SUSPICIOUS — site-fxcker-roblox-hack_GM431946152.pdf
SUSPICIOUS — site-fxcker-roblox-hack_GM431946152.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 5 of 53 detection engines flagged it.
Identification
- SHA-256:
93a49b9d9026f57b973fdfb7763d0a2bf495803bc1790e2fb80ae59bb52211de - SHA-1:
f95a26d888ae7c393fb1594bb54879886c820f6e - MD5:
cb6d5ed5a95808d73eb365e26420263d - ssdeep:
768:s7gDlQs41XmyTxm89ezWicxJy7Y0zcde0t:lRS1DTxm89ezWicxkc6cde0t - TLSH:
T1FD2F6CF3118BDC0C7A468B03ADFA615E64CAD39960A2EA6441D8A67CD07C5EF7B10621 - Submitted as: site-fxcker-roblox-hack_GM431946152.pdf
- File type: pdf · Size: 34340 bytes
- Verdict: suspicious (44/100)
Detections (5 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: Trojan:PDF/Phish.CFN!MTB
- Emsisoft (Emergency Kit): PDF.Spam.Heur.2
- Trellix Stinger (McAfee): PDF/Phish-TWM!CB6D5ED5A958
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: http://netcdn.co/app/431946152/site-fxcker-roblox-hack-game-hack, https://barokahutama.co.id/ckfinder/userfiles/files/free-coin-link-coin-master_GM406889139.pdf, https://barokahutama.co.id/ckfinder/userfiles/files/how-to-get-free-items-on-roblox_GM431946152.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://netcdn.co/app/431946152/site-fxcker-roblox-hack-game-hack
- https://barokahutama.co.id/ckfinder/userfiles/files/free-coin-link-coin-master_GM406889139.pdf
- https://barokahutama.co.id/ckfinder/userfiles/files/how-to-get-free-items-on-roblox_GM431946152.pdf
- https://barokahutama.co.id/ckfinder/userfiles/files/how-to-get-free-coins-and-spins-on-coin-master_GM406889139.pdf
- https://barokahutama.co.id/ckfinder/userfiles/files/free-spins-coin-master-daily_GM406889139.pdf
- https://barokahutama.co.id/ckfinder/userfiles/files/roblox-free-money-generator_GM431946152.pdf
- https://barokahutama.co.id/ckfinder/userfiles/files/how-to-get-roblox-credit-for-free_GM431946152.pdf
- https://barokahutama.co.id/ckfinder/userfiles/files/is-minecraft-vr-free_GM479516143.pdf
- https://barokahutama.co.id/ckfinder/userfiles/files/free-robux-no-verify_GM431946152.pdf
- https://barokahutama.co.id/ckfinder/userfiles/files/how-to-get-free-robux_GM431946152.pdf
- https://barokahutama.co.id/ckfinder/userfiles/files/how-to-get-free-robux-on-roblox_GM431946152.pdf
- https://barokahutama.co.id/ckfinder/userfiles/files/roblox-free-backpack_GM431946152.pdf
- https://barokahutama.co.id/ckfinder/userfiles/files/minecraft-fly-hack_GM479516143.pdf
- https://barokahutama.co.id/ckfinder/userfiles/files/minecraft-dungeons-free-download_GM479516143.pdf
- https://barokahutama.co.id/ckfinder/userfiles/files/free-coins-coin-master-link-2021_GM406889139.pdf
- https://barokahutama.co.id/ckfinder/userfiles/files/kachifpro_GM406889139.pdf
- https://barokahutama.co.id/ckfinder/userfiles/files/free-robux-groups-2021_GM431946152.pdf
- https://barokahutama.co.id/ckfinder/userfiles/files/coin-master-hack-tool-2021_GM406889139.pdf
- https://barokahutama.co.id/ckfinder/userfiles/files/how-to-hack-someones-account-on-roblox_GM431946152.pdf
- https://barokahutama.co.id/ckfinder/userfiles/files/free-robux-generator-2021-no-human-verification-or-survey_GM431946152.pdf
- https://barokahutama.co.id/ckfinder/userfiles/files/coin-master-free-spins-link-2021_GM406889139.pdf
Embedded domains
- netcdn.co
- barokahutama.co.id
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report