SUSPICIOUS — a57a8f14b3c033b3dd58f07fb3bce2d9793ece55a91b95f2fc6c3b7de273309f
SUSPICIOUS — a57a8f14b3c033b3dd58f07fb3bce2d9793ece55a91b95f2fc6c3b7de273309f is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 4 of 53 detection engines flagged it.
Identification
- SHA-256:
a57a8f14b3c033b3dd58f07fb3bce2d9793ece55a91b95f2fc6c3b7de273309f - SHA-1:
6d07ea2024170ecb963d0ad9adc73d0be4709fb8 - MD5:
34e0097c36467a32115eced55422e9f1 - ssdeep:
768:K10rwbMnguMcF/2NEKsL9beGHT9+by2WuK670Ki7:brwbk+NEKs5/z9+u2k6QKi7 - TLSH:
T1162E8EF7706BDE5C26878B075EF6209DA58587CC2021DB5459C836BCC178AFDAB00A62 - Submitted as: a57a8f14b3c033b3dd58f07fb3bce2d9793ece55a91b95f2fc6c3b7de273309f
- File type: pdf · Size: 31954 bytes
- Verdict: suspicious (44/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: Trojan:PDF/Phish.CFN!MTB
- Emsisoft (Emergency Kit): PDF.Spam.Heur.2
- Trellix Stinger (McAfee): PDF/Phish-TWM!34E0097C3646
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: http://netcdn.tw/app/479516143/how-to-get-minecraft-java-edition-for-free-game-hack, http://winnerwater.com.tw/image/data/files/play-minecraft-pocket-edition-for-free_GM479516143.pdf, http://winnerwater.com.tw/image/data/files/free-100-robux_GM431946152.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://netcdn.tw/app/479516143/how-to-get-minecraft-java-edition-for-free-game-hack
- http://winnerwater.com.tw/image/data/files/play-minecraft-pocket-edition-for-free_GM479516143.pdf
- http://winnerwater.com.tw/image/data/files/free-100-robux_GM431946152.pdf
- http://winnerwater.com.tw/image/data/files/free-spins-coin-master-links_GM406889139.pdf
- http://winnerwater.com.tw/image/data/files/how-to-get-free-tiktok-followers_GM835599320.pdf
- http://winnerwater.com.tw/image/data/files/free-robux-hack-2021_GM431946152.pdf
- http://winnerwater.com.tw/image/data/files/how-to-get-minecraft-for-free-on-mobile_GM479516143.pdf
- http://winnerwater.com.tw/image/data/files/free-robux-no-human-verification-or-survey_GM431946152.pdf
- http://winnerwater.com.tw/image/data/files/minecraft-pe-hack-client_GM479516143.pdf
- http://winnerwater.com.tw/image/data/files/free-tiktok-views_GM835599320.pdf
- http://winnerwater.com.tw/image/data/files/minecraft-windows-10-free-code_GM479516143.pdf
Embedded domains
- netcdn.tw
- winnerwater.com.tw
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report