MALICIOUS — fire_emblem_heroes_error_code_803.pdf
MALICIOUS — fire_emblem_heroes_error_code_803.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (75/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
7c44865c3e23e6256dd5a21340665cf72effe8143bdcc72cb2a4a8887f757e43 - SHA-1:
e50e1f2e3d0cbfaa457dbb1e3c070be175535431 - MD5:
5bd0b717497a0a71ab20c67ee07c8b80 - ssdeep:
768:8gGzpDNpnsCoTOvYSFIc9IMs07CJE4gt3PPcfUKjlS6mkkc0:ZGFppBFIcCQ4gtHsURkkc0 - TLSH:
T1EB316CF350ABED4C798BEF43A9AE295D908DC3485172A760548C762DC0BC7BE2F50911 - Submitted as: fire_emblem_heroes_error_code_803.pdf
- File type: pdf · Size: 42845 bytes
- Verdict: malicious (75/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Microsoft Defender: flagged
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The malicious score of 75/100 is the fusion of 4 weighted signals:
- Embedded link rated malicious by URL analysis: https://gapefupekud.weebly.com/uploads/1/3/1/8/131871489/ruzupaxawija.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://cctraff.ru/strik?keyword=fire+emblem+heroes+error+code+803, https://tavumake.weebly.com/uploads/1/3/2/7/132740551/suvex-xebubonozov-gavubukegago.pdf, https://juragubiv.weebly.com/uploads/1/3/0/8/130874328/lokufesurumib.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/strik?keyword=fire+emblem+heroes+error+code+803
- https://tavumake.weebly.com/uploads/1/3/2/7/132740551/suvex-xebubonozov-gavubukegago.pdf
- https://juragubiv.weebly.com/uploads/1/3/0/8/130874328/lokufesurumib.pdf
- https://gapefupekud.weebly.com/uploads/1/3/1/8/131871489/ruzupaxawija.pdf
- https://genigudepa.weebly.com/uploads/1/3/1/0/131070712/1cf22.pdf
- https://nobinetezo.weebly.com/uploads/1/3/0/9/130969761/nirawugolegu.pdf
- https://tavumake.weebly.com/uploads/1/3/2/7/132740551/daxurugut.pdf
- https://nobinetezo.weebly.com/uploads/1/3/0/9/130969761/914e7258.pdf
- https://xedaliwim.weebly.com/uploads/1/3/1/4/131454603/sudamoraz.pdf
- https://cdn-cms.f-static.net/uploads/4368742/normal_5f88197fd6733.pdf
- https://cdn-cms.f-static.net/uploads/4365589/normal_5f891b81e56e4.pdf
- https://cdn-cms.f-static.net/uploads/4366308/normal_5f875e0a55468.pdf
- https://cdn-cms.f-static.net/uploads/4368949/normal_5f8969183b7ea.pdf
- https://cdn-cms.f-static.net/uploads/4366389/normal_5f87596fea60e.pdf
- https://uploads.strikinglycdn.com/files/0aadebda-2748-4c0f-b11a-065441bd2c12/72674891373.pdf
- https://uploads.strikinglycdn.com/files/363e064b-ed78-471e-967b-a5101b4f79d6/wifitolugovuj.pdf
- https://uploads.strikinglycdn.com/files/3e754ae4-a46c-4791-858b-48a78710ea5f/dofil.pdf
- https://uploads.strikinglycdn.com/files/b273619b-a796-43df-a2a1-aa7d0b907ad2/51305952116.pdf
- https://uploads.strikinglycdn.com/files/f7710350-aec8-4f10-9283-b58e61bc0f09/nakejokadop.pdf
- https://uploads.strikinglycdn.com/files/3d97cd3f-2644-442c-80c0-150628d67060/13300531696.pdf
- https://uploads.strikinglycdn.com/files/97e45ed8-f1de-4524-b411-b71f452b6c2d/9459319448.pdf
- https://uploads.strikinglycdn.com/files/70d97970-531d-4b4d-aa73-ce0fa6fc3421/9734414490.pdf
- https://uploads.strikinglycdn.com/files/87e5de68-eaff-4b99-b64e-9fd9e7081832/silugiwadabozakasara.pdf
- https://uploads.strikinglycdn.com/files/d914ee76-b478-403c-ac60-201821291c47/pafovib.pdf
- https://uploads.strikinglycdn.com/files/7aab08c3-889a-4aa5-ae7e-eda3d3f37ebe/xesobigogadaxodaluxan.pdf
Embedded domains
- cctraff.ru
- tavumake.weebly.com
- juragubiv.weebly.com
- gapefupekud.weebly.com
- genigudepa.weebly.com
- nobinetezo.weebly.com
- xedaliwim.weebly.com
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report