MALICIOUS — 4f8c302c.pdf
MALICIOUS — 4f8c302c.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
73f4c03e84287eb3f3684e366ec2e3b74962eba8810022bbc97323e4f7ce5c98 - SHA-1:
06975bfd09bd94c9004c3e4c12eb1f641f822b2b - MD5:
c142f1a25afd9eba16764b79a7edae52 - ssdeep:
1536:GiT9qx1znpkQjIEOyuUU+VsG681403ZbsM/eGkWEE0Gojp1p:zaZ1nnGGvGGojV - TLSH:
T1FF37DFF39157CD9CBA87AB833AF6211DB44692883131E7704489BA2DC4782BD7F61D41 - Submitted as: 4f8c302c.pdf
- File type: pdf · Size: 72254 bytes
- Verdict: malicious (94/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: https://static1.squarespace.com/static/5fc28fbed26ff1194f7e5808/t/5fc640bfe6d49a06bb67be06/1606828224577/video_game_cheat_code_button.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://trafficel.ru/wb?keyword=fall%20leaf%20template%20for%20writing, https://uploads.strikinglycdn.com/files/2be18af1-37c1-432e-878f-116615d09845/how_is_holy_water_made.pdf, https://uploads.strikinglycdn.com/files/01a507b9-3780-49df-a11d-34a40d7b5ca6/down_by_the_old_mill_stream_wiki.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://trafficel.ru/wb?keyword=fall%20leaf%20template%20for%20writing
- https://uploads.strikinglycdn.com/files/2be18af1-37c1-432e-878f-116615d09845/how_is_holy_water_made.pdf
- https://uploads.strikinglycdn.com/files/01a507b9-3780-49df-a11d-34a40d7b5ca6/down_by_the_old_mill_stream_wiki.pdf
- https://uploads.strikinglycdn.com/files/e8cec392-541f-49e6-90d3-db9ec67e5f95/palewidirajenejedevetoxo.pdf
- https://uploads.strikinglycdn.com/files/16c3b6f0-7d77-4084-a489-c2f25558bbb2/37511765202.pdf
- https://rokufekajo.weebly.com/uploads/1/3/0/8/130814342/2351746.pdf
- https://jodobape.weebly.com/uploads/1/3/4/3/134317169/fofetuporuredodubiri.pdf
- https://uploads.strikinglycdn.com/files/585282f0-679d-4dfa-904e-53e05c5e70e5/wujufu.pdf
- https://static1.squarespace.com/static/5fc28fbed26ff1194f7e5808/t/5fc640bfe6d49a06bb67be06/1606828224577/video_game_cheat_code_button.pdf
- https://static1.squarespace.com/static/5fc7adb7791da6493f6bdfc1/t/5fcb48e833fb14715cb94917/1607157994055/bufudupuxaxamoruvisusoxo.pdf
- https://uploads.strikinglycdn.com/files/6a5824b3-4b1b-4e4a-afdb-96b8176c455c/volevazijozibararore.pdf
- https://uploads.strikinglycdn.com/files/73c3aa31-088c-4189-8fbe-5896abf6ce11/infecciones_de_transmision_sexualidad.pdf
- https://static1.squarespace.com/static/5fc4c46cc89e1c4b8fd75f72/t/5fce4201fe657040d5bf18f5/1607352834243/download_game_live_or_die_zombie_survival_mod.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- trafficel.ru
- uploads.strikinglycdn.com
- rokufekajo.weebly.com
- jodobape.weebly.com
- static1.squarespace.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report