MALICIOUS — wovul.pdf
MALICIOUS — wovul.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
781d1fd79e8b6eb42ef65401b3d0dd6b589c56e6c8ddd6632c20d2e6606d6f27 - SHA-1:
3eb7534629c338ec18a43a7c3394f94a39c8ccfd - MD5:
316719af6953384d16d24b728db2447b - ssdeep:
1536:9Vx4SriqNPkAs0cX4Lgw4rkTgODHCBWIGNs6LPzROy3pkw:3iqZHs0cX4sGcEiBWIGW8NOq9 - TLSH:
T1AB37D1B7A0A7DD8C3A5E5B536DFA205C6088C2D89132DB6408C8F95CC9FC6BE3D60945 - Submitted as: wovul.pdf
- File type: pdf · Size: 70145 bytes
- Verdict: malicious (96/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: https://static.s123-cdn-static.com/uploads/4415304/normal_5fc8b60d1a8b5.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=maternity%20allowance%20form%202018, https://uploads.strikinglycdn.com/files/d99497af-40e7-40de-908a-1841a6112f5a/gekakodunepowibunufi.pdf, https://uploads.strikinglycdn.com/files/2f795abb-b08e-4f72-95d7-eb50a6939e9e/zagonetuguvifowisonefamu.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=maternity%20allowance%20form%202018
- https://uploads.strikinglycdn.com/files/d99497af-40e7-40de-908a-1841a6112f5a/gekakodunepowibunufi.pdf
- https://uploads.strikinglycdn.com/files/2f795abb-b08e-4f72-95d7-eb50a6939e9e/zagonetuguvifowisonefamu.pdf
- https://s3.amazonaws.com/pipaneku/ayyappa_ringtone_2018.pdf
- https://s3.amazonaws.com/gapivegek/zotediluralewi.pdf
- https://matoxidatu.weebly.com/uploads/1/3/4/6/134602194/b3d0bf.pdf
- https://cdn-cms.f-static.net/uploads/4490752/normal_5fafb7f66a16e.pdf
- https://s3.amazonaws.com/vezumobigodub/equivalence_class_partitioning_example.pdf
- https://cdn-cms.f-static.net/uploads/4425916/normal_5fb3478e1e857.pdf
- https://s3.amazonaws.com/loneminovu/organic_crib_sheets_with_name.pdf
- https://uploads.strikinglycdn.com/files/a87f33e2-57a8-4073-95a1-f87ac03ae1dc/76965259770.pdf
- https://cdn-cms.f-static.net/uploads/4418167/normal_5f9e7b8a838ba.pdf
- https://cdn-cms.f-static.net/uploads/4473419/normal_5fa60d1fd5eb6.pdf
- https://static.s123-cdn-static.com/uploads/4415304/normal_5fc8b60d1a8b5.pdf
- https://uploads.strikinglycdn.com/files/859faf60-7457-420e-97f2-b95d88e0ce5e/kedolurigaza.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- uploads.strikinglycdn.com
- s3.amazonaws.com
- matoxidatu.weebly.com
- cdn-cms.f-static.net
- static.s123-cdn-static.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report