MALICIOUS — 237bc672.pdf
MALICIOUS — 237bc672.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
78f02eb592e265850765c570a58c70c38b118be078249ffd9d93d3c22e1444dc - SHA-1:
cd13be11920ffb3ff594285de2b2ab86b49d5d3d - MD5:
010106da583b1319dec17705a3ebfc75 - ssdeep:
1536:W0Z/yrDQpEsRQr0oRFw2RTm9MeBmb8KiR9ZwM9pw3bhps52wsPagZyflw:n6cpEsu5FrBm9HBmb3iRbwMbw3b3skPb - TLSH:
T13537CFF360DBDC8CFB45DB03A8A6119C66CAC6887062CEA02458B67CC5B85FE1E54D25 - Submitted as: 237bc672.pdf
- File type: pdf · Size: 74033 bytes
- Verdict: malicious (96/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: https://mufedagejex.weebly.com/uploads/1/3/4/7/134726032/duxujapif_jumepolifi_luzilarumezo_zomiduxevow.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=photo%20apps%20%202018%20jio%20phone, https://uploads.strikinglycdn.com/files/79a09ca3-a37c-4a4e-86ab-f280919729f4/contratos_para_eventos.pdf, https://uploads.strikinglycdn.com/files/7d5d53c0-7ff3-4018-894b-ac0aa67283cf/94421088310.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=photo%20apps%20%202018%20jio%20phone
- https://s3.amazonaws.com/tutapaxi/pest_risk_analysis.pdf
- https://uploads.strikinglycdn.com/files/79a09ca3-a37c-4a4e-86ab-f280919729f4/contratos_para_eventos.pdf
- https://uploads.strikinglycdn.com/files/7d5d53c0-7ff3-4018-894b-ac0aa67283cf/94421088310.pdf
- https://s3.amazonaws.com/wotodedaruzuk/50568793643.pdf
- https://koxoganonigowup.weebly.com/uploads/1/3/1/4/131408343/1f06f9fbaabc966.pdf
- https://gutamunimidujad.weebly.com/uploads/1/3/4/6/134667749/bunerob.pdf
- https://uploads.strikinglycdn.com/files/cb11cd8f-9a65-4ff9-8e50-7cd28178c8b4/juruwu.pdf
- https://s3.amazonaws.com/sedimeraxufi/50430078688.pdf
- https://uploads.strikinglycdn.com/files/6744e1d5-037f-40c7-8efb-227bc6345cee/card_stacking_definition_literature.pdf
- https://s3.amazonaws.com/lunojol/1741002467.pdf
- https://uploads.strikinglycdn.com/files/8cbc8a30-2bc3-4e6b-8d84-24921fe6b2b8/oracion_a_la_sangre_de_cristo_por_mi_hijos.pdf
- https://mufedagejex.weebly.com/uploads/1/3/4/7/134726032/duxujapif_jumepolifi_luzilarumezo_zomiduxevow.pdf
- https://febawamowezifu.weebly.com/uploads/1/3/4/5/134594075/4027376.pdf
- https://kobizixudowizeb.weebly.com/uploads/1/3/4/4/134402546/8093065.pdf
- https://uploads.strikinglycdn.com/files/eac0442d-aac8-43bb-9432-2b2a0fdb33c0/honeywell_thermostat_user_manual.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- s3.amazonaws.com
- uploads.strikinglycdn.com
- koxoganonigowup.weebly.com
- gutamunimidujad.weebly.com
- mufedagejex.weebly.com
- febawamowezifu.weebly.com
- kobizixudowizeb.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report