SUSPICIOUS — how-to-hack-coin-master-facebook_GM406889139.pdf
SUSPICIOUS — how-to-hack-coin-master-facebook_GM406889139.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 5 of 53 detection engines flagged it.
Identification
- SHA-256:
6e4a1ebe1c9df1bc84729371329bb5af7ef4c4cba61905ced8a165bb0aacf4a9 - SHA-1:
9b0ee7932654cb123b33316e7417705fd4d8e752 - MD5:
034563b5a08198074f86e5ce9492fb34 - ssdeep:
768:pQJTFClvdUzj5bdd2rD2NiRLCiOVItnCKA6kq:rilbdMuiRLC5VItw6kq - TLSH:
T1DC2F7DF71197CD4C658ACF036EB75859A88AC38C71729A4455CC7B2C84AC9BE7F10932 - Submitted as: how-to-hack-coin-master-facebook_GM406889139.pdf
- File type: pdf · Size: 35032 bytes
- Verdict: suspicious (44/100)
Detections (5 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: Trojan:PDF/Phish.CFN!MTB
- Emsisoft (Emergency Kit): PDF.Spam.Heur.2
- Trellix Stinger (McAfee): PDF/Phish-TWM!034563B5A081
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: http://netcdn.tw/app/406889139/how-to-hack-coin-master-facebook-game-hack, http://joaquimdourado.adv.br/uploads/ckfinder/files/roblox-play-as-guest-free_GM431946152.pdf, http://joaquimdourado.adv.br/uploads/ckfinder/files/roblox-virus-free-hack-clients_GM431946152.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://netcdn.tw/app/406889139/how-to-hack-coin-master-facebook-game-hack
- http://joaquimdourado.adv.br/uploads/ckfinder/files/roblox-play-as-guest-free_GM431946152.pdf
- http://joaquimdourado.adv.br/uploads/ckfinder/files/roblox-virus-free-hack-clients_GM431946152.pdf
- http://joaquimdourado.adv.br/uploads/ckfinder/files/free-goku-clothes-roblox_GM431946152.pdf
- http://joaquimdourado.adv.br/uploads/ckfinder/files/free-online-roblox-tycoons_GM431946152.pdf
- http://joaquimdourado.adv.br/uploads/ckfinder/files/roblox-booga-booga-mojo-hack-wearedevs_GM431946152.pdf
- http://joaquimdourado.adv.br/uploads/ckfinder/files/black-adidas-shirt-roblox-free_GM431946152.pdf
- http://joaquimdourado.adv.br/uploads/ckfinder/files/minecraft-java-edition-free-code_GM479516143.pdf
- http://joaquimdourado.adv.br/uploads/ckfinder/files/how-to-get-free-robux-on-windows-10-2021_GM431946152.pdf
- http://joaquimdourado.adv.br/uploads/ckfinder/files/hacks-fr-roblox_GM431946152.pdf
- http://joaquimdourado.adv.br/uploads/ckfinder/files/free-online-games-like-minecraft_GM479516143.pdf
- http://joaquimdourado.adv.br/uploads/ckfinder/files/coin-master-free-spins-link-2021-today_GM406889139.pdf
- http://joaquimdourado.adv.br/uploads/ckfinder/files/robux-generator-download-from-http-wehackcom-robloxgeneratorfree_GM431946152.pdf
- http://joaquimdourado.adv.br/uploads/ckfinder/files/how-long-is-the-minecraft-free-trial_GM479516143.pdf
- http://joaquimdourado.adv.br/uploads/ckfinder/files/free-20210-robux_GM431946152.pdf
- http://joaquimdourado.adv.br/uploads/ckfinder/files/como-conseguir-robux-hack-2021_GM431946152.pdf
- http://joaquimdourado.adv.br/uploads/ckfinder/files/coin-master-free-gold-cards_GM406889139.pdf
- http://joaquimdourado.adv.br/uploads/ckfinder/files/roblox-gift-card-free-codes_GM431946152.pdf
- http://joaquimdourado.adv.br/uploads/ckfinder/files/100-free-spins-coin-master_GM406889139.pdf
- http://joaquimdourado.adv.br/uploads/ckfinder/files/free-spins-coins-coin-master_GM406889139.pdf
- http://joaquimdourado.adv.br/uploads/ckfinder/files/free-obc-accounts-roblox_GM431946152.pdf
Embedded domains
- netcdn.tw
- joaquimdourado.adv.br
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report