MALICIOUS — 8619885853.pdf
MALICIOUS — 8619885853.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
4aeae4fc0ae544b5bb00a48a6cb1dafd885a1f166bf05e662776ea68e669e04d - SHA-1:
6b9de2f98436e2981fee37b3c82e4248d93d3719 - MD5:
c03437081aa202c9f9dfce3e9b17f7af - ssdeep:
1536:btRcyWja0wYmAmqs8xHr2E2/OdZzDQ1UMJH4SUpbVHBW53RfdJ7D:cyWja0wYmAA8N2ESODYxJHaTHGNdh - TLSH:
T1DD37DFF3218BDC4CBB889B8365E71458B0EAE3882536DB5444C8B57EC4786BD7F20A40 - Submitted as: 8619885853.pdf
- File type: pdf · Size: 76251 bytes
- Verdict: malicious (96/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: https://uploads.strikinglycdn.com/files/bc5dae46-3804-468d-b0b9-26f031d7a378/dn_dernek_tek_link_indir.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://trafficel.ru/strik?utm_term=%25D0%25BA%25D0%25B0%25D1%2588%25D0%25B5%25D0%25BC%25D0%25B8%25D1%2580+slim+fit, https://uploads.strikinglycdn.com/files/1f253ec7-2388-4846-90fa-2bb43aa83180/lagotewudox.pdf, https://uploads.strikinglycdn.com/files/a48ea795-a17d-4c90-a635-00b526278d86/gapogatimevudaroloteda.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://trafficel.ru/strik?utm_term=%25D0%25BA%25D0%25B0%25D1%2588%25D0%25B5%25D0%25BC%25D0%25B8%25D1%2580+slim+fit
- https://uploads.strikinglycdn.com/files/1f253ec7-2388-4846-90fa-2bb43aa83180/lagotewudox.pdf
- https://uploads.strikinglycdn.com/files/a48ea795-a17d-4c90-a635-00b526278d86/gapogatimevudaroloteda.pdf
- https://uploads.strikinglycdn.com/files/f9b7a82b-79ff-4865-b36e-8bfde2f7bc5a/ruvuvapakal.pdf
- https://s3.amazonaws.com/jebupofedijakuk/52131239650.pdf
- https://s3.amazonaws.com/fajixe/vigefamuv.pdf
- https://uploads.strikinglycdn.com/files/0d0681ef-de5c-406b-a3c1-84150fae4509/japewupiteruz.pdf
- https://s3.amazonaws.com/vogubivajavofu/cassava_production_in_the_philippines.pdf
- https://cdn-cms.f-static.net/uploads/4416136/normal_5f96994a7d8bb.pdf
- https://s3.amazonaws.com/sezebepit/thomasville_bedroom_furniture_replacement_hardware.pdf
- https://uploads.strikinglycdn.com/files/269a183f-d918-46a7-b021-01225b173f13/mumuxafijunirebudev.pdf
- https://uploads.strikinglycdn.com/files/bc5dae46-3804-468d-b0b9-26f031d7a378/dn_dernek_tek_link_indir.pdf
- https://s3.amazonaws.com/zetare/sat_probability_questions.pdf
- https://s3.amazonaws.com/fasotajedag/lopefazedolofavev.pdf
- https://cdn-cms.f-static.net/uploads/4414495/normal_5fab92135f89c.pdf
- https://cdn-cms.f-static.net/uploads/4410018/normal_5f990856e48b5.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- trafficel.ru
- uploads.strikinglycdn.com
- s3.amazonaws.com
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report