MALICIOUS — 614013.pdf
MALICIOUS — 614013.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (97/100). 4 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
8ce71c89a7245cbed01d33b8e68a54d6a5e987a59a069545a75c9b4cad33cb64 - SHA-1:
2319523c4649dbb3b5cd6e657e9fc0a45de54eb5 - MD5:
c8855e9b53f0694df84340df77bc1691 - ssdeep:
1536:JV+T9AUMlXnQP34SZVy4nkb1P14J53iVEjJjYTT95ASCE5USEBrDpHcT:GWlXnG4Onkx04EtKTL6EOSArK - TLSH:
T1EE36D0F32297DCCCBACA5747BDB51198668AC2883132A7944088FA3CC5B85BE7F50D10 - Submitted as: 614013.pdf
- File type: pdf · Size: 66287 bytes
- Verdict: malicious (97/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 97/100 is the fusion of 6 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - Embedded link rated suspicious by URL analysis: https://papunagaku.weebly.com/uploads/1/3/1/3/131384156/masiponufoxiv_fukuw_tanibipolif_rotoxego.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=vsepr%20practice%20problems%20worksheet%20answers, https://cdn-cms.f-static.net/uploads/4462046/normal_5fa232a3c019c.pdf, https://papunagaku.weebly.com/uploads/1/3/1/3/131384156/masiponufoxiv_fukuw_tanibipolif_rotoxego.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=vsepr%20practice%20problems%20worksheet%20answers
- https://cdn-cms.f-static.net/uploads/4462046/normal_5fa232a3c019c.pdf
- https://papunagaku.weebly.com/uploads/1/3/1/3/131384156/masiponufoxiv_fukuw_tanibipolif_rotoxego.pdf
- https://xexegetogud.weebly.com/uploads/1/3/4/3/134375989/zivadi.pdf
- https://cdn-cms.f-static.net/uploads/4416301/normal_5f9f1912c1e09.pdf
- https://bufazori.weebly.com/uploads/1/3/4/3/134377245/xagosezegarofopirek.pdf
- https://kafowudozajem.weebly.com/uploads/1/3/4/6/134613952/nagarabipegavavux.pdf
- https://xerekabixedil.weebly.com/uploads/1/3/4/6/134684256/4042615.pdf
- https://zoforute.weebly.com/uploads/1/3/4/3/134352948/xuzajejulugum-gogamaxu-busala-xowuxidaxigiw.pdf
- https://rimofunoduw.weebly.com/uploads/1/3/4/5/134525219/818009.pdf
- https://cdn-cms.f-static.net/uploads/4366347/normal_5f87a2f8cdc12.pdf
- https://cdn-cms.f-static.net/uploads/4389820/normal_5f90fa1a58d50.pdf
- https://uploads.strikinglycdn.com/files/518cb9a8-921d-4f0f-8f03-78447d754988/maruzojolawiw.pdf
- https://zoxuzuxebexot.weebly.com/uploads/1/3/0/9/130969059/metor.pdf
- https://cdn-cms.f-static.net/uploads/4369653/normal_5f8a9486b9759.pdf
- https://zelapagetuwuj.weebly.com/uploads/1/3/1/4/131406140/sajemewuwodojafa.pdf
- https://cdn-cms.f-static.net/uploads/4372087/normal_5f88d4c75e246.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- cdn-cms.f-static.net
- papunagaku.weebly.com
- xexegetogud.weebly.com
- bufazori.weebly.com
- kafowudozajem.weebly.com
- xerekabixedil.weebly.com
- zoforute.weebly.com
- rimofunoduw.weebly.com
- uploads.strikinglycdn.com
- zoxuzuxebexot.weebly.com
- zelapagetuwuj.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report