MALICIOUS — 50397568607.pdf
MALICIOUS — 50397568607.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
0c5b2ece14eabd8cf79cb87487051162aa9e0b113b8857069f5b88c6c48c8e52 - SHA-1:
c9dadb369a56d53056270fce7b24478216f3652e - MD5:
7730e4e9d2307870ace9d883c0c173ab - ssdeep:
1536:y+9mbKKFfvMMJRwCB4NAriMy8z6lhMx2L21AO5Qe2B4JcanEaKJ:h9mLFXMARwC8A08MtL2uOaB4JcaEag - TLSH:
T1C336D0F3610BED9C75939F03BF96151D288686492232D7B100C87B2CE5BC2BE7E61942 - Submitted as: 50397568607.pdf
- File type: pdf · Size: 68974 bytes
- Verdict: malicious (96/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: https://uploads.strikinglycdn.com/files/c1470ad3-1eca-4d12-9b1c-c5912e4de344/37123929893.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://cctraff.ru/strik?utm_term=texas+affidavit+for+bank+account, https://cdn-cms.f-static.net/uploads/4485016/normal_5fd6310f164fe.pdf, https://jedapozopimu.weebly.com/uploads/1/3/4/6/134614290/siwaga_zuponeg.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/strik?utm_term=texas+affidavit+for+bank+account
- https://cdn-cms.f-static.net/uploads/4485016/normal_5fd6310f164fe.pdf
- https://jedapozopimu.weebly.com/uploads/1/3/4/6/134614290/siwaga_zuponeg.pdf
- https://uploads.strikinglycdn.com/files/c1470ad3-1eca-4d12-9b1c-c5912e4de344/37123929893.pdf
- https://pivamaxisogen.weebly.com/uploads/1/3/4/4/134481881/be38ca3250.pdf
- https://uploads.strikinglycdn.com/files/a6c530ed-1931-4183-af51-811a7a4f7f3a/nefixifefekukago.pdf
- https://dosaremuxabibi.weebly.com/uploads/1/3/0/7/130739916/tidomixagekun-xinitepoje-binijig.pdf
- https://uploads.strikinglycdn.com/files/ebf31924-c1e6-4b44-b2c4-697ae36e3ed7/wolajisevokamojoluruwi.pdf
- https://uploads.strikinglycdn.com/files/797546ed-9686-4dc2-8c16-0e141dfff356/kidelipibosadeli.pdf
- https://kiligazifozu.weebly.com/uploads/1/3/4/5/134506598/tewedoluzosati-muwevufigolisa-letut-fomape.pdf
- https://uploads.strikinglycdn.com/files/b670e513-5efa-420b-9119-c5a9e5b5ad74/bible_tales_dick_gregory.pdf
- https://xalorato.weebly.com/uploads/1/3/4/3/134317389/gawitege-kusivetatew-fubozuzu.pdf
- https://cdn-cms.f-static.net/uploads/4427284/normal_5fae34dc61063.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- cdn-cms.f-static.net
- jedapozopimu.weebly.com
- uploads.strikinglycdn.com
- pivamaxisogen.weebly.com
- dosaremuxabibi.weebly.com
- kiligazifozu.weebly.com
- xalorato.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report