MALICIOUS — 976724.pdf
MALICIOUS — 976724.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 5 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
ceb5bbad920b0fda28da224d39710da8065fc90458234076d3c8b6b5e784b468 - SHA-1:
b24700716f54d92d7a4d9fee9a4cba541be830ca - MD5:
f0630e45c19e11046a0c5120aefcbff9 - ssdeep:
1536:SZdGcK7XzHzKbcx/miVQ3PMWNrC1QImAYt21hGhpc8oO7:YGffHzKbco30qCOjAY83Ghyc - TLSH:
T13838E0F771A3CE9C73CB5B5728BB1169719AE68C62308B904488762CC8BC75D6D50882 - Submitted as: 976724.pdf
- File type: pdf · Size: 84127 bytes
- Verdict: malicious (96/100)
Detections (5 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!F0630E45C19E
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: https://static.s123-cdn-static.com/uploads/4489241/normal_5ff7bbf27856b.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://maypoin.ru/wb?keyword=dmaic%20methodology%20template%20excel, https://static.s123-cdn-static.com/uploads/4489241/normal_5ff7bbf27856b.pdf, http://nudistoff.club/82876202816ogdzw.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://maypoin.ru/wb?keyword=dmaic%20methodology%20template%20excel
- https://s3.amazonaws.com/waduzirader/68083128755.pdf
- https://static.s123-cdn-static.com/uploads/4489241/normal_5ff7bbf27856b.pdf
- http://nudistoff.club/82876202816ogdzw.pdf
- http://giveaway2020.info/vekepaboupiw.pdf
- http://soldonlittleton.com/abridged_version_of_a_christmas_carol52zmi.pdf
- http://groby-ritual.online/vag_comwupo0.pdf
- https://cdn-cms.f-static.net/uploads/4428335/normal_5fdc2b6333f48.pdf
- http://gofosuxubajo.epizy.com/jonafomajiwujolawifekaman.pdf
- http://mandarins.space/druid_boomkin_guide_3._3._5c2iyb.pdf
- http://jipuvojenibomig.22web.org/liwukitilinebuxopomulem.pdf
- http://topazipimobol.epizy.com/abraham_lincoln_movie_300mb.pdf
- http://fruits-summer.fun/99809050162lhywf.pdf
- https://belinadojo.weebly.com/uploads/1/3/1/6/131607131/8882942.pdf
- http://card2card-perevod24.site/ball_on_long_rope_dog_toyxurl7.pdf
- http://nekemepomisares.22web.org/rupovanig.pdf
- https://static.s123-cdn-static.com/uploads/4481053/normal_60034dcef369e.pdf
- http://nibumuxadata.66ghz.com/85348681432.pdf
- https://static.s123-cdn-static.com/uploads/4486042/normal_5ff273af47b48.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- maypoin.ru
- s3.amazonaws.com
- static.s123-cdn-static.com
- nudistoff.club
- giveaway2020.info
- soldonlittleton.com
- groby-ritual.online
- cdn-cms.f-static.net
- gofosuxubajo.epizy.com
- mandarins.space
- jipuvojenibomig.22web.org
- topazipimobol.epizy.com
- fruits-summer.fun
- belinadojo.weebly.com
- card2card-perevod24.site
- nekemepomisares.22web.org
- nibumuxadata.66ghz.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report