SUSPICIOUS — minecraft-pe-apk-download-free-015-0_GM479516143.pdf
SUSPICIOUS — minecraft-pe-apk-download-free-015-0_GM479516143.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 4 of 53 detection engines flagged it.
Identification
- SHA-256:
8bdc2f3adc8866c4894ca8a64154cde827c871fadb804a55e0da8c4abf98a2ba - SHA-1:
c3d5e679788519f145e2bf1139529039101805e2 - MD5:
ee54b444bf9e9ce83be6c7a6e39a31f0 - ssdeep:
768:dlXO86XjMY/ej41narj/yAUe3G1glR0L3L6aF4uMzKLPDyjp:dlXOPjg6arj/yuOgEvk3KSjp - TLSH:
T16D31CEF3614BCD9C27479F1367FA7A28B9888AC83122CB2100C9767CC46C5FE9A51725 - Submitted as: minecraft-pe-apk-download-free-015-0_GM479516143.pdf
- File type: pdf · Size: 39383 bytes
- Verdict: suspicious (44/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: Trojan:PDF/Phish.CFN!MTB
- Emsisoft (Emergency Kit): PDF.Spam.Heur.2
- Trellix Stinger (McAfee): PDF/Phish-TWM!EE54B444BF9E
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://netcdn.xyz/app/479516143/minecraft-pe-apk-download-free-0.15-0-game-hack, https://elearning.mtsn7madiun.sch.id/__statics/gudangsoal/files/how-to-hack-roblox-for-robux_GM431946152.pdf, https://elearning.mtsn7madiun.sch.id/__statics/gudangsoal/files/coin-master-link-today_GM406889139.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://netcdn.xyz/app/479516143/minecraft-pe-apk-download-free-0.15-0-game-hack
- https://elearning.mtsn7madiun.sch.id/__statics/gudangsoal/files/how-to-hack-roblox-for-robux_GM431946152.pdf
- https://elearning.mtsn7madiun.sch.id/__statics/gudangsoal/files/coin-master-link-today_GM406889139.pdf
- https://elearning.mtsn7madiun.sch.id/__statics/gudangsoal/files/pubg-uc-purchase_GM1330123889.pdf
- https://elearning.mtsn7madiun.sch.id/__statics/gudangsoal/files/roblox-account-taker_GM431946152.pdf
- https://elearning.mtsn7madiun.sch.id/__statics/gudangsoal/files/coin-master-hack-apk-july-2021_GM406889139.pdf
Embedded domains
- netcdn.xyz
- elearning.mtsn7madiun.sch.id
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report