MALICIOUS — 1862998.pdf
MALICIOUS — 1862998.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 5 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
62b2584dcb5fa638acdc86f7a454fde996e019de6cbc219864237503f81a5bd1 - SHA-1:
81da8b4d0f5e2d0a11aa502ebdb11bf47287fc9d - MD5:
8fb95be54037496a62d911cc169ef580 - ssdeep:
1536:q95gAlb7lzUKsUGHM/4DfX0+U/FFzL+kWzv/rLtT7kk+sUQh:6XlAnr0wktFBLZIvPtTJ+9O - TLSH:
T1FB38C0F32197CD0CBA4BA747AEBB3A1D15C9864C642686A4444C733DC4BC2AE7E50E51 - Submitted as: 1862998.pdf
- File type: pdf · Size: 78992 bytes
- Verdict: malicious (96/100)
Detections (5 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!8FB95BE54037
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: https://uploads.strikinglycdn.com/files/e671c709-b67d-4265-a833-0fe0f0bbbfa0/56861906272.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://jumiwimov.ru/wb?keyword=remington%20700%20308%20short%20action%20bolt%20assembly, https://uploads.strikinglycdn.com/files/e671c709-b67d-4265-a833-0fe0f0bbbfa0/56861906272.pdf, https://bevazemirif.weebly.com/uploads/1/3/4/8/134873662/pufomomawoxip_temitesinapa_gegobipifapedu_vudavexawo.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://jumiwimov.ru/wb?keyword=remington%20700%20308%20short%20action%20bolt%20assembly
- https://uploads.strikinglycdn.com/files/e671c709-b67d-4265-a833-0fe0f0bbbfa0/56861906272.pdf
- https://bevazemirif.weebly.com/uploads/1/3/4/8/134873662/pufomomawoxip_temitesinapa_gegobipifapedu_vudavexawo.pdf
- https://uploads.strikinglycdn.com/files/f77d37d9-ba35-4785-9144-45e082a3d79b/m-audio_fast_track_pro_manual_espanol.pdf
- https://uploads.strikinglycdn.com/files/25b7fb32-1c62-4eec-aca3-0234aa4b2512/hp_e93839_motherboard_drivers.pdf
- https://witufulovavivoj.weebly.com/uploads/1/3/4/3/134351467/getuxe-vedosanu-xabidukoxozerek-lituluwawe.pdf
- https://uploads.strikinglycdn.com/files/b358af44-fb61-43d6-b45f-d3ae8b686f69/stanley_wet_dry_vac_8_gallon_parts.pdf
- https://uploads.strikinglycdn.com/files/0b21f90e-b9f8-4c87-80a5-e2400023d3f2/30320786986.pdf
- https://uploads.strikinglycdn.com/files/b26d60ac-d972-4cd3-8592-87de4d1cdbaf/13439042901.pdf
- https://uploads.strikinglycdn.com/files/e4af1867-5d14-4889-b61c-ac3e30bfa914/equalizer_e2_weight_distribution_hitch_installation.pdf
- https://wemavejuza.weebly.com/uploads/1/3/4/6/134689468/dopotusos.pdf
- https://uploads.strikinglycdn.com/files/edb48741-77ad-48f5-b095-5a976cab02c9/27067058314.pdf
- https://uploads.strikinglycdn.com/files/4f33a5c7-3785-4854-9102-c43aa828bcad/dicionrio_de_rimas_rap.pdf
- https://reravojune.weebly.com/uploads/1/3/1/4/131406269/dofedijubimavokevoma.pdf
- https://uploads.strikinglycdn.com/files/e999b92d-876e-4c89-821e-22c8bcd2761e/zewofaz.pdf
- https://uploads.strikinglycdn.com/files/33f6ea4e-7c25-49bf-be7f-2d17176cccec/78934877154.pdf
- https://fubaxuzepavuzoz.weebly.com/uploads/1/3/4/7/134755559/9514c5090ad.pdf
- https://uploads.strikinglycdn.com/files/c0b96cb7-8ac9-41d6-9e4d-db660d87cdee/programa_de_honores_a_la_bandera_secundaria_inicio_de_ciclo_escolar.pdf
- https://bapanezuginu.weebly.com/uploads/1/3/5/3/135310050/9699547.pdf
- https://zunotebizi.weebly.com/uploads/1/3/4/6/134648513/zusivavu_negibosodasak_munug.pdf
- https://nijubalalo.weebly.com/uploads/1/3/1/4/131453980/7296124.pdf
- https://uploads.strikinglycdn.com/files/41fce916-dbb0-4d76-9f35-d90e2aa53c99/23304104233.pdf
- https://ditezuni.weebly.com/uploads/1/3/5/3/135350757/c03cd76b4b4679.pdf
- https://uploads.strikinglycdn.com/files/f312497f-e0a9-4a8a-bb7e-2218570b24e6/homeless_bird_summary_chapter_1.pdf
- https://uploads.strikinglycdn.com/files/11f12d2e-4926-40f1-8fb0-aa49be955805/volunteer_management_training_courses_uk.pdf
Embedded domains
- jumiwimov.ru
- uploads.strikinglycdn.com
- bevazemirif.weebly.com
- witufulovavivoj.weebly.com
- wemavejuza.weebly.com
- reravojune.weebly.com
- fubaxuzepavuzoz.weebly.com
- bapanezuginu.weebly.com
- zunotebizi.weebly.com
- nijubalalo.weebly.com
- ditezuni.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report