MALICIOUS — gevakali-miripem.pdf
MALICIOUS — gevakali-miripem.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
be7c224298192603d4079a47d06f449ff524740d3c1644310093d2cefe090d18 - SHA-1:
0cde43712e71371351b0e881985e9c964b55ec85 - MD5:
b507e640a41df2c121135a62311bb361 - ssdeep:
1536:SDokU3ujAyaddtWNnok4l2XiHVLaTR4D8ZD3DUykl5580tuFOSmyADq:MMuMjDEnHNYO3DUxptuFO5C - TLSH:
T18E37D0E3A057DD4DBA4EA703BEBB161D2545D198E03757A081D8BFAC847C2FC6E00961 - Submitted as: gevakali-miripem.pdf
- File type: pdf · Size: 71266 bytes
- Verdict: malicious (96/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: https://uploads.strikinglycdn.com/files/9e811ded-18f4-45f8-bf45-442ad44efb30/pabavalej.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://cctraff.ru/wb?keyword=figural%20classification%20worksheets, https://static1.squarespace.com/static/5fc0052111f6a4198480c96b/t/5fceaf555c72243a4f11f130/1607380821845/global_war_simulation_asia_premium_mod_apk_download.pdf, https://xulavuxedipi.weebly.com/uploads/1/3/4/0/134017657/gedulitunum_vofevetukezel_pemufimu.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://cctraff.ru/wb?keyword=figural%20classification%20worksheets
- https://static1.squarespace.com/static/5fc0052111f6a4198480c96b/t/5fceaf555c72243a4f11f130/1607380821845/global_war_simulation_asia_premium_mod_apk_download.pdf
- https://xulavuxedipi.weebly.com/uploads/1/3/4/0/134017657/gedulitunum_vofevetukezel_pemufimu.pdf
- https://static1.squarespace.com/static/5fc78ef503f04e270fe537c2/t/5fc8fe24196f5547f36da365/1607007781249/houston_bcycle_jobs.pdf
- https://static1.squarespace.com/static/5fc129dd17e7202640ebdc1b/t/5fc59d0bf8cdb769c6a4d5e1/1606786315986/kuzezos.pdf
- https://static1.squarespace.com/static/5fc1b82e11f6a419848b6c75/t/5fc32eb1eaf37e3b640413aa/1606626994639/modern_database_management_12th_edition.pdf
- https://jifosibupegexuv.weebly.com/uploads/1/3/4/6/134692258/5461405.pdf
- https://cdn-cms.f-static.net/uploads/4387814/normal_5f91dbc53049b.pdf
- https://cdn-cms.f-static.net/uploads/4420431/normal_5fad84a95ba10.pdf
- https://uploads.strikinglycdn.com/files/9e811ded-18f4-45f8-bf45-442ad44efb30/pabavalej.pdf
- https://static1.squarespace.com/static/5fbce344be7cfc36344e8aaf/t/5fbdf41a3c02f22b9dd29fb1/1606284314640/nedoguwigepozifinoramu.pdf
- https://cdn-cms.f-static.net/uploads/4424666/normal_5f9c73661ef05.pdf
- https://cdn-cms.f-static.net/uploads/4480423/normal_5fb2bf901f62e.pdf
- https://cdn-cms.f-static.net/uploads/4444358/normal_5fa7f6757e006.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- cctraff.ru
- static1.squarespace.com
- xulavuxedipi.weebly.com
- jifosibupegexuv.weebly.com
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report