MALICIOUS — 8535383.pdf
MALICIOUS — 8535383.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
2f507381213bb807b1fad72f59b0cdb3a803ac72c86d684576e744afe48ee97b - SHA-1:
918120fde8fb3768dee6cb6f7662c783424f08d3 - MD5:
ebee1bcb89673122dd99a4937272a260 - ssdeep:
1536:KdyGpq20QO2uMaQXHWbxvJ4RVddvr21kjb7p0niDIbvQrv3deLjvDy99Jf:ATw+XW1vQVdAWb7eniUrQr3Mjvm9X - TLSH:
T10636D0F31083DC8C7A969B27BEFA185CA1CEEE445536D25411C4BBADC4785BDBE108A0 - Submitted as: 8535383.pdf
- File type: pdf · Size: 66043 bytes
- Verdict: malicious (96/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: https://uploads.strikinglycdn.com/files/f30eadbe-c6af-4492-9242-73dc5222ff93/volvo_penta_5.0_gxi_manual.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://traffset.ru/wb?keyword=joker%20bgm%20ringtone%20download%20mp3%20masstamilan, https://bugupoxe.weebly.com/uploads/1/3/4/8/134850066/goxukemunuge_mixaredulun_votesij.pdf, https://uploads.strikinglycdn.com/files/a1d22ac3-4719-424d-b1f3-ba44c22a2f19/36566662417.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://traffset.ru/wb?keyword=joker%20bgm%20ringtone%20download%20mp3%20masstamilan
- https://s3.amazonaws.com/mubefula/baxusimekirililulagobuz.pdf
- https://bugupoxe.weebly.com/uploads/1/3/4/8/134850066/goxukemunuge_mixaredulun_votesij.pdf
- https://uploads.strikinglycdn.com/files/a1d22ac3-4719-424d-b1f3-ba44c22a2f19/36566662417.pdf
- https://uploads.strikinglycdn.com/files/17fa66a7-300b-4f35-9e6c-9881856e2620/gta_v_mobile_apk.pdf
- https://s3.amazonaws.com/zarelusipofox/worship_songs_lyrics.pdf
- https://cdn.sqhk.co/tuponapalab/RKbjrm9/spotlight_room_escape_hope_math.pdf
- https://uploads.strikinglycdn.com/files/6cad01c8-c090-4ba3-89f8-1b8cb6726b72/gutevo.pdf
- https://uploads.strikinglycdn.com/files/f30eadbe-c6af-4492-9242-73dc5222ff93/volvo_penta_5.0_gxi_manual.pdf
- https://cdn.sqhk.co/libibajuzumu/hfgjogd/kung_fu_fighting_song_remix.pdf
- https://fegilekupajot.weebly.com/uploads/1/3/4/4/134404616/846c4521a39.pdf
- https://xitofubipu.weebly.com/uploads/1/3/4/3/134375163/8161710.pdf
- https://cdn-cms.f-static.net/uploads/4366034/normal_5fbd8163503f8.pdf
- https://tazaliraku.weebly.com/uploads/1/3/4/8/134884946/rexujofugiwiw_fugexulom.pdf
- https://uploads.strikinglycdn.com/files/1436b12b-ee00-4f89-94fe-c46b3780e9da/cast_of_snl_2018.pdf
- https://uploads.strikinglycdn.com/files/9de0eb97-6afd-4657-9eb2-ad837f222d3d/hero_s_journey_in_the_odyssey.pdf
- https://uploads.strikinglycdn.com/files/3b3f6533-4fad-4428-bd16-6112885801e1/81057251470.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- traffset.ru
- s3.amazonaws.com
- bugupoxe.weebly.com
- uploads.strikinglycdn.com
- cdn.sqhk.co
- fegilekupajot.weebly.com
- xitofubipu.weebly.com
- cdn-cms.f-static.net
- tazaliraku.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report