MALICIOUS — c8dd50640df4e5a6da55191d06d85b34a9bcc3aedf45226469902e5ae8175912
MALICIOUS — c8dd50640df4e5a6da55191d06d85b34a9bcc3aedf45226469902e5ae8175912 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 5 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
c8dd50640df4e5a6da55191d06d85b34a9bcc3aedf45226469902e5ae8175912 - SHA-1:
2630180e0c79204e931a8ac67dfd0c6ebb81f86f - MD5:
5f4eca5fe84dc0bce52644a23eb92fe1 - ssdeep:
1536:pkeae+58YxH8FVPE+QoEcomuDvoo1DcyAdUSXdoAzo1cht:mPfabFVPXW11DcyKRtoCo14 - TLSH:
T10B39C0F761EBDE4CFE4B9713AABA547A688FD3841432DB50049CB71CC86C86C2E24911 - Submitted as: c8dd50640df4e5a6da55191d06d85b34a9bcc3aedf45226469902e5ae8175912
- File type: pdf · Size: 88114 bytes
- Verdict: malicious (96/100)
Detections (5 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!5F4ECA5FE84D
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: https://static.s123-cdn-static.com/uploads/4387232/normal_5ff1bb107c4a1.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://laborke.ru/pbw?utm_term=interpreting+line+graphs+worksheet+high+school+pdf, https://uploads.strikinglycdn.com/files/a23f9ba3-0bc0-430a-8783-d084e9d58ef4/how_to_get_a_drivers_license_in_maine.pdf, https://static.s123-cdn-static.com/uploads/4387232/normal_5ff1bb107c4a1.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://laborke.ru/pbw?utm_term=interpreting+line+graphs+worksheet+high+school+pdf
- https://uploads.strikinglycdn.com/files/a23f9ba3-0bc0-430a-8783-d084e9d58ef4/how_to_get_a_drivers_license_in_maine.pdf
- https://static.s123-cdn-static.com/uploads/4387232/normal_5ff1bb107c4a1.pdf
- https://uploads.strikinglycdn.com/files/f06448db-31a4-4133-a5bf-64c1330c6f5c/miracle_frp_tool_thunder_edition_v1_47_crack_download.pdf
- https://uploads.strikinglycdn.com/files/e9cdd575-613c-4e0e-8600-b7a41d5eda9a/descargar_pokemon_blanco_2_emulador_ds.pdf
- https://cdn-cms.f-static.net/uploads/4451542/normal_6009f6a77dde1.pdf
- https://cdn-cms.f-static.net/uploads/4407069/normal_606d68033399d.pdf
- https://cdn-cms.f-static.net/uploads/4495837/normal_6043488b5fc90.pdf
- https://nijumaweka.weebly.com/uploads/1/3/1/3/131379182/7096730.pdf
- https://static.s123-cdn-static-d.com/uploads/4474470/normal_60b3e9fc08e57.pdf
- https://uploads.strikinglycdn.com/files/277fac52-70b8-4e27-bd19-305ea5e1306f/71955296949.pdf
- https://uploads.strikinglycdn.com/files/a01d36ab-d80c-455a-9f36-170a2e226977/how_to_ask_personal_questions.pdf
- https://uploads.strikinglycdn.com/files/68e87b22-f79d-4b82-a8b1-da2913091d14/52271765308.pdf
- https://mitexasax.weebly.com/uploads/1/3/1/8/131857270/9860614.pdf
- https://static.s123-cdn-static.com/uploads/4368228/normal_6004741186c77.pdf
- https://uploads.strikinglycdn.com/files/ba22f923-631c-43de-a2ff-83f377f2a754/boy_scouts_of_america_store_salt_lake_city_utah.pdf
- https://uploads.strikinglycdn.com/files/6ef5971a-e297-4a26-ae22-97dae84d5d0d/67667656779.pdf
- https://uploads.strikinglycdn.com/files/7e9f3d67-18f0-4bc4-ad6a-601d3fc7597b/sims_4_update_november_2020_ps4.pdf
- https://static.s123-cdn-static-d.com/uploads/4369769/normal_60b5e09a3435e.pdf
- https://cdn-cms.f-static.net/uploads/4417226/normal_6035c93dd2fb4.pdf
- https://cdn-cms.f-static.net/uploads/4417123/normal_601a1bd36b065.pdf
- https://cdn-cms.f-static.net/uploads/4377679/normal_603810e376d30.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- laborke.ru
- uploads.strikinglycdn.com
- static.s123-cdn-static.com
- cdn-cms.f-static.net
- nijumaweka.weebly.com
- static.s123-cdn-static-d.com
- mitexasax.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report