MALICIOUS — 070799_0654fc2507e84e4e875c27e12dfbe60c.pdf
MALICIOUS — 070799_0654fc2507e84e4e875c27e12dfbe60c.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 5 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
096309c4a6d245f3379462c675daff324c67f6ee247d5fa31c360ff87229b5bc - SHA-1:
6658fab55e33d34b922e8ab36fa876362af2dc0b - MD5:
cbd4f160fe63f4d2181075ce6322ca24 - ssdeep:
1536:7jnYD5mlzBtzP8LnjMOxdq/mVG+e4s9DitMTHhb8/flVEck:3tZ3zP8sAdqOVM+tMTHhb8/fnC - TLSH:
T11F37E0B390A7DD4CAA86EF177D6728A97885E38C313297A01848361CC5B93FE7F54901 - Submitted as: 070799_0654fc2507e84e4e875c27e12dfbe60c.pdf
- File type: pdf · Size: 73854 bytes
- Verdict: malicious (96/100)
Detections (5 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!CBD4F160FE63
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: https://static.s123-cdn-static.com/uploads/4479223/normal_5fcc29af93c48.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://jottigo.ru/wix?keyword=notice+of+pending+action+release+form, https://gutoxokotuvil.weebly.com/uploads/1/3/1/3/131380594/nikijiboribu.pdf, http://xumasadepa.epizy.com/xigusazosojemasunamaxij.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://jottigo.ru/wix?keyword=notice+of+pending+action+release+form
- https://gutoxokotuvil.weebly.com/uploads/1/3/1/3/131380594/nikijiboribu.pdf
- http://xumasadepa.epizy.com/xigusazosojemasunamaxij.pdf
- https://s3.amazonaws.com/rimejiguvif/67050365583.pdf
- https://cdn.sqhk.co/wukufazujuv/cigILji/piano_teacher_online_course.pdf
- https://rezezeveg.weebly.com/uploads/1/3/1/8/131871466/zebigizopifubegadab.pdf
- https://s3.amazonaws.com/donake/magic_chef_wine_fridge_home_depot.pdf
- http://lepamiruketujuf.epizy.com/vidirun.pdf
- https://static.s123-cdn-static.com/uploads/4479223/normal_5fcc29af93c48.pdf
- https://s3.amazonaws.com/fejakixoweka/pdf_para_word_online_i_love.pdf
- http://sudolurimav.epizy.com/29798267051.pdf
- https://cdn-cms.f-static.net/uploads/4500187/normal_60217dd53ceac.pdf
- https://s3.amazonaws.com/polexebuj/nafibewijuduzolomudari.pdf
- http://pixudavevenute.rf.gd/wordpress_set_user_permissions.pdf
- http://tugojan.rf.gd/english_dictionary_free_offline.pdf
- https://cdn.sqhk.co/febenapox/iZbidXK/rilaxulefotapoxi.pdf
- https://s3.amazonaws.com/kabisebax/sexowexasopunatuluruvo.pdf
- https://cdn.sqhk.co/sasibasodiwu/hbXhhjf/70811013160.pdf
- https://cdn-cms.f-static.net/uploads/4386333/normal_5fe8548f4dfe3.pdf
- https://cdn-cms.f-static.net/uploads/4482629/normal_601cb1224899a.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
Embedded domains
- jottigo.ru
- gutoxokotuvil.weebly.com
- xumasadepa.epizy.com
- s3.amazonaws.com
- cdn.sqhk.co
- rezezeveg.weebly.com
- lepamiruketujuf.epizy.com
- static.s123-cdn-static.com
- sudolurimav.epizy.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
- pixudavevenute.rf.gd
- tugojan.rf.gd
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report