SUSPICIOUS — free-headless-head-roblox_GM431946152.pdf
SUSPICIOUS — free-headless-head-roblox_GM431946152.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 4 of 53 detection engines flagged it.
Identification
- SHA-256:
6a20bc4a22b843cf595fe7deeb7b60a274aa06c5418f9561411c78b166757c7b - SHA-1:
ae62a3714339a4519bce1d56de7906e9971f4eb4 - MD5:
5116f53c857680c2f7192f7e81eb83ce - ssdeep:
768:V6VLgpuR9AL1HVsOiHaUD+bBG30q3RS4SGHvfGaTWolx:UVLggrAJH6HaUCbM3RBHvfGaTflx - TLSH:
T16C306CF71197CD9C794F8F03A9F9256D74CEA34961A6EA1040D8B32CE07CABE6B10521 - Submitted as: free-headless-head-roblox_GM431946152.pdf
- File type: pdf · Size: 36748 bytes
- Verdict: suspicious (44/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: Trojan:PDF/Phish.CFN!MTB
- Emsisoft (Emergency Kit): PDF.Spam.Heur.2
- Trellix Stinger (McAfee): PDF/Phish-TWM!5116F53C8576
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: http://netcdn.tw/app/431946152/free-headless-head-roblox-game-hack, https://www.modestuae.com/uploaded_files/userfiles/files/free-robux-without-any-verification_GM431946152.pdf, https://www.modestuae.com/uploaded_files/userfiles/files/vpn-for-roblox-hacking_GM431946152.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://netcdn.tw/app/431946152/free-headless-head-roblox-game-hack
- https://www.modestuae.com/uploaded_files/userfiles/files/free-robux-without-any-verification_GM431946152.pdf
- https://www.modestuae.com/uploaded_files/userfiles/files/vpn-for-roblox-hacking_GM431946152.pdf
- https://www.modestuae.com/uploaded_files/userfiles/files/free-robux-only-username-and-password_GM431946152.pdf
- https://www.modestuae.com/uploaded_files/userfiles/files/free-5-robux-site_GM431946152.pdf
- https://www.modestuae.com/uploaded_files/userfiles/files/coin-master-hack-xyz_GM406889139.pdf
- https://www.modestuae.com/uploaded_files/userfiles/files/free-items-on-alo-roblox_GM431946152.pdf
- https://www.modestuae.com/uploaded_files/userfiles/files/roblox-hacks-scythe-script_GM431946152.pdf
- https://www.modestuae.com/uploaded_files/userfiles/files/free-robux-no-verification-required_GM431946152.pdf
- https://www.modestuae.com/uploaded_files/userfiles/files/coin-master-free-link-facebook_GM406889139.pdf
- https://www.modestuae.com/uploaded_files/userfiles/files/how-to-free-robux_GM431946152.pdf
- https://www.modestuae.com/uploaded_files/userfiles/files/bloodborn-roblox-hack_GM431946152.pdf
- https://www.modestuae.com/uploaded_files/userfiles/files/basketball-free-charactes-in-roblox_GM431946152.pdf
- https://www.modestuae.com/uploaded_files/userfiles/files/rewards-roblox_GM431946152.pdf
- https://www.modestuae.com/uploaded_files/userfiles/files/como-hackear-coin-master_GM406889139.pdf
- https://www.modestuae.com/uploaded_files/userfiles/files/toolbox-apk_GM479516143.pdf
- https://www.modestuae.com/uploaded_files/userfiles/files/minecraft-tower-defense-2-hacked_GM479516143.pdf
- https://www.modestuae.com/uploaded_files/userfiles/files/free-robux-no-verification-at-all_GM431946152.pdf
- https://www.modestuae.com/uploaded_files/userfiles/files/free-robux-website_GM431946152.pdf
- https://www.modestuae.com/uploaded_files/userfiles/files/free-800-robux-code-2021_GM431946152.pdf
- https://www.modestuae.com/uploaded_files/userfiles/files/roblox-free-robux-hack_GM431946152.pdf
Embedded domains
- netcdn.tw
- www.modestuae.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report