MALICIOUS — she_stoops_to_conquer_summary_slideshare.pdf
MALICIOUS — she_stoops_to_conquer_summary_slideshare.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 5 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
9762b6af1daa7f00a428082e47f36b74d85ab6af7bbe01146a6cb6db0f7b03ee - SHA-1:
e3dc0a6a0837adf375ef98ff6efd6bddd9250c26 - MD5:
8fa1f57a498971be309062ffa6cb2350 - ssdeep:
1536:hAEwt5iq4GvotWbKwW0s/OuBfLpo/Dz3ubTdFzBf6o19xiGgDrWR6PIXR9DMYyH6:ChIYgvfLI3wdtlTxiNrWLR9DMYyHy0a5 - TLSH:
T19639D0F321DBDD9C7B45A7636AA5216CB4CEDB445132E3E01188BA2CC47C1BD3E50A91 - Submitted as: she_stoops_to_conquer_summary_slideshare.pdf
- File type: pdf · Size: 87814 bytes
- Verdict: malicious (96/100)
Detections (5 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!8FA1F57A4989
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: https://uploads.strikinglycdn.com/files/0e22f5eb-5218-4b6e-a0ae-1d940e3a8b8d/7817078902.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://dugedepap.ru/strik?utm_term=she+stoops+to+conquer+summary+slideshare, https://uploads.strikinglycdn.com/files/0e22f5eb-5218-4b6e-a0ae-1d940e3a8b8d/7817078902.pdf, https://cdn-cms.f-static.net/uploads/4470385/normal_5fd2afce7df89.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://dugedepap.ru/strik?utm_term=she+stoops+to+conquer+summary+slideshare
- https://uploads.strikinglycdn.com/files/0e22f5eb-5218-4b6e-a0ae-1d940e3a8b8d/7817078902.pdf
- https://cdn-cms.f-static.net/uploads/4470385/normal_5fd2afce7df89.pdf
- https://cdn-cms.f-static.net/uploads/4410222/normal_603fc8f22277e.pdf
- https://cdn-cms.f-static.net/uploads/4486045/normal_6015e255e1b02.pdf
- https://uploads.strikinglycdn.com/files/d5c6c02e-4b88-47ef-b9b7-654cb74a809e/how_to_connect_my_pixma_printer_to_wifi.pdf
- https://cdn-cms.f-static.net/uploads/4469631/normal_5fe639d22af32.pdf
- https://static.s123-cdn-static.com/uploads/4470692/normal_5fe3e63a8619e.pdf
- https://cdn-cms.f-static.net/uploads/4387816/normal_601ecb779dee2.pdf
- https://static.s123-cdn-static.com/uploads/4417414/normal_6001131cbbe0d.pdf
- https://cdn-cms.f-static.net/uploads/4446650/normal_60244991f0cda.pdf
- https://s3.amazonaws.com/rufonali/bachelor_degree_in_information_technology_in_germany.pdf
- https://cdn-cms.f-static.net/uploads/4415745/normal_6030223c64fe9.pdf
- https://cdn-cms.f-static.net/uploads/4474192/normal_6062200dad415.pdf
- https://uploads.strikinglycdn.com/files/9a57e235-d3bb-4bb8-870a-a04f2f53c7b1/nuxotulurutopemena.pdf
- https://cdn-cms.f-static.net/uploads/4420756/normal_606260e493c8f.pdf
- https://cdn-cms.f-static.net/uploads/4454306/normal_605dc37dd79fc.pdf
- https://cdn-cms.f-static.net/uploads/4402956/normal_602ed2a32fabd.pdf
- https://cdn-cms.f-static.net/uploads/4421613/normal_60188a05d9412.pdf
- https://cdn-cms.f-static.net/uploads/4453342/normal_604ecf4af18f1.pdf
- https://s3.amazonaws.com/tupofelasujewas/business_model_validation.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- dugedepap.ru
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- static.s123-cdn-static.com
- s3.amazonaws.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report