MALICIOUS — vafas.pdf
MALICIOUS — vafas.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
a270fd75e2ac19885d87b44f5ca3e2b63d7c1030ff689c3997c55a6cf0f0a388 - SHA-1:
1d80613ca0f26af6d704abc065cb9d6c6efedebd - MD5:
789448f8e38ab02fcb6859598cf3b6a6 - ssdeep:
1536:QS+NAUrOdAiPCZv7dWv4oSnP0g/86HeTE1bKNbBP1hbEhRMZzNF:YSUIAiPCZv7YQR0g/eJP1ZEm/ - TLSH:
T18437DFB32287CD4C739AD713B9F51408B48DEA897132DEA054C5BB2CC1BC5BE6E51A60 - Submitted as: vafas.pdf
- File type: pdf · Size: 69954 bytes
- Verdict: malicious (96/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: https://static.s123-cdn-static.com/uploads/4385848/normal_5fc3eccddfed9.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://traffset.ru/wb?keyword=bullguard%20antivirus%20for%20android, https://uploads.strikinglycdn.com/files/e493ddea-240c-4b9c-a5df-7956ab80b820/johnson_seahorse_10_carburetor.pdf, https://uploads.strikinglycdn.com/files/097ae07d-5622-4c11-b80f-a1a6924439b0/degradacion_de_aminoacidos_esenciales.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://traffset.ru/wb?keyword=bullguard%20antivirus%20for%20android
- https://uploads.strikinglycdn.com/files/e493ddea-240c-4b9c-a5df-7956ab80b820/johnson_seahorse_10_carburetor.pdf
- https://uploads.strikinglycdn.com/files/097ae07d-5622-4c11-b80f-a1a6924439b0/degradacion_de_aminoacidos_esenciales.pdf
- https://uploads.strikinglycdn.com/files/15f4f85e-fd6d-46d8-a9fd-31eaf9c48e69/66457017018.pdf
- https://static.s123-cdn-static.com/uploads/4385848/normal_5fc3eccddfed9.pdf
- https://wobanavemo.weebly.com/uploads/1/3/4/0/134096337/sugexam.pdf
- https://cdn-cms.f-static.net/uploads/4419441/normal_5fbc5d982e161.pdf
- https://s3.amazonaws.com/tubupejevomo/font_browallia_new_windows_10.pdf
- https://cdn-cms.f-static.net/uploads/4380543/normal_5f8c8a8363932.pdf
- https://static1.squarespace.com/static/5fc5c98f6b97992eb57d115f/t/5fc8d6a6bbb7f45a92942a17/1606997671580/31643288473.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- traffset.ru
- uploads.strikinglycdn.com
- static.s123-cdn-static.com
- wobanavemo.weebly.com
- cdn-cms.f-static.net
- s3.amazonaws.com
- static1.squarespace.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report