MALICIOUS — 7752706.pdf
MALICIOUS — 7752706.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
ba632db9e6c7244c93c21c7110dbe4b1f1d7cd94bf6cb9277ea5305e0296e841 - SHA-1:
5dab612c4690a4b2772ac498ca4633ab32f63f30 - MD5:
92e9d63514ecdd6918587a0556c036fe - ssdeep:
1536:22hCK+IjIfFWA32wcE5qhwjnsLTVBbAmQjOtfjwNz6FlszSRAf3s:2aGd12twsLT7pQitfjyz6vsKx - TLSH:
T11739DFF3B0A7DECC7A859F432EB714A8B18AEB853122DA9444C8377CD5B857D1E10960 - Submitted as: 7752706.pdf
- File type: pdf · Size: 84402 bytes
- Verdict: malicious (94/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: https://static1.squarespace.com/static/5fc798bbfc603311fbfb3b4f/t/5fc93d2eb574fc26fc00303e/1607023919344/short_paragraph_on_save_the_planet_earth.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=b.%20ed%20entrance%20exam%20form%202018%20bihar, https://uploads.strikinglycdn.com/files/515bcce3-35cd-4d9c-886f-94c5631d489c/16784739573.pdf, https://cdn-cms.f-static.net/uploads/4380228/normal_5f907b2d9ffc8.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=b.%20ed%20entrance%20exam%20form%202018%20bihar
- https://uploads.strikinglycdn.com/files/515bcce3-35cd-4d9c-886f-94c5631d489c/16784739573.pdf
- https://cdn-cms.f-static.net/uploads/4380228/normal_5f907b2d9ffc8.pdf
- https://cdn-cms.f-static.net/uploads/4454813/normal_5fb890555e0d6.pdf
- https://s3.amazonaws.com/varolexexus/startup_company_business_plan.pdf
- https://cdn-cms.f-static.net/uploads/4426269/normal_5f98e0248fce2.pdf
- https://s3.amazonaws.com/rebomedug/badger_5_garbage_disposal_leaking_from_side.pdf
- https://uploads.strikinglycdn.com/files/b81fd5d4-e07a-4953-88c8-6a3f54403533/lion_beaver_otter_golden_retriever.pdf
- https://uploads.strikinglycdn.com/files/331bd86c-5272-46de-a30d-b426b14aa073/69857812566.pdf
- https://static1.squarespace.com/static/5fc798bbfc603311fbfb3b4f/t/5fc93d2eb574fc26fc00303e/1607023919344/short_paragraph_on_save_the_planet_earth.pdf
- https://uploads.strikinglycdn.com/files/26d31d9d-1264-42ab-8dbf-3722c00d2290/capture_by_sonic_assault_download.pdf
- https://s3.amazonaws.com/sivanira/actually_formal_synonym.pdf
- https://static1.squarespace.com/static/5fc0d49a16f6d44b07be6b5d/t/5fc2ecf83485235c8627a53e/1606610168914/coaching_actuaries_exam_p_manual.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- s3.amazonaws.com
- static1.squarespace.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report