MALICIOUS — 9165d9.pdf
MALICIOUS — 9165d9.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
3a75d81fafc79add17facb2af203ef51a67d4bfff0f8145c83fe940e23a1d74d - SHA-1:
94a961fdf2dd12ab35541a86cf7036a0c7224678 - MD5:
0a5d58b86a8d8555d134de9352b2d8de - ssdeep:
1536:RoEa6ul8q/F3l4SNhwYG+pwKhDVjP+AYzfPE3nhhXe3D0:1a6it+UHG+p//kfs3XG0 - TLSH:
T11A36DFF3A057ED8CBA966B07ADF7141C218AD3CC6136AB7098D8775DC47C26DAE10A00 - Submitted as: 9165d9.pdf
- File type: pdf · Size: 64049 bytes
- Verdict: malicious (94/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: https://static1.squarespace.com/static/5fbce344be7cfc36344e8aaf/t/5fbe6b9018e72e5fdba8a52e/1606314896979/wexolafajupet.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://traffking.ru/wb?keyword=realidades%202%20capitulo%201b%20page%2022%20answers, https://uploads.strikinglycdn.com/files/7fdd8ee7-b783-4f73-8812-6ea3eb19d93e/38674588120.pdf, https://static1.squarespace.com/static/5fbce344be7cfc36344e8aaf/t/5fbe6b9018e72e5fdba8a52e/1606314896979/wexolafajupet.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://traffking.ru/wb?keyword=realidades%202%20capitulo%201b%20page%2022%20answers
- https://uploads.strikinglycdn.com/files/7fdd8ee7-b783-4f73-8812-6ea3eb19d93e/38674588120.pdf
- https://s3.amazonaws.com/dukajevo/my_cafe_recipes_and_stories_hack.pdf
- https://static1.squarespace.com/static/5fbce344be7cfc36344e8aaf/t/5fbe6b9018e72e5fdba8a52e/1606314896979/wexolafajupet.pdf
- https://s3.amazonaws.com/bunobu/66463574376.pdf
- https://static1.squarespace.com/static/5fc1b82e11f6a419848b6c75/t/5fc40531a97599144e753c8b/1606681905638/frank_gambale_chop_builder_review.pdf
- https://static1.squarespace.com/static/5fc11b4016f6d44b07c000b4/t/5fc6af983c6ccf69f34c3d66/1606856600611/sing_karaoke_bar_and_lounge.pdf
- https://uploads.strikinglycdn.com/files/4976ead9-e4ee-4871-9d2d-21a589c003ce/motorbike_games_online_unblocked.pdf
- https://uploads.strikinglycdn.com/files/adc65def-2a8e-43c2-86ed-b709141dfad1/gadukowovesexexov.pdf
- https://uploads.strikinglycdn.com/files/7e5ab965-97bd-4784-bdf0-e70519734837/kitty_cake_slime_box.pdf
- https://uploads.strikinglycdn.com/files/71976525-1bdc-4a57-a7f8-a2732e5bad37/wijapifipidefuji.pdf
- https://static1.squarespace.com/static/5fc65200ea4a794d566a2ee3/t/5fc9f5e2be6684539dee8929/1607071207744/gukanunawebujigetotula.pdf
- https://s3.amazonaws.com/vuxalirudidel/download_all_formulas_of_class_12_maths.pdf
- https://static1.squarespace.com/static/5fc1425117e7202640ec9856/t/5fc7ee540581dd30a08d06e6/1606938196761/94494742783.pdf
- https://s3.amazonaws.com/ratixifo/aluminum_design_manual_2005_free.pdf
- https://uploads.strikinglycdn.com/files/6563ad37-e529-4e84-8837-0d1abbe09df5/20735496249.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- traffking.ru
- uploads.strikinglycdn.com
- s3.amazonaws.com
- static1.squarespace.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report