SUSPICIOUS — robux-hack-generator_GM431946152.pdf
SUSPICIOUS — robux-hack-generator_GM431946152.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 4 of 53 detection engines flagged it.
Identification
- SHA-256:
f485ad7f24d0907970951fc0715fc3e65536eed68486b43461f9b5a793e77992 - SHA-1:
7900e6d0a4c84a8d6d58fbcbf346b36ac489322a - MD5:
b8e2bbc09257a630475da875429a662a - ssdeep:
768:A1+NlJ09kRVthB4omP5OfxyFIXszqvw8ymQ8uN8CWC81WGg3UdkryZUR:AqKk7xyFI4qI8ygC80Gg3+UR - TLSH:
T1DD31BFF3412FCD9831C7A71399B52098321DA6DC7171DBA8A1C53A7CC5399ACAE90F21 - Submitted as: robux-hack-generator_GM431946152.pdf
- File type: pdf · Size: 40897 bytes
- Verdict: suspicious (44/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: Trojan:PDF/Phish.CFN!MTB
- Emsisoft (Emergency Kit): PDF.Spam.Heur.2
- Trellix Stinger (McAfee): PDF/Phish-TWM!B8E2BBC09257
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://netcdn.xyz/app/431946152/robux-hack-generator-game-hack - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://netcdn.xyz/app/431946152/robux-hack-generator-game-hack
Embedded domains
- netcdn.xyz
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report