MALICIOUS — 0ecc9a7ad39.pdf
MALICIOUS — 0ecc9a7ad39.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 4 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
bd7b0544ba10e478ac89fea9943b74a11b42bb9619903cf6351df6df02e853a7 - SHA-1:
3b64bd9a8932e74bf081d6f4c15ffa81103a6194 - MD5:
b1186552f0ef10215df00317b8195682 - ssdeep:
1536:J+DNXK0k+nk2Bkf3wFAGAGKTtWaZ7YNagjKzyIC5+4Es5VYWxBZtfIG:93+kEkIFWimYIg6yTE4EsL/N - TLSH:
T1033AD0F360A7DD8DB68B6B437AA7215DB48CC35D65329B800444BA6C9079DFC7F019A0 - Submitted as: 0ecc9a7ad39.pdf
- File type: pdf · Size: 95229 bytes
- Verdict: malicious (94/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: https://gamepasak.weebly.com/uploads/1/3/4/1/134109087/xoderogemefisemake.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://trafftec.ru/wb?keyword=class%2010%20maths%20exemplar%20solutions%20chapter%202, https://cdn.sqhk.co/vexorikodo/6sNggih/32581838858.pdf, https://site-1174826.mozfiles.com/files/1174826/16269832547.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://trafftec.ru/wb?keyword=class%2010%20maths%20exemplar%20solutions%20chapter%202
- https://cdn.sqhk.co/vexorikodo/6sNggih/32581838858.pdf
- https://s3.amazonaws.com/jaloto/bhangra_song_djjohal.pdf
- https://site-1174826.mozfiles.com/files/1174826/16269832547.pdf
- https://s3.amazonaws.com/kozewuposoridil/ph_and_buffer_biochemistry.pdf
- https://cdn.sqhk.co/kovixileta/ciaggO0/niniworopinis.pdf
- https://gamepasak.weebly.com/uploads/1/3/4/1/134109087/xoderogemefisemake.pdf
- https://cdn.sqhk.co/xarozowuzosa/gXphi8i/91729930243.pdf
- https://site-1168389.mozfiles.com/files/1168389/27802234907.pdf
- https://cdn.sqhk.co/namaboniki/rjdXhga/photo_collage_art.pdf
- https://mizavuzozubex.weebly.com/uploads/1/3/4/7/134730625/9556535.pdf
- https://s3.amazonaws.com/tasufagijaremo/candy_striper_uniform_2019.pdf
- https://s3.amazonaws.com/memobofilenabon/12281560792.pdf
- https://s3.amazonaws.com/pajeriramal/sesisazawuwixafiberoveni.pdf
- https://xujopikaxatanow.weebly.com/uploads/1/3/4/8/134850499/2433043.pdf
- https://site-1174122.mozfiles.com/files/1174122/98271566357.pdf
- https://pirizujimo.weebly.com/uploads/1/3/4/4/134454944/e2b85.pdf
- https://cdn.sqhk.co/xewumoxu/hjdhg3m/51341568515.pdf
- https://cdn.sqhk.co/benibavagoge/g1hbYtk/small_living_world_game_tips.pdf
- https://cdn.sqhk.co/nomazotesi/ibchijf/download_game_stormblades_mod_apk.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
Embedded domains
- trafftec.ru
- cdn.sqhk.co
- s3.amazonaws.com
- site-1174826.mozfiles.com
- gamepasak.weebly.com
- site-1168389.mozfiles.com
- mizavuzozubex.weebly.com
- xujopikaxatanow.weebly.com
- site-1174122.mozfiles.com
- pirizujimo.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report