MALICIOUS — d7c70aef.pdf
MALICIOUS — d7c70aef.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 5 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
d34b0ae261219d3afd222f0854980ea14988df4793eab5474b10866161309127 - SHA-1:
14462008096f97a5011200db7cf33464c1bf2ea2 - MD5:
fbe2416483abca3426d65343b7cd6153 - ssdeep:
1536:VvJTK6S+yPFLPOITZwi2Qq9z6XfM7oDFt0pqCxAyEkbqxEJb2E1BrevdjWg7Gwvv:pO+EHTZK0fGyt0f+mGEJKbOwgY/ - TLSH:
T1F137BFF361ABCE9C7B8B6F53FDE72168254EC7846471AAA14088776D807C3AD2D10A11 - Submitted as: d7c70aef.pdf
- File type: pdf · Size: 76491 bytes
- Verdict: malicious (96/100)
Detections (5 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!FBE2416483AB
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: https://static.s123-cdn-static.com/uploads/4391620/normal_5fff395f5d0af.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://mezovuduw.ru/wb?keyword=cellular%20respiration%20lab%20answers, https://fivujage.weebly.com/uploads/1/3/4/3/134316273/vedunolajo_romamu_jukule_gegexigifota.pdf, https://uploads.strikinglycdn.com/files/a355f2a9-2274-4499-ad47-b5b0c81b2328/tegawibemuriwuzemukok.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://mezovuduw.ru/wb?keyword=cellular%20respiration%20lab%20answers
- https://fivujage.weebly.com/uploads/1/3/4/3/134316273/vedunolajo_romamu_jukule_gegexigifota.pdf
- https://s3.amazonaws.com/mipeboro/1527460288.pdf
- https://uploads.strikinglycdn.com/files/a355f2a9-2274-4499-ad47-b5b0c81b2328/tegawibemuriwuzemukok.pdf
- https://s3.amazonaws.com/belapawerezuju/12855946093.pdf
- https://cdn-cms.f-static.net/uploads/4415525/normal_6015d0f642c0e.pdf
- https://uploads.strikinglycdn.com/files/bb08539f-b639-4dd8-bbf1-57a1b19ff09a/72787877244.pdf
- https://s3.amazonaws.com/loxopudizus/shooting_games_for_pc_highly_compressed.pdf
- https://uploads.strikinglycdn.com/files/2ed9772b-ccb8-453b-b54c-433573b34723/97292639512.pdf
- https://uploads.strikinglycdn.com/files/692f293a-da37-4b8a-a0e4-44ac0746f6ed/56081710834.pdf
- https://cdn-cms.f-static.net/uploads/4410459/normal_606c821125516.pdf
- https://s3.amazonaws.com/guvovigo/video_star_pro_apk.pdf
- https://uploads.strikinglycdn.com/files/5fb73d2d-7004-406a-99a5-9152d7a2c213/gre_quantitative_practice_test_with_answers.pdf
- https://static.s123-cdn-static.com/uploads/4391620/normal_5fff395f5d0af.pdf
- https://cdn-cms.f-static.net/uploads/4498971/normal_606c4ab304b67.pdf
- https://cdn-cms.f-static.net/uploads/4453900/normal_6052bbae231fe.pdf
- https://uploads.strikinglycdn.com/files/7cba8caa-09c1-4732-8d90-88b50468af4f/white_tiger_pictures_free.pdf
- https://uploads.strikinglycdn.com/files/6dbb1825-a7b8-4b8c-bc2c-e312a813e562/91275354935.pdf
- https://s3.amazonaws.com/bisiku/totaguzegoj.pdf
- https://wibixebaroz.weebly.com/uploads/1/3/1/8/131856543/2454195.pdf
- https://raputaluwim.weebly.com/uploads/1/3/1/6/131606275/nujozokafadudo-dupokezuge-tanoj-lubuz.pdf
- https://cdn-cms.f-static.net/uploads/4410201/normal_604f23fee1c52.pdf
- https://cdn-cms.f-static.net/uploads/4385634/normal_5fd63b186ab3d.pdf
- https://uploads.strikinglycdn.com/files/3fa7114b-5ee1-4e28-b9c1-644d1ce64f7f/basic_english_grammar_in_hindi.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- mezovuduw.ru
- fivujage.weebly.com
- s3.amazonaws.com
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- static.s123-cdn-static.com
- wibixebaroz.weebly.com
- raputaluwim.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report