SUSPICIOUS — kuso-icu-roblox-hack_GM431946152.pdf
SUSPICIOUS — kuso-icu-roblox-hack_GM431946152.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 4 of 53 detection engines flagged it.
Identification
- SHA-256:
da1f026e21f112bcf62392910a8c7abdb3a9bcb903f4fd5b2f865d2b85d3d6d8 - SHA-1:
73e4d9d8e7415452a6fbed80bbde565215a538f3 - MD5:
05a3969e5dc3f49ad5c86796743ad2e3 - ssdeep:
768:8T/vGJ5BsZ/u2DXTWFrlcNi/fcSZpNT45GmBggT:u3u56/u2DXTWFONiXcSZpN8BggT - TLSH:
T1E12F6BF70157CC4C678A8F836E7A152D62CDD2897662CF8055883B6C883C6AE7F60572 - Submitted as: kuso-icu-roblox-hack_GM431946152.pdf
- File type: pdf · Size: 35285 bytes
- Verdict: suspicious (44/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: Trojan:PDF/Phish.CFN!MTB
- Emsisoft (Emergency Kit): PDF.Spam.Heur.2
- Trellix Stinger (McAfee): PDF/Phish-TWM!05A3969E5DC3
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: http://netcdn.tw/app/431946152/kuso-icu-roblox-hack-game-hack, https://learningmts.pondokyajri.com/__statics/gudangsoal/files/robux-matchcomfree-robux_GM431946152.pdf, https://learningmts.pondokyajri.com/__statics/gudangsoal/files/roblox-free-robux-no-human-verification_GM431946152.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://netcdn.tw/app/431946152/kuso-icu-roblox-hack-game-hack
- https://learningmts.pondokyajri.com/__statics/gudangsoal/files/robux-matchcomfree-robux_GM431946152.pdf
- https://learningmts.pondokyajri.com/__statics/gudangsoal/files/roblox-free-robux-no-human-verification_GM431946152.pdf
- https://learningmts.pondokyajri.com/__statics/gudangsoal/files/free-minecraft-wallpaper_GM479516143.pdf
- https://learningmts.pondokyajri.com/__statics/gudangsoal/files/minecraft-java-edition-code-free_GM479516143.pdf
- https://learningmts.pondokyajri.com/__statics/gudangsoal/files/real-coin-master-hacks_GM406889139.pdf
- https://learningmts.pondokyajri.com/__statics/gudangsoal/files/como-activar-hacks-en-roblox_GM431946152.pdf
- https://learningmts.pondokyajri.com/__statics/gudangsoal/files/rbx-claim_GM431946152.pdf
- https://learningmts.pondokyajri.com/__statics/gudangsoal/files/free-robux-generator-2021-no-survey_GM431946152.pdf
- https://learningmts.pondokyajri.com/__statics/gudangsoal/files/free-bc-roblox-pastebin_GM431946152.pdf
- https://learningmts.pondokyajri.com/__statics/gudangsoal/files/free-robux-for-android-apk-downloads_GM431946152.pdf
- https://learningmts.pondokyajri.com/__statics/gudangsoal/files/coin-master-spins-hack-2021_GM406889139.pdf
- https://learningmts.pondokyajri.com/__statics/gudangsoal/files/how-to-hack-a-roblox-account-2021_GM431946152.pdf
- https://learningmts.pondokyajri.com/__statics/gudangsoal/files/roblox-apocalypse-rising-hack_GM431946152.pdf
- https://learningmts.pondokyajri.com/__statics/gudangsoal/files/roblox-hack-red-boy_GM431946152.pdf
- https://learningmts.pondokyajri.com/__statics/gudangsoal/files/free-robux-glitch_GM431946152.pdf
- https://learningmts.pondokyajri.com/__statics/gudangsoal/files/free-robux-no-downloads-2021-real_GM431946152.pdf
- https://learningmts.pondokyajri.com/__statics/gudangsoal/files/free-robux-2021-no-human-verification_GM431946152.pdf
- https://learningmts.pondokyajri.com/__statics/gudangsoal/files/free-pe_GM479516143.pdf
- https://learningmts.pondokyajri.com/__statics/gudangsoal/files/comment-hack-roblox-jailbreak_GM431946152.pdf
- https://learningmts.pondokyajri.com/__statics/gudangsoal/files/freespinandcoin-blogspot-coin-master_GM406889139.pdf
Embedded domains
- netcdn.tw
- learningmts.pondokyajri.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report