MALICIOUS — bodenu.pdf
MALICIOUS — bodenu.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
3e7b4964c40be6b3df54f9edb19808ce1789032c13dff32a738a9826a42719ec - SHA-1:
a3a7fb1c11bd520751215448329788330e13b6a7 - MD5:
d51f8d0dcc4082ba0bd6c1864b2ee59f - ssdeep:
1536:pPHacERMoJuLQDbfFBGzOoD9JAN7ERck9FH9efxK1U9BiXEwDW:9HLguLQHfFBGiHNcH9eMax3 - TLSH:
T1FF37E0F31063DE4C7A86DB23A96A155D748A9788B13A5A7104CC7A7DC5BC2FC3E10C82 - Submitted as: bodenu.pdf
- File type: pdf · Size: 72112 bytes
- Verdict: malicious (94/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: https://jaxemojemilela.weebly.com/uploads/1/3/4/6/134622921/goxejexoza-zivez-weduzumulofaxuf.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://traffine.ru/wb?keyword=motorola%20astro%20spectra%20programming%20software, https://jaxemojemilela.weebly.com/uploads/1/3/4/6/134622921/goxejexoza-zivez-weduzumulofaxuf.pdf, https://uploads.strikinglycdn.com/files/7f818974-db04-4475-847c-7231641ad400/77757148860.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://traffine.ru/wb?keyword=motorola%20astro%20spectra%20programming%20software
- https://jaxemojemilela.weebly.com/uploads/1/3/4/6/134622921/goxejexoza-zivez-weduzumulofaxuf.pdf
- https://uploads.strikinglycdn.com/files/7f818974-db04-4475-847c-7231641ad400/77757148860.pdf
- https://xexidizufom.weebly.com/uploads/1/3/4/5/134508107/vuxap.pdf
- https://uploads.strikinglycdn.com/files/06f521ae-14ee-44ca-891f-08bbffdac667/nikon_l110_coolpix.pdf
- https://demaromut.weebly.com/uploads/1/3/4/3/134358025/ec5027c9b8f59dd.pdf
- https://mavevataxivira.weebly.com/uploads/1/3/4/6/134600118/0cb8c7445be8e.pdf
- https://uploads.strikinglycdn.com/files/aaa094c7-fc19-4a19-9700-3d8af3d1d673/kinetic_molecular_theory_worksheet_middle_school.pdf
- https://static1.squarespace.com/static/5fc6a839be9b69395132fc47/t/5fd686ded654060362cd9417/1607894751067/format_of_writing_a_scientific_report.pdf
- https://static1.squarespace.com/static/5fc0d3b00b6b03258f353712/t/5fc58eecf3de5e49b523e2af/1606782701628/roscas_unc_tabela.pdf
- https://uploads.strikinglycdn.com/files/44c5c0d2-2458-47e2-9fa7-28e9c0f07954/boy_scout_motto_in_latin.pdf
- https://satobolusiv.weebly.com/uploads/1/3/1/3/131398412/9361455.pdf
- https://uploads.strikinglycdn.com/files/d1e997cf-dcf2-48df-b3fe-468ab2cdeea5/marc_faber_libro_encima_oro.pdf
- https://tokemenar.weebly.com/uploads/1/3/4/3/134337898/nisexizemulipov.pdf
- https://zalawevovupat.weebly.com/uploads/1/3/0/9/130969727/1128d1973.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- traffine.ru
- jaxemojemilela.weebly.com
- uploads.strikinglycdn.com
- xexidizufom.weebly.com
- demaromut.weebly.com
- mavevataxivira.weebly.com
- static1.squarespace.com
- satobolusiv.weebly.com
- tokemenar.weebly.com
- zalawevovupat.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report