MALICIOUS — 5020259.pdf
MALICIOUS — 5020259.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 5 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
9fd8570974a1e4dbbc64375433291ada30b8fa1fcb97c895b4543589061d21bc - SHA-1:
1b2b0dd3e89803af39391ea37e3d5f08c641f8b3 - MD5:
c45b3ef39b4dacc8f32958c058e0d4d1 - ssdeep:
1536:jyFUlAJLFwAfhe0WIkpuQjXEBzeuNrgwwtazemwjG4jwO:m8sve3Ikc+EBKuVwwzaB - TLSH:
T11937D1F7609BCD8CAA478B576976351C6489D34DA635CB604488BBBCC4BC7BC3E20A11 - Submitted as: 5020259.pdf
- File type: pdf · Size: 74199 bytes
- Verdict: malicious (94/100)
Detections (5 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!C45B3EF39B4D
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: http://bunnygummy.ru/70942719263gugz.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: http://kawafopi.mygamesonline.org/anaesthesia_drug_doses.pdf, http://online-bestshop.xyz/68081860219ddefd.pdf, http://siwosupegejolop.medianewsonline.com/youth_strength_training_program.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://feedproxy.google.com/~r/wb/ENAH/~3/bQ3nTxENlgE/wb?keyword=the%20bee%20tree%20setting
- http://kawafopi.mygamesonline.org/anaesthesia_drug_doses.pdf
- http://online-bestshop.xyz/68081860219ddefd.pdf
- https://s3.amazonaws.com/jejulurowev/62493411204.pdf
- http://siwosupegejolop.medianewsonline.com/youth_strength_training_program.pdf
- http://lowemugujirowox.rf.gd/48927855581.pdf
- https://s3.amazonaws.com/gagotaniwipure/wapibipamiti.pdf
- http://bunnygummy.ru/70942719263gugz.pdf
- http://limixumijegaf.epizy.com/96725983509.pdf
- http://katorewudejizut.22web.org/33362312304.pdf
- http://koprovk.xyz/what_does_the_maintenance_required_light_mean_on_a_2002_honda_civicye1hf.pdf
- http://wefinexof.iblogger.org/boilerplate_text_in_oracle_forms.pdf
- https://s3.amazonaws.com/dewazewokib/email_writing_format_for_cbse_class_10.pdf
- http://kenubuw.epizy.com/jofidigo.pdf
- http://daxafedijumexir.rf.gd/jenizojimebiwixar.pdf
- https://s3.amazonaws.com/sobaketemu/room_database_android_example_codelab.pdf
- https://s3.amazonaws.com/vunizi/how_to_replace_2017_toyota_corolla_key_battery.pdf
- https://s3.amazonaws.com/telasebisu/jepefexuloxomozoj.pdf
- http://gumomexad.onlinewebshop.net/54463220559.pdf
- http://fojudesekuxujef.22web.org/images_of_fc_barcelona_logo.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
Embedded domains
- feedproxy.google.com
- kawafopi.mygamesonline.org
- online-bestshop.xyz
- s3.amazonaws.com
- siwosupegejolop.medianewsonline.com
- bunnygummy.ru
- limixumijegaf.epizy.com
- katorewudejizut.22web.org
- koprovk.xyz
- wefinexof.iblogger.org
- kenubuw.epizy.com
- gumomexad.onlinewebshop.net
- fojudesekuxujef.22web.org
- www.w3.org
- purl.org
- ns.adobe.com
- lowemugujirowox.rf.gd
- daxafedijumexir.rf.gd
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report