MALICIOUS — 71028530602db5965040a23a9893e18686720ffa34f513cf818a07cbb8fe2c5a
MALICIOUS — 71028530602db5965040a23a9893e18686720ffa34f513cf818a07cbb8fe2c5a is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 5 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
71028530602db5965040a23a9893e18686720ffa34f513cf818a07cbb8fe2c5a - SHA-1:
c8527653bd5d74345c5e7639b548871f5dbcd96c - MD5:
b31c8dece73d9a889514373c0f6765f1 - ssdeep:
1536:jPkmGzbxPv1Gqm21V+/U1F0o58KebbYhga1Qvm5pi3pA66VT2XNNM:L0zb1a2bznu5Ae4QvSi3Fo2XY - TLSH:
T15538CFF35093CE4CBA4F2F07AAB755A9108ED3C861268BA1448CFB6DD5BC5AD3D20550 - Submitted as: 71028530602db5965040a23a9893e18686720ffa34f513cf818a07cbb8fe2c5a
- File type: pdf · Size: 77185 bytes
- Verdict: malicious (96/100)
Detections (5 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!B31C8DECE73D
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: https://static.s123-cdn-static.com/uploads/4482399/normal_5fff35f5c8b12.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://ketchas.ru/pbw?utm_term=biggest+80s+hits, https://cdn-cms.f-static.net/uploads/4459324/normal_5fd74331ab588.pdf, https://cdn-cms.f-static.net/uploads/4367287/normal_603ce4ba5c332.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded URLs
- https://ketchas.ru/pbw?utm_term=biggest+80s+hits
- https://cdn-cms.f-static.net/uploads/4459324/normal_5fd74331ab588.pdf
- https://cdn-cms.f-static.net/uploads/4367287/normal_603ce4ba5c332.pdf
- https://cdn-cms.f-static.net/uploads/4392210/normal_602ce8314f321.pdf
- https://uploads.strikinglycdn.com/files/308c931c-fbab-4aed-a6d2-3720707f3c40/15929876417.pdf
- https://uploads.strikinglycdn.com/files/39d69a80-7142-4703-928e-a9f16729ac26/how_much_is_a_2007_audi_worth.pdf
- https://uploads.strikinglycdn.com/files/763fa418-e17c-482f-a37d-f5088baa5538/gosaresewiregov.pdf
- https://cdn-cms.f-static.net/uploads/4450898/normal_603f150d4b8f4.pdf
- https://bozaveruri.weebly.com/uploads/1/3/1/4/131483492/4633196.pdf
- https://static.s123-cdn-static.com/uploads/4482399/normal_5fff35f5c8b12.pdf
- https://uploads.strikinglycdn.com/files/5c12ab0f-468f-4aae-a423-890b4799b54d/21414361806.pdf
- https://uploads.strikinglycdn.com/files/2cf5aa8a-3925-42b4-89ae-0eb15c4166bf/the_secret_to_money_by_rhonda_byrne_apk.pdf
- https://cdn-cms.f-static.net/uploads/4484375/normal_60bbae2c0f31d.pdf
- https://cdn-cms.f-static.net/uploads/4424682/normal_604d6fadab98f.pdf
- https://watinamubil.weebly.com/uploads/1/3/0/8/130813586/nezikazunuxuruzof.pdf
- https://uploads.strikinglycdn.com/files/6f13006f-2069-403d-a2de-3f2f46271ec6/max_lucado_daily_devotional_bible.pdf
- https://uploads.strikinglycdn.com/files/cb1e3386-4998-4a01-8493-a9db82b3bb19/pujupilovosubozivoxamod.pdf
- https://uploads.strikinglycdn.com/files/1b65f0dc-6c22-47e5-a835-f70dcb140233/how_to_change_your_name_on_nys_drivers_license.pdf
- https://uploads.strikinglycdn.com/files/800914ee-44e3-45b2-8589-c48ea679b8bb/warm_bodies_streaming.pdf
- https://uploads.strikinglycdn.com/files/e356490a-4cab-4b57-9a4f-bdb679a071eb/mifoxulinal.pdf
- https://tuzakalo.weebly.com/uploads/1/3/4/4/134492431/cf8d4372e9.pdf
- https://uploads.strikinglycdn.com/files/bac0041b-2706-4519-8044-7e400cfa1a54/vukorifebesokolomutul.pdf
- https://vigenawora.weebly.com/uploads/1/3/4/4/134495248/5de05c5.pdf
- https://uploads.strikinglycdn.com/files/d435053b-fb2c-4351-857a-12745bc0cdfc/xesibazexawusulesamo.pdf
- https://cdn-cms.f-static.net/uploads/4459787/normal_605204dc20392.pdf
Embedded domains
- ketchas.ru
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- bozaveruri.weebly.com
- static.s123-cdn-static.com
- watinamubil.weebly.com
- tuzakalo.weebly.com
- vigenawora.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report