MALICIOUS — 22292939043.pdf
MALICIOUS — 22292939043.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (97/100). 5 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
aee0f4f002c6a94c61df2538f045fb546009d2936adf66f09ae6d548385ec490 - SHA-1:
dc6fcd1c4f56d143b41d76b1360943bda27b5f43 - MD5:
07b28142f483a95775be0184f6466312 - ssdeep:
1536:cTglm2NtU1Zqj0AHeeseJppVD6rnDgxkrg6pGk4l/PCC8sDHe7cYWIzIdWe/:YgnU/qjxHeiJ7VysxkrgrHliCfDHn5h5 - TLSH:
T19C39D0F350A7EC4CBECA9F037DA719AD6089938851369BA1508C777DD87C6AD3D10A80 - Submitted as: 22292939043.pdf
- File type: pdf · Size: 85454 bytes
- Verdict: malicious (97/100)
Detections (5 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!07B28142F483
MITRE ATT&CK
Why this verdict
The malicious score of 97/100 is the fusion of 6 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Kaspersky (KVRT) flagged HEUR:Hoax.PDF.Phish.gen (rule
HEUR:Hoax.PDF.Phish.gen) - engine signal, weight 0.55, confidence 0.85 - Embedded link rated suspicious by URL analysis: https://uploads.strikinglycdn.com/files/2a9c6da3-25b1-4a65-a767-10b73385a5d5/example_of_legal_contracts.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://botokaw.ru/strik?utm_term=ford+mustang+service+manual+download, https://nulazonale.weebly.com/uploads/1/3/4/8/134892754/7009035.pdf, https://uploads.strikinglycdn.com/files/2a9c6da3-25b1-4a65-a767-10b73385a5d5/example_of_legal_contracts.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://botokaw.ru/strik?utm_term=ford+mustang+service+manual+download
- https://nulazonale.weebly.com/uploads/1/3/4/8/134892754/7009035.pdf
- https://uploads.strikinglycdn.com/files/2a9c6da3-25b1-4a65-a767-10b73385a5d5/example_of_legal_contracts.pdf
- https://cdn-cms.f-static.net/uploads/4479214/normal_6061aec6c31a7.pdf
- http://tokio-2020.fun/wosomop93f81.pdf
- https://uploads.strikinglycdn.com/files/2bdf0268-0031-496f-9b8e-0851830c1ae7/how_to_replace_waste_toner_box.pdf
- https://cdn-cms.f-static.net/uploads/4499021/normal_60472dca5292a.pdf
- https://jogemubo.weebly.com/uploads/1/3/4/3/134321321/wokolosebu.pdf
- http://socialwave.me/crest_fruit_burst_toothpaste_discontinuedfrh65.pdf
- http://meriline.store/telehealth_services_definedukz8h.pdf
- https://uploads.strikinglycdn.com/files/6c7a361e-9d08-44d5-b615-508a438cf33a/90068641930.pdf
- https://cdn-cms.f-static.net/uploads/4403541/normal_602c77b2340f7.pdf
- https://static.s123-cdn-static.com/uploads/4405642/normal_5fcd7a32e5713.pdf
- https://cdn.sqhk.co/zupitefa/4ggDDUB/71085806839.pdf
- https://cdn.sqhk.co/boxokozofe/5ZBZgdo/c64._emu_apk_full.pdf
- http://mpvideo.org/zombie_virus_zombie_fps_shooting_zombie_gamesrsqej.pdf
- https://cdn.sqhk.co/malevevipali/Ngigdjb/zitufepexenege.pdf
- https://vesanalu.weebly.com/uploads/1/3/1/4/131482823/mepoza_fabawala_labenaxalirob_kafarodorok.pdf
- http://garant-ritual.online/kosanokofenowsy9.pdf
- https://cdn.sqhk.co/rarirawibowo/jjib6gg/lizom.pdf
- https://cdn.sqhk.co/zivuzigup/ihhejeI/72046697610.pdf
- https://cdn-cms.f-static.net/uploads/4402504/normal_601a07a65270e.pdf
- https://uploads.strikinglycdn.com/files/4e404c82-3dd4-40f1-b742-1243993cdfb0/gotogod.pdf
- https://uploads.strikinglycdn.com/files/46984f57-2c6f-4f9f-8462-6cdc9e1b5d4f/13177477675.pdf
- https://uploads.strikinglycdn.com/files/5ecc2c81-c3e9-4734-9dee-ae889eaed81a/why_does_my_playstation_gold_headset_keep_cutting_out.pdf
Embedded domains
- botokaw.ru
- nulazonale.weebly.com
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- tokio-2020.fun
- jogemubo.weebly.com
- socialwave.me
- meriline.store
- static.s123-cdn-static.com
- cdn.sqhk.co
- mpvideo.org
- vesanalu.weebly.com
- garant-ritual.online
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report