MALICIOUS — 4091158.pdf
MALICIOUS — 4091158.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
587e83c55b1ba1faffe377d69c20242d8b0cff8b70cd44067219ed35d6fbd0b0 - SHA-1:
bbda3a806af90bd77a5931147badf6ec38151883 - MD5:
3a68800d2484c847dd72c44f763f65ef - ssdeep:
1536:9pKuGonC4iT7ub9drTubI7k50OYCy4tjvMgVPmxirHyuN/LaoEs8Xtg:LvCtuhd/uPCY22x/LaoiG - TLSH:
T1F436C0B3608BDD8C7296AB53A6E704683485D6897037CA5008CCB67CC8BC77DBF61951 - Submitted as: 4091158.pdf
- File type: pdf · Size: 68367 bytes
- Verdict: malicious (96/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: https://static.s123-cdn-static.com/uploads/4486965/normal_5fccd1b0b305b.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=measurements%20worksheets%20grade%206, https://static1.squarespace.com/static/5fc0dd9b8ef7301f8b108504/t/5fc221499b1ed0353824575c/1606558025618/sql_server_change_table_schema.pdf, https://static1.squarespace.com/static/5fc30d185bcb0228a2907835/t/5fc5f2329b1ed03538aae96a/1606808121406/xamixelofav.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=measurements%20worksheets%20grade%206
- https://static1.squarespace.com/static/5fc0dd9b8ef7301f8b108504/t/5fc221499b1ed0353824575c/1606558025618/sql_server_change_table_schema.pdf
- https://s3.amazonaws.com/medaliwifufugel/rugebe.pdf
- https://s3.amazonaws.com/subud/65394360703.pdf
- https://s3.amazonaws.com/bajapovogam/winerojifokepugozo.pdf
- https://static1.squarespace.com/static/5fc30d185bcb0228a2907835/t/5fc5f2329b1ed03538aae96a/1606808121406/xamixelofav.pdf
- https://static1.squarespace.com/static/5fc28b4ea13a450babfe95ac/t/5fc8820e90a4f8549d7adcd6/1606976015374/crossing_over_occurs_in_what_phase.pdf
- https://static1.squarespace.com/static/5fc00a03c6229360eca839ab/t/5fc115565147b148045a27c2/1606489439277/14454340388.pdf
- https://cdn-cms.f-static.net/uploads/4425230/normal_5fb9baa8cabba.pdf
- https://static1.squarespace.com/static/5fbce344be7cfc36344e8aaf/t/5fbdee803485235c868a3f55/1606282882416/buxuxufikopufimokovef.pdf
- https://static.s123-cdn-static.com/uploads/4486965/normal_5fccd1b0b305b.pdf
- https://titawijuneve.weebly.com/uploads/1/3/4/0/134012454/mulidezasite.pdf
- https://s3.amazonaws.com/sojaxub/gold_bars_blast_furnace_osrs_guide.pdf
- https://static1.squarespace.com/static/5fbce344be7cfc36344e8aaf/t/5fbe1aa53570fb44d1cba4c5/1606294181919/merrill_court_reporting.pdf
- https://cdn-cms.f-static.net/uploads/4413701/normal_5fc0c21a1d8e9.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- static1.squarespace.com
- s3.amazonaws.com
- cdn-cms.f-static.net
- static.s123-cdn-static.com
- titawijuneve.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report