MALICIOUS — f3c4d5890ed0a115879022d01c0d96ca8f0c80d88fa7971675c129e9321cac0c
MALICIOUS — f3c4d5890ed0a115879022d01c0d96ca8f0c80d88fa7971675c129e9321cac0c is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 5 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
f3c4d5890ed0a115879022d01c0d96ca8f0c80d88fa7971675c129e9321cac0c - SHA-1:
a996a81002b10d8129ccb4cd9d92197569aa3020 - MD5:
cb02fae378e2ef2699b700505a8db8e3 - ssdeep:
1536:su95BnuuzM445F+kS9C7sXKCLA9uW0aXwRmIcY2SDI:pfSF+b9C7P9B0aXwRdF2b - TLSH:
T13B36D1F3A143DE9D3F8B5B1379BB115CA98AD5843036DBD01088BA2F517CAADAE00C51 - Submitted as: f3c4d5890ed0a115879022d01c0d96ca8f0c80d88fa7971675c129e9321cac0c
- File type: pdf · Size: 68637 bytes
- Verdict: malicious (96/100)
Detections (5 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!CB02FAE378E2
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: https://static.s123-cdn-static.com/uploads/4377128/normal_600212b9b33dd.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://botokaw.ru/strik?utm_term=how+to+prepare+dextrose+powder+for+dogs, https://sawuvuvexefiz.weebly.com/uploads/1/3/5/9/135964560/3c1babb0712.pdf, https://cdn-cms.f-static.net/uploads/4372983/normal_605a4a3019028.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://botokaw.ru/strik?utm_term=how+to+prepare+dextrose+powder+for+dogs
- https://sawuvuvexefiz.weebly.com/uploads/1/3/5/9/135964560/3c1babb0712.pdf
- https://cdn-cms.f-static.net/uploads/4372983/normal_605a4a3019028.pdf
- https://uploads.strikinglycdn.com/files/d60858b1-292a-47d5-9360-d53bbb4e5201/what_is_rhetorical_structure_theory.pdf
- https://cdn-cms.f-static.net/uploads/4496005/normal_605f0d6ee1429.pdf
- https://zutekavewer.weebly.com/uploads/1/3/4/5/134514418/632763.pdf
- https://static.s123-cdn-static.com/uploads/4377128/normal_600212b9b33dd.pdf
- https://rapusixub.weebly.com/uploads/1/3/4/6/134631860/ada11739d373.pdf
- https://uploads.strikinglycdn.com/files/85f9c713-6c26-4cf3-b84a-e845fa3b90dd/transfer_of_heat_class_7_science.pdf
- https://giwaxevo.weebly.com/uploads/1/3/4/6/134644090/bidaf.pdf
- https://bunepefetupudir.weebly.com/uploads/1/3/2/7/132741430/c2a3009.pdf
- https://uploads.strikinglycdn.com/files/ecdec661-66ae-45da-b13a-a0624e001f67/4326592706.pdf
- https://widawukilifuduz.weebly.com/uploads/1/3/5/3/135398171/zobizibunaziwakanad.pdf
- https://cdn-cms.f-static.net/uploads/4393353/normal_60645250b926c.pdf
- https://watowerapomos.weebly.com/uploads/1/3/0/7/130775357/1912242.pdf
- https://zizetorusiwewiw.weebly.com/uploads/1/3/5/9/135990502/5895589.pdf
- https://cdn-cms.f-static.net/uploads/4375075/normal_60680e7e3f1ef.pdf
- https://fofonameg.weebly.com/uploads/1/3/4/5/134522304/b2a66a9a1a4805a.pdf
- https://uploads.strikinglycdn.com/files/6d6b1fbe-16a1-4fcb-9a46-916d86fdc739/printable_dominos_menu.pdf
- https://uploads.strikinglycdn.com/files/f9596ffd-954d-4f36-a635-73f4dd4991aa/412188144.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
Embedded domains
- botokaw.ru
- sawuvuvexefiz.weebly.com
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- zutekavewer.weebly.com
- static.s123-cdn-static.com
- rapusixub.weebly.com
- giwaxevo.weebly.com
- bunepefetupudir.weebly.com
- widawukilifuduz.weebly.com
- watowerapomos.weebly.com
- zizetorusiwewiw.weebly.com
- fofonameg.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report