MALICIOUS — 6120009.pdf
MALICIOUS — 6120009.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 5 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
99b18dafea8c2b21b13bd3222b9d509a64e65640500472a5e8444d98f0885cf5 - SHA-1:
014dd909bb8096e1c480881881882227b6a1766f - MD5:
bbd55a67c0f63567373fc183d8f39115 - ssdeep:
1536:Gn2ADN62FWjIijVbXQkbQh903aVdm9fIcYlv+GSAevcCyf/:bADw2FLGbgp9Aa+9fIcYSAlCg - TLSH:
T1A938D0F36297CC4CA68A8F03BED6555B708EC2897031CA90558C7A6CC87C67E3F65921 - Submitted as: 6120009.pdf
- File type: pdf · Size: 80363 bytes
- Verdict: malicious (94/100)
Detections (5 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!BBD55A67C0F6
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: https://vojelapavefiga.weebly.com/uploads/1/3/4/3/134308780/biwevomekoj.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://jacksth.ru/wb?keyword=what%20are%20the%20character%20names%20in%20jungle%20book, http://nopawumakonip.22web.org/16th_nso_answer_key_set_b.pdf, http://gedawirij.66ghz.com/atavus_tackling_test_answers.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://jacksth.ru/wb?keyword=what%20are%20the%20character%20names%20in%20jungle%20book
- http://nopawumakonip.22web.org/16th_nso_answer_key_set_b.pdf
- http://gedawirij.66ghz.com/atavus_tackling_test_answers.pdf
- http://lajirobodogew.epizy.com/tomaradaf.pdf
- https://s3.amazonaws.com/mudurixo/android_8_iso_for_pc.pdf
- http://ziwigosopijulal.mygamesonline.org/samsung_tablet_sm-t530nu_specs.pdf
- http://zumepaposakuf.scienceontheweb.net/bluebook_citation_format_for_articles.pdf
- https://s3.amazonaws.com/takurugilij/gaming_pc_build_guide.pdf
- http://runuwug.myartsonline.com/how_to_find_initial_velocity_with_angle_and_distance.pdf
- https://s3.amazonaws.com/nilafafakem/icom_ic-706_mk2_service_manual.pdf
- https://vojelapavefiga.weebly.com/uploads/1/3/4/3/134308780/biwevomekoj.pdf
- http://zezomaxijuduj.22web.org/cloudy_with_achance_of_meatballs_tv_show_cast.pdf
- http://telagivepovadul.epizy.com/84367842280.pdf
- http://fejavodexata.getenjoyment.net/wavozozisipiloxe.pdf
- https://s3.amazonaws.com/mizeteb/64932755539.pdf
- https://cdn-cms.f-static.net/uploads/4478132/normal_6020cf9fb06ce.pdf
- https://cdn-cms.f-static.net/uploads/4417534/normal_602004acab3a2.pdf
- https://kadeniki.weebly.com/uploads/1/3/4/0/134097858/xeruxe.pdf
- https://s3.amazonaws.com/xunilukegez/gasopewovitusupowelis.pdf
- https://kovajokuluvemu.weebly.com/uploads/1/3/5/3/135335912/8416854.pdf
- http://wijopimitiraze.epizy.com/what_is_high-concept_fiction.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- jacksth.ru
- nopawumakonip.22web.org
- gedawirij.66ghz.com
- lajirobodogew.epizy.com
- s3.amazonaws.com
- ziwigosopijulal.mygamesonline.org
- zumepaposakuf.scienceontheweb.net
- runuwug.myartsonline.com
- vojelapavefiga.weebly.com
- zezomaxijuduj.22web.org
- telagivepovadul.epizy.com
- fejavodexata.getenjoyment.net
- cdn-cms.f-static.net
- kadeniki.weebly.com
- kovajokuluvemu.weebly.com
- wijopimitiraze.epizy.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report