SUSPICIOUS — oprewards-com-login_GM431946152.pdf
SUSPICIOUS — oprewards-com-login_GM431946152.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 5 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
254793700a98d49b9595cbc9cc4d43911c366ba4b8bf00bf4e080730c3ed302f - SHA-1:
09ed9102536eae5b8b24785909eccf0a9093cb0e - MD5:
3bb21ec7ed4768a3178e86620a79baff - ssdeep:
768:fpxahcR8PCfKJQzqwjNFP/KIQugTXcolfwvD9ToR:BgVPyKFuF3nQukffwBToR - TLSH:
T1E3328EF70497CC4CA99A4F1369FB165AA49DD7887122DF5094DC3AAC84BC1BE2F30921 - Submitted as: oprewards-com-login_GM431946152.pdf
- File type: pdf · Size: 46070 bytes
- Verdict: suspicious (58/100)
Detections (5 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: Trojan:PDF/Phish.CFN!MTB
- Emsisoft (Emergency Kit): PDF.Spam.Heur.2
- Trellix Stinger (McAfee): PDF/Phish-TWM!3BB21EC7ED47
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: http://www.js100.com/uploads/ckeditor/files/free-executor-roblox_GM431946152.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://netcdn.online/app/431946152/oprewards-com-login-game-hack, http://www.js100.com/uploads/ckeditor/files/free-executor-roblox_GM431946152.pdf, http://www.js100.com/uploads/ckeditor/files/free-minecraft-mods_GM479516143.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://netcdn.online/app/431946152/oprewards-com-login-game-hack
- http://www.js100.com/uploads/ckeditor/files/free-executor-roblox_GM431946152.pdf
- http://www.js100.com/uploads/ckeditor/files/free-minecraft-mods_GM479516143.pdf
- http://www.js100.com/uploads/ckeditor/files/daily-free-spins_GM406889139.pdf
- http://www.js100.com/uploads/ckeditor/files/free-robux-obby_GM431946152.pdf
- http://www.js100.com/uploads/ckeditor/files/free-robux-no-verification-or-survey-2021_GM431946152.pdf
- http://www.js100.com/uploads/ckeditor/files/free-robux-without-doing-anything_GM431946152.pdf
- http://www.js100.com/uploads/ckeditor/files/coin-master-free-spins-through-coin-pop_GM406889139.pdf
- http://www.js100.com/uploads/ckeditor/files/free-robux-generator-without-verification_GM431946152.pdf
- http://www.js100.com/uploads/ckeditor/files/coin-master-free-food-for-pet_GM406889139.pdf
- http://www.js100.com/uploads/ckeditor/files/pubg-uc-official-center_GM1330123889.pdf
- http://www.js100.com/uploads/ckeditor/files/best-free-minecraft-server-hosting_GM479516143.pdf
- http://www.js100.com/uploads/ckeditor/files/free-robux-no-verification-or-survey_GM431946152.pdf
- http://www.js100.com/uploads/ckeditor/files/minecraft-free-download-laptop_GM479516143.pdf
- http://www.js100.com/uploads/ckeditor/files/roblox-studio-free-download_GM431946152.pdf
- http://www.js100.com/uploads/ckeditor/files/free-tiktok-like_GM835599320.pdf
- http://www.js100.com/uploads/ckeditor/files/coin-master-free-link-spin_GM406889139.pdf
- http://www.js100.com/uploads/ckeditor/files/free-robux-gift-card_GM431946152.pdf
- http://www.js100.com/uploads/ckeditor/files/roblox-ftw_GM431946152.pdf
- http://www.js100.com/uploads/ckeditor/files/coin-master-free-rare-cards_GM406889139.pdf
- http://www.js100.com/uploads/ckeditor/files/free-robux-no-verify_GM431946152.pdf
Embedded domains
- netcdn.online
- www.js100.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report