SUSPICIOUS — aristois-minecraft-hack_GM479516143.pdf
SUSPICIOUS — aristois-minecraft-hack_GM479516143.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 4 of 53 detection engines flagged it.
Identification
- SHA-256:
36b1357f6177ebe7c1b71df173e99841969c670b6efd3d9d43cde5f2fe490ffb - SHA-1:
d7ae3cb9520ecc61e234ca6fc73f0e051ab10d26 - MD5:
49a62acab67dfd99077ee6dcf4289773 - ssdeep:
768:Ou0kfJb7LG8L2MBq7Sv1lzEKDtCA351g7S5:rbPuMBq7+lAKQAp+S5 - TLSH:
T1A52F6BF3418BCC2C7946CB43A9FB60AE20DD93896172D950419C776CE1BCABE7B20551 - Submitted as: aristois-minecraft-hack_GM479516143.pdf
- File type: pdf · Size: 34680 bytes
- Verdict: suspicious (44/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: Trojan:PDF/Phish.CFN!MTB
- Emsisoft (Emergency Kit): PDF.Spam.Heur.2
- Trellix Stinger (McAfee): PDF/Phish-TWM!49A62ACAB67D
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: http://netcdn.tw/app/479516143/aristois-minecraft-hack-game-hack, https://www.espritroue.fr/ckfinder/userfiles/files/free-minecraft-java-account_GM479516143.pdf, https://www.espritroue.fr/ckfinder/userfiles/files/coin-master-hack-without-verification-ios_GM406889139.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://netcdn.tw/app/479516143/aristois-minecraft-hack-game-hack
- https://www.espritroue.fr/ckfinder/userfiles/files/free-minecraft-java-account_GM479516143.pdf
- https://www.espritroue.fr/ckfinder/userfiles/files/coin-master-hack-without-verification-ios_GM406889139.pdf
- https://www.espritroue.fr/ckfinder/userfiles/files/abd-roblox_GM431946152.pdf
- https://www.espritroue.fr/ckfinder/userfiles/files/free-things-in-the-catalog-for-roblox_GM431946152.pdf
- https://www.espritroue.fr/ckfinder/userfiles/files/pubg-uc-zarah_GM1330123889.pdf
- https://www.espritroue.fr/ckfinder/userfiles/files/free-coins-coin-master-link-today_GM406889139.pdf
- https://www.espritroue.fr/ckfinder/userfiles/files/me-hackearon-la-cuenta-de-roblox_GM431946152.pdf
- https://www.espritroue.fr/ckfinder/userfiles/files/hack-coin-master-dzooka_GM406889139.pdf
- https://www.espritroue.fr/ckfinder/userfiles/files/hack-para-roblox-de-robux_GM431946152.pdf
- https://www.espritroue.fr/ckfinder/userfiles/files/free-robux-no-password-or-phone-number-needed_GM431946152.pdf
- https://www.espritroue.fr/ckfinder/userfiles/files/supreme-t-shirt-roblox-free_GM431946152.pdf
- https://www.espritroue.fr/ckfinder/userfiles/files/android-hack-roblox_GM431946152.pdf
- https://www.espritroue.fr/ckfinder/userfiles/files/free-robux-hack-no-waiting_GM431946152.pdf
- https://www.espritroue.fr/ckfinder/userfiles/files/coin-master-free-coins-link_GM406889139.pdf
- https://www.espritroue.fr/ckfinder/userfiles/files/free-robux-no-download_GM431946152.pdf
- https://www.espritroue.fr/ckfinder/userfiles/files/how-to-get-free-gear-in-roblox-2021_GM431946152.pdf
- https://www.espritroue.fr/ckfinder/userfiles/files/free-robux-scams_GM431946152.pdf
- https://www.espritroue.fr/ckfinder/userfiles/files/coin-master-free-coins-and-spins-link_GM406889139.pdf
- https://www.espritroue.fr/ckfinder/userfiles/files/1x1x1x1-roblox-id_GM431946152.pdf
- https://www.espritroue.fr/ckfinder/userfiles/files/coin-master-apk-hack-2021_GM406889139.pdf
Embedded domains
- netcdn.tw
- www.espritroue.fr
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report