MALICIOUS — live_streaming_film_avengers_endgame.pdf
MALICIOUS — live_streaming_film_avengers_endgame.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
b4528c52ea3ae244e2166a884b6c5bddfa2fd5997a0c52a6a2274d0a1ed57378 - SHA-1:
844f22ecce863a9a9118b84d1fd785558bad9eb8 - MD5:
f2b20530fc2f34f9f191df5172db815c - ssdeep:
3072:+/EMxhaEgpmvZO24zQYP2Zt83Ob3J/6Jkc48fMlUAaXT85NH/:+8MxYEzZO7cYP23838J+XFelv - TLSH:
T1BD3EF2F3B15BDC0C34479F937EBA299971A9C388662283511855E37C85BC6AF7F10A10 - Submitted as: live_streaming_film_avengers_endgame.pdf
- File type: pdf · Size: 143685 bytes
- Verdict: malicious (96/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: https://static.s123-cdn-static.com/uploads/4365998/normal_5fe056b45400a.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://pistant.ru/pbw?utm_term=live+streaming+film+avengers+endgame, https://suxuwimuwudex.weebly.com/uploads/1/3/4/6/134641155/dcf010e9a.pdf, http://tujedet.pbworks.com/f/super_mario_bros_ds_rom_download.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://pistant.ru/pbw?utm_term=live+streaming+film+avengers+endgame
- https://suxuwimuwudex.weebly.com/uploads/1/3/4/6/134641155/dcf010e9a.pdf
- http://tujedet.pbworks.com/f/super_mario_bros_ds_rom_download.pdf
- http://xoxafepapesu.pbworks.com/f/what_is_an_example_of_combined_variation.pdf
- https://bekawoxe.weebly.com/uploads/1/3/4/5/134529307/6315098.pdf
- https://pepotojil.weebly.com/uploads/1/3/4/9/134900045/zomimeva.pdf
- https://cdn-cms.f-static.net/uploads/4450152/normal_606099f402861.pdf
- https://kuxoredekudo.weebly.com/uploads/1/3/4/3/134368385/tixojejevopube-sodexafum-panuxenizarik-fizat.pdf
- https://nusatugob.weebly.com/uploads/1/3/4/8/134865614/6598c9bb17770c.pdf
- https://xudufuzed.weebly.com/uploads/1/3/0/8/130815664/1847056.pdf
- https://goradexajegofip.weebly.com/uploads/1/3/0/8/130874122/06d9b036c.pdf
- https://cdn-cms.f-static.net/uploads/4373297/normal_6051783d9a9ac.pdf
- https://static.s123-cdn-static.com/uploads/4365998/normal_5fe056b45400a.pdf
- http://zewalar.pbworks.com/w/file/fetch/144446898/mx_player_codec_1.9.8_armv7_neon_zip.pdf
- https://ladufuvugekowek.weebly.com/uploads/1/3/4/1/134108614/gebewosatodum.pdf
- https://cdn-cms.f-static.net/uploads/4530429/normal_603043f039a3e.pdf
- https://cdn-cms.f-static.net/uploads/4403823/normal_603f378942594.pdf
- https://cdn-cms.f-static.net/uploads/4464877/normal_5fe64bb8526b8.pdf
- http://kefimazusob.pbworks.com/w/file/fetch/144894594/candraphon_raid_shadow_legends_build.pdf
- https://semitedajun.weebly.com/uploads/1/3/1/6/131636975/02c65552fdb5.pdf
- https://jonomivebotuw.weebly.com/uploads/1/3/4/6/134683751/tikebati.pdf
- https://dironirodog.weebly.com/uploads/1/3/4/7/134760169/6cae8b540.pdf
- https://fizupubiwox.weebly.com/uploads/1/3/0/7/130775838/lejasirapugosedos.pdf
- https://nuzepobijane.weebly.com/uploads/1/3/4/8/134885792/veripat_wipefibabuge.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- pistant.ru
- suxuwimuwudex.weebly.com
- tujedet.pbworks.com
- xoxafepapesu.pbworks.com
- bekawoxe.weebly.com
- pepotojil.weebly.com
- cdn-cms.f-static.net
- kuxoredekudo.weebly.com
- nusatugob.weebly.com
- xudufuzed.weebly.com
- goradexajegofip.weebly.com
- static.s123-cdn-static.com
- zewalar.pbworks.com
- ladufuvugekowek.weebly.com
- kefimazusob.pbworks.com
- semitedajun.weebly.com
- jonomivebotuw.weebly.com
- dironirodog.weebly.com
- fizupubiwox.weebly.com
- nuzepobijane.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report