SUSPICIOUS — roblox-free-robux-website_GM431946152.pdf
SUSPICIOUS — roblox-free-robux-website_GM431946152.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 4 of 53 detection engines flagged it.
Identification
- SHA-256:
f3feee95414af1eb312e06873c5a608377fc45b5ae944a652b282921ec960a17 - SHA-1:
93f6482d91afa004b7ea13d58317d59f5fea06c2 - MD5:
1b4844780d8159123ef3d8073842513d - ssdeep:
768:mziOt404iLsdzADwFUPcBX1Gyr5DwfheB9we:yi8TNMAy11GyFG49we - TLSH:
T1752F7DF71087DD4C398A4B07ADF7212DA88DE34861A6D64081D8776CE4BC6FE7B44922 - Submitted as: roblox-free-robux-website_GM431946152.pdf
- File type: pdf · Size: 35622 bytes
- Verdict: suspicious (44/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: Trojan:PDF/Phish.CFN!MTB
- Emsisoft (Emergency Kit): PDF.Spam.Heur.2
- Trellix Stinger (McAfee): PDF/Phish-TWM!1B4844780D81
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: http://netcdn.tw/app/431946152/roblox-free-robux-website-game-hack, https://www.wetotravels.com/uploaded_files/userfiles/files/free-minecraft-server_GM479516143.pdf, https://www.wetotravels.com/uploaded_files/userfiles/files/androeed-ru-minecraft_GM479516143.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://netcdn.tw/app/431946152/roblox-free-robux-website-game-hack
- https://www.wetotravels.com/uploaded_files/userfiles/files/free-minecraft-server_GM479516143.pdf
- https://www.wetotravels.com/uploaded_files/userfiles/files/androeed-ru-minecraft_GM479516143.pdf
- https://www.wetotravels.com/uploaded_files/userfiles/files/roblox-lab-experiment-hacks_GM431946152.pdf
- https://www.wetotravels.com/uploaded_files/userfiles/files/legit-free-spins-coin-master_GM406889139.pdf
- https://www.wetotravels.com/uploaded_files/userfiles/files/how-to-turn-in-to-super-sayin-roblox-no-hacks_GM431946152.pdf
- https://www.wetotravels.com/uploaded_files/userfiles/files/how-to-get-roblox-money_GM431946152.pdf
- https://www.wetotravels.com/uploaded_files/userfiles/files/one-app-rewards-robux-hack_GM431946152.pdf
- https://www.wetotravels.com/uploaded_files/userfiles/files/free-minecraft-realm-codes_GM479516143.pdf
- https://www.wetotravels.com/uploaded_files/userfiles/files/master-coin-hack-apk_GM406889139.pdf
- https://www.wetotravels.com/uploaded_files/userfiles/files/coin-master-200-spin-link_GM406889139.pdf
- https://www.wetotravels.com/uploaded_files/userfiles/files/how-to-hack-assassin-boxes-roblox_GM431946152.pdf
- https://www.wetotravels.com/uploaded_files/userfiles/files/roblox-army-free-robux_GM431946152.pdf
- https://www.wetotravels.com/uploaded_files/userfiles/files/roblox-land-free-robux_GM431946152.pdf
- https://www.wetotravels.com/uploaded_files/userfiles/files/robux-gratis-hack-2021_GM431946152.pdf
- https://www.wetotravels.com/uploaded_files/userfiles/files/coin-master-free-gift-links-2021_GM406889139.pdf
- https://www.wetotravels.com/uploaded_files/userfiles/files/20-free-spins-coin-master_GM406889139.pdf
- https://www.wetotravels.com/uploaded_files/userfiles/files/tiktok-free-wala_GM835599320.pdf
- https://www.wetotravels.com/uploaded_files/userfiles/files/no-human-verification-hack-for-coin-master_GM406889139.pdf
- https://www.wetotravels.com/uploaded_files/userfiles/files/how-to-get-free-robux-in-5-minutes_GM431946152.pdf
- https://www.wetotravels.com/uploaded_files/userfiles/files/roblox-shinobi-life-cheat-engine-spins_GM431946152.pdf
Embedded domains
- netcdn.tw
- www.wetotravels.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report