SUSPICIOUS — rbl-gg-free-robux_GM431946152.pdf
SUSPICIOUS — rbl-gg-free-robux_GM431946152.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 5 of 53 detection engines flagged it.
Identification
- SHA-256:
f901fcd337480c0de55dab0a0ad1be93b1dc0204d84f4fdb036a838a03247662 - SHA-1:
d68b46bb5bf4b90f68a9c261b49fa164338da718 - MD5:
936617b3632fc41933c03e0a3872ec64 - ssdeep:
768:gBB+Ab5sV1iOxISwvn8Zafk2SeBFEmVm/vVj5J:o3K41v8sDBmwm/v15J - TLSH:
T1052F6DF75487CC8C7A8A4F03A9FA955DB8CAC38DB072DE41D4D4362C946C6AE7B40161 - Submitted as: rbl-gg-free-robux_GM431946152.pdf
- File type: pdf · Size: 34943 bytes
- Verdict: suspicious (44/100)
Detections (5 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: Trojan:PDF/Phish.CFN!MTB
- Emsisoft (Emergency Kit): PDF.Spam.Heur.2
- Trellix Stinger (McAfee): PDF/Phish-TWM!936617B3632F
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: http://netcdn.tw/app/431946152/rbl-gg-free-robux-game-hack, http://elearning.mtsnkra.sch.id/__statics/gudangsoal/files/secrcet-free-roblox-hats_GM431946152.pdf, http://elearning.mtsnkra.sch.id/__statics/gudangsoal/files/roblox-hack-scripts-pastebin_GM431946152.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://netcdn.tw/app/431946152/rbl-gg-free-robux-game-hack
- http://elearning.mtsnkra.sch.id/__statics/gudangsoal/files/secrcet-free-roblox-hats_GM431946152.pdf
- http://elearning.mtsnkra.sch.id/__statics/gudangsoal/files/roblox-hack-scripts-pastebin_GM431946152.pdf
- http://elearning.mtsnkra.sch.id/__statics/gudangsoal/files/free-auto-clicker-for-roblox-ipad_GM431946152.pdf
- http://elearning.mtsnkra.sch.id/__statics/gudangsoal/files/coin-master-free-spins-link-download-ios_GM406889139.pdf
- http://elearning.mtsnkra.sch.id/__statics/gudangsoal/files/how-to-get-free-robux-urban420-network_GM431946152.pdf
- http://elearning.mtsnkra.sch.id/__statics/gudangsoal/files/roblox-free-military-clothes_GM431946152.pdf
- http://elearning.mtsnkra.sch.id/__statics/gudangsoal/files/roblox-promo-hack-code_GM431946152.pdf
- http://elearning.mtsnkra.sch.id/__statics/gudangsoal/files/free-coins-on-coin-master_GM406889139.pdf
- http://elearning.mtsnkra.sch.id/__statics/gudangsoal/files/xbox-john-roblox-free_GM431946152.pdf
- http://elearning.mtsnkra.sch.id/__statics/gudangsoal/files/robux-best_GM431946152.pdf
- http://elearning.mtsnkra.sch.id/__statics/gudangsoal/files/free-roblox-shirts-to-upload_GM431946152.pdf
- http://elearning.mtsnkra.sch.id/__statics/gudangsoal/files/free-spins-from-coin-master_GM406889139.pdf
- http://elearning.mtsnkra.sch.id/__statics/gudangsoal/files/free-robux-codes-no-verification-2021_GM431946152.pdf
- http://elearning.mtsnkra.sch.id/__statics/gudangsoal/files/coin-master-hack-xyz_GM406889139.pdf
- http://elearning.mtsnkra.sch.id/__statics/gudangsoal/files/how-to-hack-someones-roblox-account_GM431946152.pdf
- http://elearning.mtsnkra.sch.id/__statics/gudangsoal/files/natural-disaster-roblox-cheats_GM431946152.pdf
- http://elearning.mtsnkra.sch.id/__statics/gudangsoal/files/roblox-cheating-story_GM431946152.pdf
- http://elearning.mtsnkra.sch.id/__statics/gudangsoal/files/roblox-hacked-client-mac_GM431946152.pdf
- http://elearning.mtsnkra.sch.id/__statics/gudangsoal/files/roblox-online-hack-2021_GM431946152.pdf
- http://elearning.mtsnkra.sch.id/__statics/gudangsoal/files/how-to-hack-robux_GM431946152.pdf
Embedded domains
- netcdn.tw
- elearning.mtsnkra.sch.id
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report