MALICIOUS — fa6e288aa50fcb6.pdf
MALICIOUS — fa6e288aa50fcb6.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 5 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
1339624718d56fddc86f9e1b35764e347c862663ddc0ce5d66545c73dd222157 - SHA-1:
ac36ab922207de4f3df1c07ed7704d8a8110fe8e - MD5:
7f4c7d045db4f645b6390e4468f35840 - ssdeep:
1536:SeCPBjJXHXRI4648z9YNE/YtN00ThY2wooUz2AOhoI98GXL1Hx4FmgQyoAX:nYdBIfJYNFLlY2wiS7oI98GXLjTyD - TLSH:
T17138E0F3509BDE8D7B8E1B433B6614296A66D389B833E7705480B62CD86C5EE3D10902 - Submitted as: fa6e288aa50fcb6.pdf
- File type: pdf · Size: 80105 bytes
- Verdict: malicious (94/100)
Detections (5 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!7F4C7D045DB4
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: http://helps-lnstagramcopyrights-about.com/71103761844do667.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://traffine.ru/wb?keyword=feudal%20system%20definition%20japan, https://cdn.sqhk.co/metexemoraga/YggdXJy/zombix_online_mod_apk_latest_version.pdf, https://cdn.sqhk.co/vibisidumes/QjjhcCv/83309532592.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://traffine.ru/wb?keyword=feudal%20system%20definition%20japan
- https://cdn.sqhk.co/metexemoraga/YggdXJy/zombix_online_mod_apk_latest_version.pdf
- https://cdn.sqhk.co/vibisidumes/QjjhcCv/83309532592.pdf
- http://helps-lnstagramcopyrights-about.com/71103761844do667.pdf
- http://wuwatomugexove.epizy.com/begana_song_raashi_sood_video.pdf
- http://cesaregaspari.com/84841432215glssj.pdf
- http://jonegukum.epizy.com/materials_requisition_slip_template.pdf
- http://pevetune.66ghz.com/minecraft_crafting_guide_book.pdf
- http://erethiztzj.space/62982537319vi487.pdf
- https://cdn.sqhk.co/ralapogifur/ietU4yx/vat_calculator_italy.pdf
- https://cdn.sqhk.co/pijuvedozuw/dlhjjgh/59516480910.pdf
- http://wirizobesopo.epizy.com/string._format_double_quotes.pdf
- http://jipinasin.epizy.com/85487162604.pdf
- http://lekinip.epizy.com/tidobezujifodaribijoke.pdf
- https://cdn.sqhk.co/nutakurij/IhaF9zM/heroines_fantasy_wiki.pdf
- https://cdn.sqhk.co/polidupokasu/jlhgZjh/clash_of_clans_best_war_army_th7.pdf
- http://puligop.epizy.com/vuxirenukikenezatig.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- traffine.ru
- cdn.sqhk.co
- helps-lnstagramcopyrights-about.com
- wuwatomugexove.epizy.com
- cesaregaspari.com
- jonegukum.epizy.com
- pevetune.66ghz.com
- erethiztzj.space
- wirizobesopo.epizy.com
- jipinasin.epizy.com
- lekinip.epizy.com
- puligop.epizy.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report