MALICIOUS — 67989569927.pdf
MALICIOUS — 67989569927.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 5 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
4c02180d9cd16b3d005eaa104be82cf77df1806aa5b815cbad89ee6ad6f9d43c - SHA-1:
0117ac5d0c0ef733a67fb8c9779aadc301871eb0 - MD5:
c30c0b527b9387e60d15c2259a96d04c - ssdeep:
1536:9CNy2BpUB5ERu50y5Eur72ydiA9R8Vefugbn4gFTaKEP+6MBMf1i:A9pU4U5TqyMAPugbnJFE3Myk - TLSH:
T12438D0E7B1C7DD9CB6878B035DAF1969648AD3886031DB6050C8B97CC1BC7BE6E25900 - Submitted as: 67989569927.pdf
- File type: pdf · Size: 79437 bytes
- Verdict: malicious (96/100)
Detections (5 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!C30C0B527B93
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: https://static.s123-cdn-static.com/uploads/4450039/normal_5ffc3316f2d89.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://drafthe.ru/pbw?utm_term=call+of+duty+mobile+app+download+apk, https://lopuradusat.weebly.com/uploads/1/3/5/2/135297354/likitamatidijituwej.pdf, https://bazojarazete.weebly.com/uploads/1/3/4/6/134650598/gumabizakun_towam_papunodu.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://drafthe.ru/pbw?utm_term=call+of+duty+mobile+app+download+apk
- https://lopuradusat.weebly.com/uploads/1/3/5/2/135297354/likitamatidijituwej.pdf
- https://bazojarazete.weebly.com/uploads/1/3/4/6/134650598/gumabizakun_towam_papunodu.pdf
- https://static.s123-cdn-static.com/uploads/4450039/normal_5ffc3316f2d89.pdf
- http://wenuveraroto.pbworks.com/w/file/fetch/144529407/78153212033.pdf
- https://uploads.strikinglycdn.com/files/b7a8b2d7-775a-47f7-890a-a3962918b372/98174917082.pdf
- https://zutosexumapa.weebly.com/uploads/1/3/1/6/131606298/fikanodogutegepa.pdf
- https://fakavenudir.weebly.com/uploads/1/3/4/0/134042443/kewumonekat.pdf
- https://cdn-cms.f-static.net/uploads/4454807/normal_5fe8adefca29c.pdf
- https://fufuwotasivixi.weebly.com/uploads/1/3/5/9/135966690/jowamijabiwumubij.pdf
- https://cdn-cms.f-static.net/uploads/4421048/normal_602f589d3c24a.pdf
- https://telutifezidawu.weebly.com/uploads/1/3/4/6/134624569/271105.pdf
- https://neberesoz.weebly.com/uploads/1/3/4/5/134512227/582339.pdf
- https://gumevuwogixuxuj.weebly.com/uploads/1/3/5/3/135317748/xajuravonom_digavomijavav.pdf
- https://uploads.strikinglycdn.com/files/691e6628-b429-46a0-8161-c3c8fdf28f6c/32761295824.pdf
- https://static.s123-cdn-static.com/uploads/4408864/normal_6007fa5b3221a.pdf
- https://jivimukik.weebly.com/uploads/1/3/0/7/130775904/fuxoninavanofedex.pdf
- http://giresizuloki.pbworks.com/f/ribudikadadonob.pdf
- https://uploads.strikinglycdn.com/files/0a3cdf11-224c-43d8-bd36-f17a05090932/sanyo_tv_codes_for_bell_remote.pdf
- https://tefimapotile.weebly.com/uploads/1/3/4/3/134351392/deloragej_puvonixalem_fuxisa.pdf
- https://dolopexoje.weebly.com/uploads/1/3/1/8/131872138/6011730.pdf
- https://vujexuxifu.weebly.com/uploads/1/3/0/7/130739824/lenevususiliwedav.pdf
- https://cdn-cms.f-static.net/uploads/4453328/normal_606be1fd9bff0.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- drafthe.ru
- lopuradusat.weebly.com
- bazojarazete.weebly.com
- static.s123-cdn-static.com
- wenuveraroto.pbworks.com
- uploads.strikinglycdn.com
- zutosexumapa.weebly.com
- fakavenudir.weebly.com
- cdn-cms.f-static.net
- fufuwotasivixi.weebly.com
- telutifezidawu.weebly.com
- neberesoz.weebly.com
- gumevuwogixuxuj.weebly.com
- jivimukik.weebly.com
- giresizuloki.pbworks.com
- tefimapotile.weebly.com
- dolopexoje.weebly.com
- vujexuxifu.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report