MALICIOUS — feponox.pdf
MALICIOUS — feponox.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
16cf0153bd63905fb92e3d568a09f1daf89289ae64386aa7db4a8a2bf92144b9 - SHA-1:
547fa8e5fa49ef87377af30fecb58057dce9837a - MD5:
f43a4ede12be00d9e35c3eca511d84e6 - ssdeep:
1536:kFfg8cM8WhB7oZYx+nn2kuSTGB9gMdcTDqoDH8efNDbimXBc9Q:cBcM8WhRloxuSTGEqoDHddbiwh - TLSH:
T12837C0F3A55BDD8C3E875B036EF931283089D3487422DAA454C8F72C94B86BE7E11A51 - Submitted as: feponox.pdf
- File type: pdf · Size: 70790 bytes
- Verdict: malicious (94/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: https://static1.squarespace.com/static/5fc2ca3a3dfdd95b60e15de0/t/5fc62b4beaf37e3b646e81f0/1606822731573/mancala_online_cool_math_games.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://ggtraff.ru/wb?keyword=big%20fish%20audio%20vintage%20horns%20kontakt, https://uploads.strikinglycdn.com/files/d1b20007-f42b-4a0c-9e1e-7e6fd74a3ca6/pitakafef.pdf, https://uploads.strikinglycdn.com/files/6be189f6-8872-4b59-b8a6-087d9f53f647/89953122854.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/wb?keyword=big%20fish%20audio%20vintage%20horns%20kontakt
- https://s3.amazonaws.com/kisimujuk/franchise_basketball_2020_apk_mod.pdf
- https://uploads.strikinglycdn.com/files/d1b20007-f42b-4a0c-9e1e-7e6fd74a3ca6/pitakafef.pdf
- https://uploads.strikinglycdn.com/files/6be189f6-8872-4b59-b8a6-087d9f53f647/89953122854.pdf
- https://static1.squarespace.com/static/5fc2ca3a3dfdd95b60e15de0/t/5fc62b4beaf37e3b646e81f0/1606822731573/mancala_online_cool_math_games.pdf
- https://static1.squarespace.com/static/5fc78e0da4492a057e242502/t/5fcdb2c3c836a917f92b4178/1607316164565/mojitusom.pdf
- https://static1.squarespace.com/static/5fc15df1e9fc3622d5255c20/t/5fcb0560190ee82df8d587dc/1607140704730/94216927231.pdf
- https://s3.amazonaws.com/metubevozisul/56816080347.pdf
- https://s3.amazonaws.com/rejiner/52236724605.pdf
- https://static1.squarespace.com/static/5fc777f5a3ccef3526eb9256/t/5fd7416596ed101a3e5c1717/1607942502645/grievance_letter_template_australia.pdf
- https://uploads.strikinglycdn.com/files/ee3130a7-d42a-4334-b4c6-d85aee589354/persona_5_melchizedek_build.pdf
- https://uploads.strikinglycdn.com/files/9ecc6a9d-f8c2-4d83-a9c8-e62ae45d0c85/camtasia_key_code.pdf
- https://static1.squarespace.com/static/5fbce344be7cfc36344e8aaf/t/5fbd03f68cb11b25c09ceb64/1606222839382/rovaxiwel.pdf
- https://uploads.strikinglycdn.com/files/3cefd263-3cf8-4c3f-b2e9-02c3faaafcde/el_oro_de_los_dioses.pdf
- https://static1.squarespace.com/static/5fc19923a3bf4b14abae1a5b/t/5fc680ac08845d09246c6e57/1606844590066/51523253310.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- s3.amazonaws.com
- uploads.strikinglycdn.com
- static1.squarespace.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report