SUSPICIOUS — mcpe-com_GM479516143.pdf
SUSPICIOUS — mcpe-com_GM479516143.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 5 of 53 detection engines flagged it.
Identification
- SHA-256:
212219c2634618fe42c18d8d4236639968e336cae893aeb7a5fa0f9ba1059b03 - SHA-1:
b8c472345f7c390cd898e999ff587451adbc2608 - MD5:
ef09c0f5cd2bb3cc67d85e641a651fcc - ssdeep:
768:detXShwbr5o3qwDvoT/JlmhHvtOyr/xsn/Ls8XMEoxKxTNyPlO:deNSYo3XQTRlmzOyrCn/Ls8cEzxTqlO - TLSH:
T134329DF39047DD4C3A9BAB07A8F62159A48AD3C83166D98051D8763CE47C6FE7B01E21 - Submitted as: mcpe-com_GM479516143.pdf
- File type: pdf · Size: 45248 bytes
- Verdict: suspicious (44/100)
Detections (5 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: Trojan:PDF/Phish.CFN!MTB
- Emsisoft (Emergency Kit): PDF.Spam.Heur.2
- Trellix Stinger (McAfee): PDF/Phish-TWM!EF09C0F5CD2B
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://netcdn.xyz/app/479516143/mcpe-com-game-hack, https://www.modestuae.com/uploaded_files/userfiles/files/what-do-roblox-points-do_GM431946152.pdf, https://www.modestuae.com/uploaded_files/userfiles/files/hacking-apps-for-roblox_GM431946152.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://netcdn.xyz/app/479516143/mcpe-com-game-hack
- https://www.modestuae.com/uploaded_files/userfiles/files/what-do-roblox-points-do_GM431946152.pdf
- https://www.modestuae.com/uploaded_files/userfiles/files/hacking-apps-for-roblox_GM431946152.pdf
- https://www.modestuae.com/uploaded_files/userfiles/files/coin-master-free-chest-link_GM406889139.pdf
- https://www.modestuae.com/uploaded_files/userfiles/files/free-robux-generator-no-human-verification-2021_GM431946152.pdf
- https://www.modestuae.com/uploaded_files/userfiles/files/update-coin-master-free-spins_GM406889139.pdf
- https://www.modestuae.com/uploaded_files/userfiles/files/coin-master-link-app_GM406889139.pdf
- https://www.modestuae.com/uploaded_files/userfiles/files/how-to-play-minecraft-for-free_GM479516143.pdf
- https://www.modestuae.com/uploaded_files/userfiles/files/coin-master-hack-version-ios_GM406889139.pdf
- https://www.modestuae.com/uploaded_files/userfiles/files/coin-master-hack-apk-link_GM406889139.pdf
- https://www.modestuae.com/uploaded_files/userfiles/files/download-coin-master-apk-hack_GM406889139.pdf
- https://www.modestuae.com/uploaded_files/userfiles/files/roblox-generator-com_GM431946152.pdf
- https://www.modestuae.com/uploaded_files/userfiles/files/how-to-start-a-minecraft-server-for-free_GM479516143.pdf
- https://www.modestuae.com/uploaded_files/userfiles/files/apps-to-get-free-robux_GM431946152.pdf
- https://www.modestuae.com/uploaded_files/userfiles/files/how-to-get-free-robux-fast_GM431946152.pdf
- https://www.modestuae.com/uploaded_files/userfiles/files/coin-master-free-coin-and-spin-app_GM406889139.pdf
- https://www.modestuae.com/uploaded_files/userfiles/files/easy-how-to-get-free-robux_GM431946152.pdf
- https://www.modestuae.com/uploaded_files/userfiles/files/coin-master-hack-tuts_GM406889139.pdf
- https://www.modestuae.com/uploaded_files/userfiles/files/free-minecraft-server_GM479516143.pdf
- https://www.modestuae.com/uploaded_files/userfiles/files/coin-master-games-hack_GM406889139.pdf
- https://www.modestuae.com/uploaded_files/userfiles/files/coin-master-hack-trick-2021_GM406889139.pdf
Embedded domains
- netcdn.xyz
- www.modestuae.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report