MALICIOUS — bewal.pdf
MALICIOUS — bewal.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 5 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
c340fbcf05066467ce7c5dc53abb8323680b939008736fa1f600024c714ff543 - SHA-1:
8ce12e9cfb74fd1e6a816973627b70459dec21a9 - MD5:
9d8bb580f45b31c9f07049ed8f4889ce - ssdeep:
1536:YCAjUEPhaXZEw5iEwVT03vY/Y+TYC1I8nRfAzRO+uJqXvfK:cjlpiBis/YBTk8nRIzRO+nXa - TLSH:
T12338C0F3309BDD8C7B8FA7836EB611AC7486D3886122AB905584765DC57C2BC3F10A90 - Submitted as: bewal.pdf
- File type: pdf · Size: 79590 bytes
- Verdict: malicious (94/100)
Detections (5 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!9D8BB580F45B
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: https://4cd5eafb-d261-4666-a528-29b55b1676c1.filesusr.com/ugd/8dde66_2d22398d84a443f7b06e1366d5e8bc37.pdf?index=true - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: http://tevuvisena.iblogger.org/34842026952.pdf, https://uploads.strikinglycdn.com/files/71b93c26-3b81-42ad-8393-bb2d17f5a1a7/the_hunger_games_catching_fire_online_read.pdf, https://4cd5eafb-d261-4666-a528-29b55b1676c1.filesusr.com/ugd/8dde66_2d22398d84a443f7b06e1366d5e8bc37.pdf?index=true - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://feedproxy.google.com/~r/wb/ENAH/~3/4NO0L8wlyOA/wb?keyword=how%20to%20fix%20sole%20treadmill
- http://tevuvisena.iblogger.org/34842026952.pdf
- https://uploads.strikinglycdn.com/files/71b93c26-3b81-42ad-8393-bb2d17f5a1a7/the_hunger_games_catching_fire_online_read.pdf
- https://4cd5eafb-d261-4666-a528-29b55b1676c1.filesusr.com/ugd/8dde66_2d22398d84a443f7b06e1366d5e8bc37.pdf?index=true
- http://fumojaw.epizy.com/42525741126.pdf
- http://vwwv-avito.online/minority_report_480p_freeun5q5.pdf
- https://s3.amazonaws.com/boduxatavepe/widenumimekotato.pdf
- https://s3.amazonaws.com/buwosevax/baidu_browser_offline_installer_free.pdf
- https://uploads.strikinglycdn.com/files/8e0c9406-1c21-4af1-be51-a53ca6a26aa0/lexile_conversion_chart_fountas_and_pinnell.pdf
- https://87c8fc71-818b-4167-bf0d-2ac3bc49ffd1.filesusr.com/ugd/f9d4cd_11131d1608a1447196203773146b06c0.pdf?index=true
- https://bunonosuvon.weebly.com/uploads/1/3/5/9/135976801/1517991.pdf
- http://devlp.design/tixukadey3nm3.pdf
- http://fuvepupur.22web.org/90740067902.pdf
- https://s3.amazonaws.com/remavuj/ella_minnow_pea_book_barnes_and_noble.pdf
- https://uploads.strikinglycdn.com/files/de4e782e-88da-474c-8d85-db9100569d15/how_to_prepare_for_soa_exam_pa.pdf
- https://xuwukixirekut.weebly.com/uploads/1/3/5/9/135966502/zaguxujogamexivuriw.pdf
- http://dugules.iblogger.org/fidemelagoxiranaxunoxin.pdf
- https://s3.amazonaws.com/feborobegibew/85390454080.pdf
- https://uploads.strikinglycdn.com/files/44df4fb9-ee67-4fa1-97a2-c1c89ce94ced/93067235285.pdf
- https://veliwomi.weebly.com/uploads/1/3/5/3/135343105/8cd2d4e5e866d4.pdf
- https://uploads.strikinglycdn.com/files/51c0b0e4-49bf-4e3f-ae21-fe36df6ab7be/food_safety_modernization_act_produce_safety_rule.pdf
- http://lnstagram-helping.live/98710310589dxd5m.pdf
- https://dujomujur.weebly.com/uploads/1/3/4/8/134883281/notanolonutagujemo.pdf
- http://meetchambre.xyz/schumacher_xm1-5_maintainer_1.5-ampm9riw.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- feedproxy.google.com
- tevuvisena.iblogger.org
- uploads.strikinglycdn.com
- 4cd5eafb-d261-4666-a528-29b55b1676c1.filesusr.com
- fumojaw.epizy.com
- vwwv-avito.online
- s3.amazonaws.com
- 87c8fc71-818b-4167-bf0d-2ac3bc49ffd1.filesusr.com
- bunonosuvon.weebly.com
- fuvepupur.22web.org
- xuwukixirekut.weebly.com
- dugules.iblogger.org
- veliwomi.weebly.com
- lnstagram-helping.live
- dujomujur.weebly.com
- meetchambre.xyz
- www.w3.org
- purl.org
- ns.adobe.com
- devlp.design
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report