MALICIOUS — example_of_legal_contracts.pdf
MALICIOUS — example_of_legal_contracts.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 5 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
ac3d701b7a2e0d687d4c652185c4454e0ce8ba01282e6d06584b4679a601adf5 - SHA-1:
91211d7be658fb0c276604d55def5592798f1053 - MD5:
a3398a574f81a99bf2790143c38cffb0 - ssdeep:
1536:1O8VTfoaAg6/wespfDFqe18APoBUAweuRuR+2k9T3VGLNHNL+9JtI:YSjoKgGFp6QlVEUlGLNH4o - TLSH:
T10138D0F76197DD8CBE875BC77DA7645C649AD2887132DB8050886F3CD47C2AE7A20820 - Submitted as: example_of_legal_contracts.pdf
- File type: pdf · Size: 79886 bytes
- Verdict: malicious (96/100)
Detections (5 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!A3398A574F81
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: https://cdn-cms.f-static.net/uploads/4470679/normal_6049866ae3b1e.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://lozipotod.ru/strik?utm_term=example+of+legal+contracts, https://cdn-cms.f-static.net/uploads/4470679/normal_6049866ae3b1e.pdf, http://gorogukusesewu.rf.gd/genetically_modified_organisms_articles.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://lozipotod.ru/strik?utm_term=example+of+legal+contracts
- https://cdn-cms.f-static.net/uploads/4470679/normal_6049866ae3b1e.pdf
- http://gorogukusesewu.rf.gd/genetically_modified_organisms_articles.pdf
- http://graatorama.space/3663548208z8zj9.pdf
- http://gaxodusipif.epizy.com/zabiwobebojoxodiwuxawa.pdf
- https://cdn-cms.f-static.net/uploads/4505687/normal_5fd0d8746e226.pdf
- http://amst-watch-v1.club/62078877398pifyf.pdf
- http://pufomatuluwe.epizy.com/what_is_the_history_of_islamic_education.pdf
- https://static.s123-cdn-static.com/uploads/4462678/normal_600451457893a.pdf
- http://jarujoburisuw.rf.gd/chori_chupke_movie_song.pdf
- http://nafaradevofipaf.myartsonline.com/ccna_voice_configuration.pdf
- https://cdn-cms.f-static.net/uploads/4451736/normal_603c19e17c0c0.pdf
- http://hamlikjorettoop.ru/books_on_mind_control_techniquesaxc2g.pdf
- http://xirokigekokumar.rf.gd/litarizudigevezira.pdf
- http://pidawudimo.scienceontheweb.net/how_to_connect_sony_soundbar_and_subwoofer_to_tv.pdf
- http://lnstagramoriginal.com/5573973502vm4ez.pdf
- http://fredo.run/iqsms_reporting_3aq9fn.pdf
- http://about-igsupport.com/color_theory_tattoohey3w.pdf
- http://d-youtube.com/riptide_gp_renegade_2_mod_apkfh5z7.pdf
- http://tarobajasupimi.epizy.com/strength_exercises_for_runners.pdf
- https://static.s123-cdn-static.com/uploads/4500208/normal_5fce84e88168c.pdf
- http://wewonak.rf.gd/6597329322.pdf
- http://a-trvl.ru/kalonodilinoxozeferaz1rwq.pdf
- http://nagasawovebuba.epizy.com/algebra_1_regents_2020.pdf
- http://wegoluxetas.scienceontheweb.net/definicion_de_autodominio.pdf
Embedded domains
- lozipotod.ru
- cdn-cms.f-static.net
- graatorama.space
- gaxodusipif.epizy.com
- amst-watch-v1.club
- pufomatuluwe.epizy.com
- static.s123-cdn-static.com
- nafaradevofipaf.myartsonline.com
- hamlikjorettoop.ru
- pidawudimo.scienceontheweb.net
- lnstagramoriginal.com
- about-igsupport.com
- d-youtube.com
- tarobajasupimi.epizy.com
- a-trvl.ru
- nagasawovebuba.epizy.com
- wegoluxetas.scienceontheweb.net
- www.w3.org
- purl.org
- ns.adobe.com
- gorogukusesewu.rf.gd
- jarujoburisuw.rf.gd
- xirokigekokumar.rf.gd
- fredo.run
- wewonak.rf.gd
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report