MALICIOUS — 2240118.pdf
MALICIOUS — 2240118.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
3f169e514824b6b2c518f51ea4b5a41f7dc4d6c131b77704aab1a2850abadc61 - SHA-1:
51062f67c4e8048a1cd7001097091d474060871e - MD5:
1ce52717e4afefb7b961ec00b1cb45dc - ssdeep:
1536:7Y+zBgHmRoAHJ81JLmLNDAHXgONb7cymqjFT61cBBH2nPkLWMjn+eWWk8mb+OTNu:5zBRojYpDKdVIoFTSKIPkSA+omb+OM - TLSH:
T11638D0F3504BCD9CB9C65F93AE762459284AE78861339BA011CCFB9CC1B477D6D20A60 - Submitted as: 2240118.pdf
- File type: pdf · Size: 79967 bytes
- Verdict: malicious (94/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: https://static1.squarespace.com/static/5fcee6fafa8be4403e0934c7/t/5fd73afb0f11661d4c46d1e3/1607940859896/caravan_war_td_mod_apk.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://traffine.ru/wb?keyword=encyclopaedia%20of%20islam%20pdf, https://static1.squarespace.com/static/5fcee6fafa8be4403e0934c7/t/5fd73afb0f11661d4c46d1e3/1607940859896/caravan_war_td_mod_apk.pdf, https://bodupojuribun.weebly.com/uploads/1/3/4/7/134758420/puronejolik.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://traffine.ru/wb?keyword=encyclopaedia%20of%20islam%20pdf
- https://s3.amazonaws.com/vipinib/77294236028.pdf
- https://static1.squarespace.com/static/5fcee6fafa8be4403e0934c7/t/5fd73afb0f11661d4c46d1e3/1607940859896/caravan_war_td_mod_apk.pdf
- https://s3.amazonaws.com/wuwabobujasivor/punctuation_worksheets_for_class_8.pdf
- https://bodupojuribun.weebly.com/uploads/1/3/4/7/134758420/puronejolik.pdf
- https://s3.amazonaws.com/xefezesebusu/parkdean_cherry_tree_entertainment_guide.pdf
- https://uploads.strikinglycdn.com/files/39900fd3-c467-497a-ac2e-f9d1a9038cfb/zokizurewubokoguzi.pdf
- https://uploads.strikinglycdn.com/files/c898c4b1-488a-406d-8245-ff3e2ae46237/meaning_of_binomial_nomenclature.pdf
- https://tifimiwarefimi.weebly.com/uploads/1/3/4/8/134895051/kagoxuxesupafuv_bebekobividek_lelejodi_fogib.pdf
- https://s3.amazonaws.com/vatakefojunib/catit_flower_water_fountain_manual.pdf
- https://jatokogeredere.weebly.com/uploads/1/3/3/9/133997843/6392471.pdf
- https://s3.amazonaws.com/somamere/ruwutumozoxusogog.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- traffine.ru
- s3.amazonaws.com
- static1.squarespace.com
- bodupojuribun.weebly.com
- uploads.strikinglycdn.com
- tifimiwarefimi.weebly.com
- jatokogeredere.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report