MALICIOUS — 5764383.pdf
MALICIOUS — 5764383.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
b6d2dffb517d7bfdd86d9100cca0791fa886be3a229e2f92fb73727c85f64bd5 - SHA-1:
7cf09bf7611fddfb6c43095d6db8e00d5d730636 - MD5:
d11ce14902f36d9664c29bc54bb35174 - ssdeep:
1536:akjcxPWOt6D3Qx2KRz460kJ0O9glN9D6Pe8UP9dmD1ranZ41lRf+OFOD:XbkggEaqdQ4ODdaZgf+OI - TLSH:
T19D38D1F7A147CD8CA7561B07AEEA6258A0D4D2CD2073F65404C4B72CC9B85FE6E20D62 - Submitted as: 5764383.pdf
- File type: pdf · Size: 79201 bytes
- Verdict: malicious (96/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: https://uploads.strikinglycdn.com/files/8546c2d6-8e36-44f5-9528-a214b2fea7f6/30938649082.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=geometry%20dash%20meltdown%20apk%20full%20version, https://sofuwikomu.weebly.com/uploads/1/3/4/3/134308783/5317274.pdf, https://uploads.strikinglycdn.com/files/8546c2d6-8e36-44f5-9528-a214b2fea7f6/30938649082.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=geometry%20dash%20meltdown%20apk%20full%20version
- https://s3.amazonaws.com/nademopor/tuximujativ.pdf
- https://sofuwikomu.weebly.com/uploads/1/3/4/3/134308783/5317274.pdf
- https://uploads.strikinglycdn.com/files/8546c2d6-8e36-44f5-9528-a214b2fea7f6/30938649082.pdf
- https://uploads.strikinglycdn.com/files/a598c91f-2e01-4519-9cd3-78a4fd0a1e71/90872339955.pdf
- https://s3.amazonaws.com/lakujusitejojet/2017_econ_dse_mc_answer.pdf
- https://uploads.strikinglycdn.com/files/9acb3a08-221c-4744-99c7-88b0d87be067/uan_parmaklar_hz_testi.pdf
- https://s3.amazonaws.com/vonusirukete/82633171251.pdf
- https://s3.amazonaws.com/lomogas/mitewunopefa.pdf
- https://tixovokibena.weebly.com/uploads/1/3/4/1/134109053/sisosefutavif-kakinenosa-wetedawum.pdf
- https://cdn.sqhk.co/nupegefozub/utcUPgj/dead_eyes_podcast.pdf
- https://s3.amazonaws.com/fisulefajow/alembic_pharmaceuticals_ltd_annual_report_2016-_17.pdf
- https://uploads.strikinglycdn.com/files/ace6d563-46d9-4a1c-a6eb-dc05427fc0f3/house_of_darkness_house_of_light.pdf
- https://s3.amazonaws.com/belopudevuzuza/2993133971.pdf
- https://uploads.strikinglycdn.com/files/eb7abe4b-f9d0-4465-b612-e89f0ebc435d/air_venturi_g6_hand_pump_rebuild.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- s3.amazonaws.com
- sofuwikomu.weebly.com
- uploads.strikinglycdn.com
- tixovokibena.weebly.com
- cdn.sqhk.co
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report