MALICIOUS — c71772.pdf
MALICIOUS — c71772.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
36af8943cbc272219ad45ddddbd3a6093be569d1b8c3e87096a29dfa0733892f - SHA-1:
1745757fdf0ae6148080ff5e1074dd2447bfb608 - MD5:
a4bb43ae789280680da5bc89e1f6534c - ssdeep:
1536:o2qIoaTxedZWCgzZnjW5BTNM1MXpNoKRT/rtD2vvpjWfSSDChTiYH83zW1:oL1PECgzZ6yMHLTpaXcfS9hNHYw - TLSH:
T14736D1F3A1A7EE9CB5565B432DAA652C548FC3C855315F90008C3F7C887866DBE01EA1 - Submitted as: c71772.pdf
- File type: pdf · Size: 69185 bytes
- Verdict: malicious (94/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: https://rotutokobuzafoj.weebly.com/uploads/1/3/4/4/134455929/13971.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://traffset.ru/wb?keyword=download%20super%20tank%20rumble%20mod%20unlimited%20money, https://uploads.strikinglycdn.com/files/82818a03-84ff-4168-9076-5c0aed9f0814/geneva_sound_system.pdf, https://uploads.strikinglycdn.com/files/063972b1-ed9e-45fe-a24d-009f24c6a111/en_un_mundo_de_grises.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://traffset.ru/wb?keyword=download%20super%20tank%20rumble%20mod%20unlimited%20money
- https://uploads.strikinglycdn.com/files/82818a03-84ff-4168-9076-5c0aed9f0814/geneva_sound_system.pdf
- https://s3.amazonaws.com/forupokisip/89974869653.pdf
- https://uploads.strikinglycdn.com/files/063972b1-ed9e-45fe-a24d-009f24c6a111/en_un_mundo_de_grises.pdf
- https://lijipowurop.weebly.com/uploads/1/3/4/3/134314174/kabasekudagosemezama.pdf
- https://s3.amazonaws.com/jamuluvuvava/68572238879.pdf
- https://uploads.strikinglycdn.com/files/9e40e8ad-67c2-48a9-b141-41779056b33f/53309538086.pdf
- https://uploads.strikinglycdn.com/files/938e58ba-fb82-4f03-9d30-84584505cbc2/11478096540.pdf
- https://uploads.strikinglycdn.com/files/af49f611-1505-4ccd-bb3e-945ad11e4586/wendys_menu_calories.pdf
- https://s3.amazonaws.com/fusidejebi/dasolowudijakagagitizapo.pdf
- https://s3.amazonaws.com/tosasugokod/multiplying_polynomials_coloring_activity_worksheet_answer_key_aliens.pdf
- https://rotutokobuzafoj.weebly.com/uploads/1/3/4/4/134455929/13971.pdf
- https://s3.amazonaws.com/wexoteluwag/lijetewuwom.pdf
- https://s3.amazonaws.com/fewifuwu/middle_school_math_brain_teasers.pdf
- https://niruzezigup.weebly.com/uploads/1/3/4/8/134889773/812244.pdf
- https://nenimokevip.weebly.com/uploads/1/3/4/3/134336374/tosawawupajiwuxoxej.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- traffset.ru
- uploads.strikinglycdn.com
- s3.amazonaws.com
- lijipowurop.weebly.com
- rotutokobuzafoj.weebly.com
- niruzezigup.weebly.com
- nenimokevip.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report