MALICIOUS — gated.pdf
MALICIOUS — gated.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
97ae07d23c6dc39c8e4d7de453d1824ea5ad8448d5db2ed30e0965dd37d8abbe - SHA-1:
63bca8196917d4f0466ba4983502695c25bb160c - MD5:
820b53329074eef0e7210fc3d00f2376 - ssdeep:
1536:+xiKIEcFVTyA3gVZGcm2wcoxOZGWcpOyX+pVKWxlg+XM2aOI/:IiK/cFVTKMGoxOZByW9lg+s - TLSH:
T1E737D1F73147DC8DB78B9F435AEA11686096DB5C21A3DA5090C8B91CC5BC2BEBF40A11 - Submitted as: gated.pdf
- File type: pdf · Size: 69805 bytes
- Verdict: malicious (94/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: http://stellarvvv.ru/ckfinder/userfiles/files/13715259919.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://allytemp.ru/uplcv?utm_term=best+epub+editor+android, https://gospel-streams.com/asset/ckfinder/userfiles/files/30414159316.pdf, https://italvaping.com/file/rofubipatarovese.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://allytemp.ru/uplcv?utm_term=best+epub+editor+android
- https://gospel-streams.com/asset/ckfinder/userfiles/files/30414159316.pdf
- https://italvaping.com/file/rofubipatarovese.pdf
- https://ctapigroup3.com/contents/files/53468462245.pdf
- https://dienlanhhonganh.com/images/pic/file/36916879864.pdf
- http://koyomisushi.com/uploads/files/tejekiw.pdf
- https://www.andreivieru.com/ckfinder/userfiles/files/kajojebuwumubazoxedorotu.pdf
- http://stellarvvv.ru/ckfinder/userfiles/files/13715259919.pdf
- http://english-island.pl/wp-content/plugins/super-forms/uploads/php/files/011cj8vd09clajgoo0i7pueip1/simidedujevesujolibepifuf.pdf
- http://bonezi.morefriendship.com/upload/files/82464985246.pdf
- http://jockmurray.com/wp-content/plugins/formcraft/file-upload/server/content/files/16137db2f46252---sojazojikitizanufoviw.pdf
- https://108pizza.pl/uploads/userfiles/files/9571685453.pdf
- https://francoisdaulte.com/ckfinder/userfiles/files/xajalitewidazup.pdf
- http://aquarium-kochi.com/app/webroot/ckfinder/userfiles/files/jevoworarulagumovixul.pdf
- http://www.tivafa.hu/upload/file/bewilorub.pdf
- http://bagpack.com.np/wp-content/plugins/formcraft/file-upload/server/content/files/1614113b2d80b4---mamutamonovamijejobi.pdf
- https://doanandieuduong295doson.vn/namthuan/images/news/files/tugamod.pdf
- http://starroadchina.com/userfiles/file/24808910316.pdf
- http://argyleliquidations.com/userfiles/files/dekotobog.pdf
- http://cdjuchuan.com/upload/files/munemijulamusupivumim.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
Embedded domains
- allytemp.ru
- gospel-streams.com
- italvaping.com
- ctapigroup3.com
- dienlanhhonganh.com
- koyomisushi.com
- www.andreivieru.com
- stellarvvv.ru
- english-island.pl
- bonezi.morefriendship.com
- jockmurray.com
- 108pizza.pl
- francoisdaulte.com
- aquarium-kochi.com
- starroadchina.com
- argyleliquidations.com
- cdjuchuan.com
- www.w3.org
- purl.org
- ns.adobe.com
- www.tivafa.hu
- bagpack.com.np
- doanandieuduong295doson.vn
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report