MALICIOUS — what_order_should_i_watch_the_silence_of_the_lambs_series.pdf
MALICIOUS — what_order_should_i_watch_the_silence_of_the_lambs_series.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (92/100). 5 of 53 detection engines flagged it.
Identification
- SHA-256:
139c07f64ce7684c695c8939178c7ff7bd1faa19c6f7275811f1e95354595690 - SHA-1:
2c4c5236aefe1c7d06af326c9542c31288b11e0b - MD5:
e38f7a2fc8755950c3d84009bdd70c7f - ssdeep:
1536:/bOh902YK0BS3xMGkfPyLeLtwcBWyz1x5CFCkiHt1v5GO30wb96x/oCkw/SSeuIg:/qLppPhGyLeLq0Wav5lN1UpiDw/SvunF - TLSH:
T14938C0F300ABDC5C3B4B6F13AAFB1A59A489C3883521AB81084C765DD5BC6EF7E50650 - Submitted as: what_order_should_i_watch_the_silence_of_the_lambs_series.pdf
- File type: pdf · Size: 77742 bytes
- Verdict: malicious (92/100)
Detections (5 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!E38F7A2FC875
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
Why this verdict
The malicious score of 92/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded network infrastructure: https://jacksth.ru/strik?utm_term=what+order+should+i+watch+the+silence+of+the+lambs+series, https://uploads.strikinglycdn.com/files/91070df8-6169-43b6-8f98-5920d1a8a08f/carrier_9200_code_31.pdf, https://cdn-cms.f-static.net/uploads/4476127/normal_5fd742b96111c.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://jacksth.ru/strik?utm_term=what+order+should+i+watch+the+silence+of+the+lambs+series
- https://uploads.strikinglycdn.com/files/91070df8-6169-43b6-8f98-5920d1a8a08f/carrier_9200_code_31.pdf
- https://cdn-cms.f-static.net/uploads/4476127/normal_5fd742b96111c.pdf
- http://fowidosufos.epizy.com/catia_v5-6r2014_for_beginners.pdf
- https://uploads.strikinglycdn.com/files/6687729e-f96a-4250-89ac-b3193941e9c1/mazinizefunokijive.pdf
- https://cdn-cms.f-static.net/uploads/4381978/normal_6010893ecb323.pdf
- https://cdn-cms.f-static.net/uploads/4420019/normal_6034c5185a282.pdf
- https://cdn-cms.f-static.net/uploads/4379742/normal_60439445db8d4.pdf
- https://uploads.strikinglycdn.com/files/d2f2ae56-d7be-49e9-b348-5fb3b9025cd1/will_there_be_a_third_book_in_the_you_series.pdf
- http://roxaresasupuke.iblogger.org/godinejitex.pdf
- https://static.s123-cdn-static.com/uploads/4426954/normal_6007b6838af8f.pdf
- https://cdn-cms.f-static.net/uploads/4446500/normal_603af98b355f8.pdf
- https://static.s123-cdn-static.com/uploads/4409255/normal_5fc6dd6bee3ca.pdf
- http://help-violation.com/how_to_restart_verizon_router_g3100f2ox1.pdf
- http://bewaniv.22web.org/liftmaster_p3_security_2.0_program_remote.pdf
- https://uploads.strikinglycdn.com/files/32e50e33-4570-46aa-85ab-22dd2059789d/brandsmart_usa_thanksgiving_hours.pdf
- http://de-bewertung-id2842384.icu/pioneer_avh-x3600bhs_appslg59n.pdf
- https://cdn-cms.f-static.net/uploads/4448345/normal_602cb6054e805.pdf
- http://deemonatrafik.xyz/576805877732dndr.pdf
- https://static.s123-cdn-static.com/uploads/4455901/normal_5ff772c8b4778.pdf
- https://uploads.strikinglycdn.com/files/4ee0c69e-376b-4a7b-9df4-79f0a588c617/elite_air_fryer.pdf
- http://fukatotapi.epizy.com/esia_screening_report.pdf
- http://tididesonorevo.rf.gd/rumafisux.pdf
- https://static.s123-cdn-static.com/uploads/4451752/normal_5ff84c96d7d4a.pdf
- https://cdn-cms.f-static.net/uploads/4382966/normal_603542b3f13d8.pdf
Embedded domains
- jacksth.ru
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- fowidosufos.epizy.com
- roxaresasupuke.iblogger.org
- static.s123-cdn-static.com
- help-violation.com
- bewaniv.22web.org
- de-bewertung-id2842384.icu
- deemonatrafik.xyz
- fukatotapi.epizy.com
- 4kuhd.me
- www.w3.org
- purl.org
- ns.adobe.com
- tididesonorevo.rf.gd
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report