MALICIOUS — 3724239.pdf
MALICIOUS — 3724239.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
5958ad5fde809a4e9a94187e5da3f84b42594e5aeff97bff0bdcb41ad20bcd88 - SHA-1:
ca83c0f92467f6ffc521fa39d15579cbb1d1abe8 - MD5:
b33f896a56b001d9b8c5f7284cd8cafe - ssdeep:
1536:l7hTN9087OBkotOxPvlCwdvbZRAigyVNfEvgGVxIMh4vyyO:rJ77Bx5hbZRAv2f/Yxrp - TLSH:
T10637D0F36187DE8C3F969B0369BB242DB45AD64D303166A05489B77CC1FC26D7E60A20 - Submitted as: 3724239.pdf
- File type: pdf · Size: 70823 bytes
- Verdict: malicious (96/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): UDS:Trojan.PDF.SBadur.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: https://uploads.strikinglycdn.com/files/68998019-653d-4c74-af9e-a000f1140357/chez_nous_4th_edition.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=indiana%20dnr%20harvest%20report, https://uploads.strikinglycdn.com/files/58dcac64-241a-4368-b6fd-d801339da59b/gofuz.pdf, https://uploads.strikinglycdn.com/files/3d4a1423-faa8-4390-b3d2-9a6ee438336a/40681376212.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=indiana%20dnr%20harvest%20report
- https://uploads.strikinglycdn.com/files/58dcac64-241a-4368-b6fd-d801339da59b/gofuz.pdf
- https://uploads.strikinglycdn.com/files/3d4a1423-faa8-4390-b3d2-9a6ee438336a/40681376212.pdf
- https://cdn-cms.f-static.net/uploads/4476150/normal_5fb5f631459a8.pdf
- https://s3.amazonaws.com/pilazi/aashiqui_2_movie_songs_naasongs._com.pdf
- https://mimejomukokije.weebly.com/uploads/1/3/4/5/134510045/578665.pdf
- https://uploads.strikinglycdn.com/files/68998019-653d-4c74-af9e-a000f1140357/chez_nous_4th_edition.pdf
- https://uploads.strikinglycdn.com/files/e8a69d38-7623-41d3-8da7-46987c884dad/the_blanket_by_floyd_dell.pdf
- https://uploads.strikinglycdn.com/files/a448cb57-3e67-41b5-898b-4365ea6a5f83/8532307073.pdf
- https://uploads.strikinglycdn.com/files/ff57f653-e22d-4c7c-bc8d-0a77a2c28d03/darorefijurakabugir.pdf
- https://uploads.strikinglycdn.com/files/3b3a53ea-3b00-47b5-941a-5b4bcd2aea6e/50801609675.pdf
- https://uploads.strikinglycdn.com/files/b50af063-854c-4a08-9e13-bac43d15a131/pinawazufonabod.pdf
- https://uploads.strikinglycdn.com/files/b30bfecd-ad88-4ad6-8d6b-61aee9d10f31/adobe_master_collection_cs6_crack_reddit.pdf
- https://s3.amazonaws.com/tabobujimo/85750212964.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- s3.amazonaws.com
- mimejomukokije.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report