MALICIOUS — 5cc78e1bf8735859def97a7963f66f6b7d0f3a6b0619db4a1e96734251ff33b3
MALICIOUS — 5cc78e1bf8735859def97a7963f66f6b7d0f3a6b0619db4a1e96734251ff33b3 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 5 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
5cc78e1bf8735859def97a7963f66f6b7d0f3a6b0619db4a1e96734251ff33b3 - SHA-1:
6a78565ae4005235d7070eb29891d4523cf6f66b - MD5:
3a40ef7e1f781b255bdf8233c4a5cfc9 - ssdeep:
1536:EKvJ+XZsHWCIuCn9lzHZpA+UqVqJa6RYdq/P+:pgJz3uCn9ttUSAzRIqe - TLSH:
T1B337D0F37187DD8CB6C75783A9F6116DA04ADA869227D71044C8F26C91BC7BD2F20950 - Submitted as: 5cc78e1bf8735859def97a7963f66f6b7d0f3a6b0619db4a1e96734251ff33b3
- File type: pdf · Size: 75720 bytes
- Verdict: malicious (94/100)
Detections (5 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!3A40EF7E1F78
- Kaspersky (KVRT): HEUR:Hoax.PDF.Agent.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: https://webmodels.studio/wp-content/plugins/formcraft/file-upload/server/content/files/1607026d795f39---55711200919.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://drafthe.ru/uplcv?utm_term=pdf+reader+editor+apk, https://traveltokiev.com/wp-content/plugins/super-forms/uploads/php/files/0covfqkvgr1qgqbdf10coh5s02/19849086365.pdf, https://webmodels.studio/wp-content/plugins/formcraft/file-upload/server/content/files/1607026d795f39---55711200919.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://drafthe.ru/uplcv?utm_term=pdf+reader+editor+apk
- https://traveltokiev.com/wp-content/plugins/super-forms/uploads/php/files/0covfqkvgr1qgqbdf10coh5s02/19849086365.pdf
- https://webmodels.studio/wp-content/plugins/formcraft/file-upload/server/content/files/1607026d795f39---55711200919.pdf
- http://shinies.ru/img/lib/file/99022399258.pdf
- http://lt101shop.com/userfiles/files/91944387447.pdf
- https://www.properties-thassos.com/wp-content/plugins/super-forms/uploads/php/files/i8ij0mppeb0hlcu940it5a6ja2/nakaxilavenodogoful.pdf
- https://braviengenharia.com.br/wp-content/plugins/super-forms/uploads/php/files/36dln7vjrmlam43hc60q6dif75/solelerulupagaz.pdf
- https://atlanthealth.com/wp-content/plugins/super-forms/uploads/php/files/6df0290f8fb26bf7ec5a41896dc95724/85585556247.pdf
- http://triumphtoday.org/wp-content/plugins/formcraft/file-upload/server/content/files/16085e07ca0b96---xisusatonatavoga.pdf
- http://urbanconstructions.org/images/uploadedimages/file/88348339076.pdf
- http://mouaumfb.com/wp-content/plugins/formcraft/file-upload/server/content/files/1608356b5da48b---negopeb.pdf
- http://www.peopleoftheheath.com/wp-content/plugins/formcraft/file-upload/server/content/files/160b5257157df2---weloji.pdf
- http://xperion.hu/wp-content/plugins/super-forms/uploads/php/files/1bc2fb8126f83e93fb86591c253f7ac5/81265352589.pdf
- https://spectrumohio.com/wp-content/plugins/super-forms/uploads/php/files/dd59a233b067e6cb461126cecf7972e3/wewugososalavunulazunej.pdf
- https://www.hausbootgeiseltalsee.de/wp-content/plugins/super-forms/uploads/php/files/t9con3vqn5ava9ig9mk90mdern/bebofigelanokorapibukenu.pdf
- https://www.kadinlarsitesi.org/wp-content/plugins/formcraft/file-upload/server/content/files/1607e81f78d68d---sowofezifipapevogibija.pdf
- http://www.virtualaid.eu/wp-content/plugins/formcraft/file-upload/server/content/files/16076f4fea03d0---26388611819.pdf
- https://vidolamerica.org/wp-content/plugins/super-forms/uploads/php/files/3acfcd26966a6cf98230bcca0000d345/vebafukukisimubijebo.pdf
- https://paklya.su/design/img/upload/file/13081346613.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- drafthe.ru
- traveltokiev.com
- shinies.ru
- lt101shop.com
- www.properties-thassos.com
- braviengenharia.com.br
- atlanthealth.com
- triumphtoday.org
- urbanconstructions.org
- mouaumfb.com
- www.peopleoftheheath.com
- spectrumohio.com
- www.hausbootgeiseltalsee.de
- www.kadinlarsitesi.org
- www.virtualaid.eu
- vidolamerica.org
- paklya.su
- www.w3.org
- purl.org
- ns.adobe.com
- webmodels.studio
- xperion.hu
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report