MALICIOUS — 3220271.pdf
MALICIOUS — 3220271.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 5 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
730bdcaebcbd85125f9ee9cbdd302e541845a0d1e6a9df9496c075299de3498b - SHA-1:
2856bf4679ef59310406235c6efe8be46f02b838 - MD5:
8248ad45c04d784b8dd9faf61e8d7390 - ssdeep:
1536:nyX6rcUFPyhp+ihpiytUczQ4gmrn3TgtbIlYvmrs7XOQOmI522Ej:yKrcUFMp+Cltbz5DGoR4OQjI529 - TLSH:
T1FC38D0E361E7DCCCB68BAB436DB71079659AD3886032EBD0158C762CC5AC67D3D10950 - Submitted as: 3220271.pdf
- File type: pdf · Size: 81845 bytes
- Verdict: malicious (94/100)
Detections (5 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!8248AD45C04D
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: https://kavanezeso.weebly.com/uploads/1/3/4/4/134477356/kizipasog.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://vilenefex.ru/wb?keyword=how%20much%20salt%20water%20for%20master%20cleanse, https://kavanezeso.weebly.com/uploads/1/3/4/4/134477356/kizipasog.pdf, https://kodetinerimaguw.weebly.com/uploads/1/3/5/3/135347088/5343280.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://vilenefex.ru/wb?keyword=how%20much%20salt%20water%20for%20master%20cleanse
- https://kavanezeso.weebly.com/uploads/1/3/4/4/134477356/kizipasog.pdf
- https://kodetinerimaguw.weebly.com/uploads/1/3/5/3/135347088/5343280.pdf
- https://cdn-cms.f-static.net/uploads/4382639/normal_6058b34873289.pdf
- https://gunajotigur.weebly.com/uploads/1/3/4/7/134738866/wikexatixirobisix.pdf
- http://tonerinkstore.com/frost_mage_azerite_armor_guide58v6m.pdf
- http://varomevapaxobud.22web.org/5981646073.pdf
- https://cdn.sqhk.co/remowiwa/heijgjb/ghost_files_the_face_of_guilt_edycja_kolekcjonerska.pdf
- http://nabulegewuwal.myartsonline.com/gabalitexixufalozote.pdf
- https://nuresoxak.weebly.com/uploads/1/3/1/3/131380504/vinug_juzelomuwid_pamadukezunepab.pdf
- https://cdn.sqhk.co/mebereserab/hjribkP/uhaul_u_box_insurance.pdf
- http://bufukaw.iblogger.org/materials_science_and_engineering_callister_9th_edition_solution_manual.pdf
- https://losarofimet.weebly.com/uploads/1/3/1/3/131384333/mezigodutigo.pdf
- http://sefogozi.epizy.com/how_long_to_ignore_a_guy_to_get_his_attention.pdf
- https://cdn-cms.f-static.net/uploads/4375197/normal_6032ff12d4665.pdf
- http://doctora.club/85214205999wlgxk.pdf
- https://static.s123-cdn-static.com/uploads/4375075/normal_5ffda223ad362.pdf
- https://cdn-cms.f-static.net/uploads/4465707/normal_60561be0c6c5d.pdf
- http://instasale.company/micr_toner_for_hp_laserjet_pro_400_m401dneu419j.pdf
- https://cdn-cms.f-static.net/uploads/4426422/normal_6051e1729bb4e.pdf
- http://xejopegig.mypressonline.com/pematoxukomixit.pdf
- http://it50disconto.info/18492578571rqx69.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- vilenefex.ru
- kavanezeso.weebly.com
- kodetinerimaguw.weebly.com
- cdn-cms.f-static.net
- gunajotigur.weebly.com
- tonerinkstore.com
- varomevapaxobud.22web.org
- cdn.sqhk.co
- nabulegewuwal.myartsonline.com
- nuresoxak.weebly.com
- bufukaw.iblogger.org
- losarofimet.weebly.com
- sefogozi.epizy.com
- doctora.club
- static.s123-cdn-static.com
- xejopegig.mypressonline.com
- it50disconto.info
- www.w3.org
- purl.org
- ns.adobe.com
- instasale.company
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report