MALICIOUS — template_ppt_pastel_free.pdf
MALICIOUS — template_ppt_pastel_free.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 5 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
c694abe04178e60c06c85c130c6d99658304a75f8eaf02d76fa0afb60d27c79a - SHA-1:
b814ea226ffcd4b5e7b4a476f495b8f7b8990d2d - MD5:
0161b453cb283221583e65d85f67a4a9 - ssdeep:
1536:9SwsYtAgzdlYqE9QESyz1HiR2lBmfyd+Q9yyd16B9:srYtAg5k9QEVBiu8e+Q9d1O - TLSH:
T18337C0F33097EE8C7A8BAB437EA7126D588AC3897111869145887B5DC87C77E7F00A50 - Submitted as: template_ppt_pastel_free.pdf
- File type: pdf · Size: 73064 bytes
- Verdict: malicious (96/100)
Detections (5 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!0161B453CB28
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://ridelox.pbworks.com/f/66425659263.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://oniceh.ru/pbw?utm_term=template+ppt+pastel+free, http://wuranosa.pbworks.com/w/file/fetch/144416106/x_videostudio.video_editor_apk_free_download_for_android_phone.pdf, https://kilavolofijon.weebly.com/uploads/1/3/1/1/131164174/kobonijak.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://oniceh.ru/pbw?utm_term=template+ppt+pastel+free
- http://wuranosa.pbworks.com/w/file/fetch/144416106/x_videostudio.video_editor_apk_free_download_for_android_phone.pdf
- https://kilavolofijon.weebly.com/uploads/1/3/1/1/131164174/kobonijak.pdf
- http://vomokig.pbworks.com/f/84783417061.pdf
- https://uploads.strikinglycdn.com/files/69be55d7-6c5d-45f1-a19f-bd3718a65642/how_many_calories_in_one_taco_bell_taco.pdf
- http://rujuboxu.pbworks.com/w/file/fetch/144457512/is_there_a_auto_clicker_for_mac.pdf
- https://uploads.strikinglycdn.com/files/b8eb0d37-b684-479e-928d-e94a292b43ad/tawexesimabofogus.pdf
- https://uploads.strikinglycdn.com/files/de95e619-19f6-49cb-af6b-946b933f5d34/cisco_command_switchport_mode_trunk.pdf
- http://ridelox.pbworks.com/f/66425659263.pdf
- https://uploads.strikinglycdn.com/files/34afc4ec-2410-404b-bb7d-4de768ccceb1/13255360014.pdf
- http://lulimogosan.pbworks.com/w/file/fetch/144492831/bach_cantata_147_piano.pdf
- https://uploads.strikinglycdn.com/files/25bfbb55-58e7-4d77-9a95-14aaedd8f636/devilbiss_5hp_60_gallon_air_compressor_parts.pdf
- https://uploads.strikinglycdn.com/files/24af3ada-458d-4799-8517-e451b223bf72/journal_of_alloys_and_compounds_template.pdf
- https://vizudenorip.weebly.com/uploads/1/3/4/6/134674315/cc8f438240317a7.pdf
- https://uploads.strikinglycdn.com/files/8ba0f425-0e21-433e-bbcf-045863f38b1f/what_did_pharaohs_do_in_their_daily_life.pdf
- https://uploads.strikinglycdn.com/files/edca7ecb-70f0-4ce9-b466-406a2c9c2ce5/12303971635.pdf
- https://uploads.strikinglycdn.com/files/05cb7677-3975-4d66-96d6-3db085c1a993/gakezodu.pdf
- https://uploads.strikinglycdn.com/files/73e70804-7a25-45f3-9416-0676644da803/200_gramos_a_tazas_harina.pdf
- http://kosubufegu.pbworks.com/f/gta_5_crack_apk.pdf
- https://uploads.strikinglycdn.com/files/3acf2563-cf96-428b-8f8b-8c300310c25a/17148883306.pdf
- http://lezakoliz.pbworks.com/f/atmananda_krishna_menon_books.pdf
- https://uploads.strikinglycdn.com/files/01b4f1a1-3fdd-402c-8e4f-1b3d769e570c/lean_six_sigma_certification_online_university.pdf
- https://uploads.strikinglycdn.com/files/3aaf3a7c-8533-4d81-a3ce-45b355604645/dominos_garlic_sauce_ingredients_uk.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- oniceh.ru
- wuranosa.pbworks.com
- kilavolofijon.weebly.com
- vomokig.pbworks.com
- uploads.strikinglycdn.com
- rujuboxu.pbworks.com
- ridelox.pbworks.com
- lulimogosan.pbworks.com
- vizudenorip.weebly.com
- kosubufegu.pbworks.com
- lezakoliz.pbworks.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report