MALICIOUS — gamota-tonekewakubemof-gesaw-semopiduwiga.pdf
MALICIOUS — gamota-tonekewakubemof-gesaw-semopiduwiga.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 5 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
7f1e7024393a4344e6f85482065f628e5a236bd04d1a76f709a76242465ecf99 - SHA-1:
461ddfb185550f00b51013e5ac7a2f06c2a0d460 - MD5:
0c19684cd58a43ec784a4a1d588cf153 - ssdeep:
1536:qS4sJdjEtvOW1L9ziHRYXP776FU0VUsj7spGWB054G/xuMxrOIixjvf:14ztW29WxY/72aoZmxBK4GjxrOIix7 - TLSH:
T1F938E0F35097ED0CB95B9B03ADF618AC618FC7C46032EAA04084B76DD4687BD3CA0A54 - Submitted as: gamota-tonekewakubemof-gesaw-semopiduwiga.pdf
- File type: pdf · Size: 79563 bytes
- Verdict: malicious (94/100)
Detections (5 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!0C19684CD58A
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: https://dofixojibol.weebly.com/uploads/1/3/0/8/130874360/2860941.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://cdn-cms.f-static.net/uploads/4420034/normal_606bab3fced3e.pdf, https://uploads.strikinglycdn.com/files/ce7e1483-3b8a-41ad-b520-b4572dd9069d/que_son_las_sumas_y_restas_de_fracciones_heterogeneas.pdf, https://uploads.strikinglycdn.com/files/466234bc-12d7-40f3-9791-4e9957df390a/the_raven_movie_netflix.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://feedproxy.google.com/~r/wb/ENAH/~3/_7yJ53orglQ/wb?keyword=how%20to%20say%20oh%20my%20god%20in%20hebrew
- https://cdn-cms.f-static.net/uploads/4420034/normal_606bab3fced3e.pdf
- https://uploads.strikinglycdn.com/files/ce7e1483-3b8a-41ad-b520-b4572dd9069d/que_son_las_sumas_y_restas_de_fracciones_heterogeneas.pdf
- https://uploads.strikinglycdn.com/files/466234bc-12d7-40f3-9791-4e9957df390a/the_raven_movie_netflix.pdf
- https://uploads.strikinglycdn.com/files/30908dae-bd41-4809-b1a7-875ebc39eed1/5701004114.pdf
- https://uploads.strikinglycdn.com/files/3658e52e-fcf4-45de-95c7-c7b32ec4bc9f/honda_hrc216_parts_breakdown.pdf
- https://uploads.strikinglycdn.com/files/a60885ff-5520-49c2-b649-1a53634909df/delonghi_heater_ew7507eb_manual.pdf
- https://dofixojibol.weebly.com/uploads/1/3/0/8/130874360/2860941.pdf
- https://pobogovowot.weebly.com/uploads/1/3/5/3/135323888/5771464.pdf
- https://uploads.strikinglycdn.com/files/0e0b06ca-3778-4d52-9631-a1a29b7f543d/34985753749.pdf
- https://cdn-cms.f-static.net/uploads/4449974/normal_606c3dae4c0ef.pdf
- https://uploads.strikinglycdn.com/files/fa5cab37-6d17-447b-86af-fe971498fdd5/wutazewaz.pdf
- https://cdn-cms.f-static.net/uploads/4444374/normal_6069f9100143d.pdf
- https://static.s123-cdn-static.com/uploads/4464862/normal_5ffdc3e7a0124.pdf
- https://uploads.strikinglycdn.com/files/c63a248d-2883-4faf-95ce-5ee5338f8d1b/savare.pdf
- https://durewisopugus.weebly.com/uploads/1/3/4/3/134369166/3117809.pdf
- https://uploads.strikinglycdn.com/files/64c11c81-86b9-4f60-a2e3-32db4cba4c93/wabisojudonogajuluv.pdf
- https://static.s123-cdn-static.com/uploads/4501632/normal_5fff7b2a765a1.pdf
- https://wazumiwu.weebly.com/uploads/1/3/6/0/136038811/769191.pdf
- https://uploads.strikinglycdn.com/files/c88e9e12-c1ef-4d9e-b5a6-6fc1e91d7f3f/danby_ac_unit_12000_btu.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
Embedded domains
- feedproxy.google.com
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- dofixojibol.weebly.com
- pobogovowot.weebly.com
- static.s123-cdn-static.com
- durewisopugus.weebly.com
- wazumiwu.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report