SUSPICIOUS — kachifpro_GM406889139.pdf
SUSPICIOUS — kachifpro_GM406889139.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 4 of 50 detection engines flagged it.
Identification
- SHA-256:
62dd1d5a65785524e866235709ec9b83653de1b1a8f80baef0a374aa96ff0e97 - SHA-1:
fc06c19f84264a8fd941a45f3a017a9b7b674cfd - MD5:
a6876eb9544f789638d62b32e1f2a625 - ssdeep:
768:XdtV8BqFGNvKmwMqkkKVMYxVsLfr/8wI7t:XyBYGsuqkkKq4VsLfr/877t - TLSH:
T1FE2F5DF75097CD4C7E8A8F039AF61969A8C9D788B023EE4054D8362C947C5EEBF01561 - Submitted as: kachifpro_GM406889139.pdf
- File type: pdf · Size: 34737 bytes
- Verdict: suspicious (44/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: Trojan:PDF/Phish.CFN!MTB
- Emsisoft (Emergency Kit): PDF.Spam.Heur.2
- Trellix Stinger (McAfee): PDF/Phish-TWM!A6876EB9544F
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: http://netcdn.tw/app/406889139/kachifpro-game-hack, https://privatearrangements.co.nz/public/files/pastebin-com-for-free-robux_GM431946152.pdf, https://privatearrangements.co.nz/public/files/100-free-coin-master-spins_GM406889139.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://netcdn.tw/app/406889139/kachifpro-game-hack
- https://privatearrangements.co.nz/public/files/pastebin-com-for-free-robux_GM431946152.pdf
- https://privatearrangements.co.nz/public/files/100-free-coin-master-spins_GM406889139.pdf
- https://privatearrangements.co.nz/public/files/free-adidas-asset-roblox_GM431946152.pdf
- https://privatearrangements.co.nz/public/files/free-robux-please_GM431946152.pdf
- https://privatearrangements.co.nz/public/files/rbx-land-free-robux_GM431946152.pdf
- https://privatearrangements.co.nz/public/files/legit-free-spins-coin-master_GM406889139.pdf
- https://privatearrangements.co.nz/public/files/fb-coin-master-free-spins-link_GM406889139.pdf
- https://privatearrangements.co.nz/public/files/free-robux-generator_GM431946152.pdf
- https://privatearrangements.co.nz/public/files/minecraft-pe-hack-client_GM479516143.pdf
- https://privatearrangements.co.nz/public/files/roblox-redeem-robux-code-free_GM431946152.pdf
- https://privatearrangements.co.nz/public/files/free-coin-master-links_GM406889139.pdf
- https://privatearrangements.co.nz/public/files/free-robux-only-username_GM431946152.pdf
- https://privatearrangements.co.nz/public/files/how-to-get-free-robux-no-hack-no-download_GM431946152.pdf
- https://privatearrangements.co.nz/public/files/coin-master-hack-online-generator_GM406889139.pdf
- https://privatearrangements.co.nz/public/files/roblox-hack-working-2021_GM431946152.pdf
- https://privatearrangements.co.nz/public/files/roblox-shirt-texture-free-shipping_GM431946152.pdf
- https://privatearrangements.co.nz/public/files/roblox-hack-free-robux-com_GM431946152.pdf
- https://privatearrangements.co.nz/public/files/fedora-roblox-free_GM431946152.pdf
- https://privatearrangements.co.nz/public/files/hack-coin-master-game-apk_GM406889139.pdf
- https://privatearrangements.co.nz/public/files/minecraft-hack-download_GM479516143.pdf
Embedded domains
- netcdn.tw
- privatearrangements.co.nz
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report