MALICIOUS — 3f0e57_664f671b3780491087be67a2de1201c9.pdf
MALICIOUS — 3f0e57_664f671b3780491087be67a2de1201c9.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 5 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
426e0cf1ee36eff55073e9f43bff43e6472d894f323973be86ec878bebba78b2 - SHA-1:
2e20842200699cdbffcf3e75860c742239eed9e2 - MD5:
aedaec3cc59c513ffadab38526d9636b - ssdeep:
1536:MBZsC0t00EsIHZi0+FMHzk23Hssxkz6eq/pJDHBUsMpzbFixRA8iO1A1o8jBj:cmbEsI80+mTk23Hjxkz6X/pJbBmpzbIs - TLSH:
T17438E1F33097CFCC699B9F436AF7202AA458C74E606399A15058B97C887CAFD6E15C40 - Submitted as: 3f0e57_664f671b3780491087be67a2de1201c9.pdf
- File type: pdf · Size: 81608 bytes
- Verdict: malicious (94/100)
Detections (5 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!AEDAEC3CC59C
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: https://wavoxodasamemat.weebly.com/uploads/1/3/5/3/135348105/5b6198ccb4.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://jacksth.ru/wix?keyword=root+tablet+canaima+apk, http://choosenews.space/firebreather_cartoon_network_full_movie_downloadlz881.pdf, https://wavoxodasamemat.weebly.com/uploads/1/3/5/3/135348105/5b6198ccb4.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://jacksth.ru/wix?keyword=root+tablet+canaima+apk
- http://choosenews.space/firebreather_cartoon_network_full_movie_downloadlz881.pdf
- https://s3.amazonaws.com/jipowumat/robizej.pdf
- https://s3.amazonaws.com/datarofapakil/zisudilad.pdf
- https://wavoxodasamemat.weebly.com/uploads/1/3/5/3/135348105/5b6198ccb4.pdf
- http://bcpreactiva-enlinea.com/ccna_200_301_official_cert_guide_volume_2ujt1b.pdf
- https://nikojaba.weebly.com/uploads/1/3/4/6/134683319/wexovumulusep.pdf
- https://bigimenuxorotel.weebly.com/uploads/1/3/4/6/134655509/zukumumojurunu-guzugasa.pdf
- http://natlegend.space/15605216866ogxsa.pdf
- http://mazers.fun/wijosakijuzugubewogiri2f57m.pdf
- https://s3.amazonaws.com/rawesaragegugar/54573093948.pdf
- http://magnitoli-2ekran.site/21225805484ww8ii.pdf
- https://s3.amazonaws.com/xajowu/fapolirefirabelir.pdf
- https://s3.amazonaws.com/xugigabitulu/awareness_anthony_de_mello.pdf
- http://calipshatngaccs1.xyz/81110817283ck2xu.pdf
- https://s3.amazonaws.com/jotizifime/orthographe_d_anglais.pdf
- https://s3.amazonaws.com/vatosolikijike/denumagimozawagevav.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- jacksth.ru
- choosenews.space
- s3.amazonaws.com
- wavoxodasamemat.weebly.com
- bcpreactiva-enlinea.com
- nikojaba.weebly.com
- bigimenuxorotel.weebly.com
- natlegend.space
- mazers.fun
- magnitoli-2ekran.site
- calipshatngaccs1.xyz
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report