MALICIOUS — normal_6022ceb117497.pdf
MALICIOUS — normal_6022ceb117497.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 5 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
cf785c7c1a9f3d33660b68e96e12c8d1dc6d950035942188e99229720c5cde7f - SHA-1:
754a81b4d605534d8631dc0558330f7b3c1ddcf6 - MD5:
3049e2bff2c93db3484352ea76f3ca17 - ssdeep:
1536:rEdQu+ajNpkx+lruxldHPK+nt+RAwYXYw9ildtC10nzWvzV+M3t2:QdQuPJ6+tuvdHxn0y9ildc10nzMFA - TLSH:
T18C38D0F335ABDD8C2FCA9B53A97A20AC7489C6886132BB904088B63CD6755FD7D10590 - Submitted as: normal_6022ceb117497.pdf
- File type: pdf · Size: 81348 bytes
- Verdict: malicious (96/100)
Detections (5 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!3049E2BFF2C9
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: https://static.s123-cdn-static.com/uploads/4413002/normal_5fde841029146.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://bologen.ru/123?utm_term=hack+apk+download+pubg, http://skout.tech/manual_assembly_line_adalah791ts.pdf, http://chategratis.online/black_spiderman_wallpaper_in_hdo6602.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://bologen.ru/123?utm_term=hack+apk+download+pubg
- http://skout.tech/manual_assembly_line_adalah791ts.pdf
- http://chategratis.online/black_spiderman_wallpaper_in_hdo6602.pdf
- https://static.s123-cdn-static.com/uploads/4413002/normal_5fde841029146.pdf
- http://kraftmann.su/fefatatipexiwuriteff4rvt.pdf
- http://iclod.tech/zakixutofuwevuturivunimm53xn.pdf
- https://cdn.sqhk.co/jidulopavoji/hifWIif/vlc_for_android_tv_apkmirror.pdf
- https://static.s123-cdn-static.com/uploads/4488842/normal_5fc603b2b0994.pdf
- https://static.s123-cdn-static.com/uploads/4450336/normal_5fc76f1733557.pdf
- http://cosmeteca.com/74655496441rw1km.pdf
- https://static.s123-cdn-static.com/uploads/4500186/normal_5ff0ea5ad696c.pdf
- https://s3.amazonaws.com/fenatagazise/preposition_with_sentences.pdf
- http://trikolor.site/undead_walking_animationsvqvgi.pdf
- https://cdn-cms.f-static.net/uploads/4413707/normal_5fdc4936eeb15.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- bologen.ru
- skout.tech
- chategratis.online
- static.s123-cdn-static.com
- kraftmann.su
- iclod.tech
- cdn.sqhk.co
- cosmeteca.com
- s3.amazonaws.com
- trikolor.site
- cdn-cms.f-static.net
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report