 35569 bytes
- Verdict: suspicious (58/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: Trojan:PDF/Phish.CFN!MTB
- Emsisoft (Emergency Kit): PDF.Spam.Heur.2
- Trellix Stinger (McAfee): PDF/Phish-TWM!5B1142D3608F
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: http://www.valenciamaids.com/userfiles/files/coin-master-card-hack-apk_GM406889139.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: http://netcdn.tw/app/406889139/coin-master-hack-xyz-download-game-hack, http://www.valenciamaids.com/userfiles/files/coin-master-card-hack-apk_GM406889139.pdf, http://www.valenciamaids.com/userfiles/files/free-tiktok-comments_GM835599320.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://netcdn.tw/app/406889139/coin-master-hack-xyz-download-game-hack
- http://www.valenciamaids.com/userfiles/files/coin-master-card-hack-apk_GM406889139.pdf
- http://www.valenciamaids.com/userfiles/files/free-tiktok-comments_GM835599320.pdf
- http://www.valenciamaids.com/userfiles/files/free-generator_GM431946152.pdf
- http://www.valenciamaids.com/userfiles/files/coin-master-haktuts_GM406889139.pdf
- http://www.valenciamaids.com/userfiles/files/free-robux-games-that-actually-work_GM431946152.pdf
- http://www.valenciamaids.com/userfiles/files/free-roblox-accounts-with-robux-that-work-not-banned_GM431946152.pdf
- http://www.valenciamaids.com/userfiles/files/how-can-i-get-a-roblox-hack-gui-to-work_GM431946152.pdf
- http://www.valenciamaids.com/userfiles/files/get-free-robux_GM431946152.pdf
- http://www.valenciamaids.com/userfiles/files/scary-larry-roblox_GM431946152.pdf
- http://www.valenciamaids.com/userfiles/files/roblox-hacks-2021_GM431946152.pdf
- http://www.valenciamaids.com/userfiles/files/free-robux-message_GM431946152.pdf
- http://www.valenciamaids.com/userfiles/files/hack-coin-master-apk-32_GM406889139.pdf
- http://www.valenciamaids.com/userfiles/files/free-robux-command-2021_GM431946152.pdf
- http://www.valenciamaids.com/userfiles/files/get-free-robux-info_GM431946152.pdf
- http://www.valenciamaids.com/userfiles/files/coin-master-hack-app-2021_GM406889139.pdf
- http://www.valenciamaids.com/userfiles/files/free-coin-master-spins-2021_GM406889139.pdf
- http://www.valenciamaids.com/userfiles/files/roblox-hack-tool-download-free_GM431946152.pdf
- http://www.valenciamaids.com/userfiles/files/free-blood-shirt-roblox_GM431946152.pdf
- http://www.valenciamaids.com/userfiles/files/i-know-who-hacked-my-roblox-account_GM431946152.pdf
- http://www.valenciamaids.com/userfiles/files/how-to-hack-roblox-2021_GM431946152.pdf
Embedded domains
- netcdn.tw
- www.valenciamaids.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report