MALICIOUS — 322950.pdf
MALICIOUS — 322950.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
dfa1ca76f331470ac3ad7bb22e542b8b4727f712ec67835066f60d7e3aa86b9e - SHA-1:
b60b43bb64f3560c6217d47537c9c9539bcfd6ca - MD5:
6b91871363aa971adc27af9525dd8e71 - ssdeep:
3072:cKQHttqkTY+v7cJJadi0XJcMUWI4j6z18oO0qgp:J3ks0cJATUWI4qfq+ - TLSH:
T17B3DE0F301A7ED8DBAD69B07B8AA246C34CAD7447232EE9414C8776C887C6ED6C40561 - Submitted as: 322950.pdf
- File type: pdf · Size: 123806 bytes
- Verdict: malicious (94/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: http://mexicotop.xyz/wapopidudujr3bl.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://crophysi.ru/wb?keyword=monkey%20journey%20to%20the%20west%20book%20pdf, https://cdn.sqhk.co/jotepomi/orDhgRl/41931140164.pdf, http://ctuxuu.com/hamlet_act_5_study_guide_questions_ad1v86.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://crophysi.ru/wb?keyword=monkey%20journey%20to%20the%20west%20book%20pdf
- https://cdn.sqhk.co/jotepomi/orDhgRl/41931140164.pdf
- http://ctuxuu.com/hamlet_act_5_study_guide_questions_ad1v86.pdf
- http://kvyovk.xyz/60700124426hsryf.pdf
- http://noncomform.space/wuguxaril3zbed.pdf
- https://cdn.sqhk.co/razotefo/fGnyibb/offline_games_iphone_2019.pdf
- https://cdn.sqhk.co/zanudiwageg/jihjox3/vortex_cloud_gaming_mod_apk_2019.pdf
- https://cdn.sqhk.co/nudizodi/Mjbgghf/filenoduwila.pdf
- https://s3.amazonaws.com/fajetufekejo/advanced_level_physics_syllabus_tanzania.pdf
- http://boost-shop.xyz/2089714351cxje4.pdf
- https://s3.amazonaws.com/gedimuta/zobubitopawemudaretaku.pdf
- https://s3.amazonaws.com/nodetuxapabara/bollywood_actress_heroine_photo.pdf
- http://mexicotop.xyz/wapopidudujr3bl.pdf
- http://letnesil.xyz/what_is_the_most_famous_quote_by_franklin_d._roosevelt3l68k.pdf
- http://slamelina.website/nobisukomibuseniwuwiky29u.pdf
- http://idealica-tufficiale.website/attestation_format_for_signature_difference_cameo3qg3a.pdf
- https://s3.amazonaws.com/patilawasu/benzodiazepines_prescribing_guidelines_uk.pdf
- http://genusadnlo.space/standard_en55024_downloadi8s8a.pdf
- https://cdn.sqhk.co/xaxovowupofa/hjijihr/76938662341.pdf
- https://cdn.sqhk.co/dozumapufa/XNzgigj/23828989090.pdf
- http://volosaty100.xyz/xokopij1h3su.pdf
- http://krokoboko6.xyz/65574810035ou4ou.pdf
- https://cdn.sqhk.co/gufezitaxato/22pXnhc/stickman_backflip_killer_5_apk.pdf
- https://cdn.sqhk.co/sinemajud/chfWjae/85848250896.pdf
- http://laithub.pro/balupaginovuxizatirojewh1dzv.pdf
Embedded domains
- crophysi.ru
- cdn.sqhk.co
- ctuxuu.com
- kvyovk.xyz
- noncomform.space
- s3.amazonaws.com
- boost-shop.xyz
- mexicotop.xyz
- letnesil.xyz
- genusadnlo.space
- volosaty100.xyz
- krokoboko6.xyz
- laithub.pro
- www.w3.org
- purl.org
- ns.adobe.com
- slamelina.website
- idealica-tufficiale.website
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report