MALICIOUS — 10314258646.pdf
MALICIOUS — 10314258646.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (98/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
e9a53af112f94be4f9079d292df675e8d0e9167958c597967135f0b578c33cfd - SHA-1:
8674750a9e9ed573b26a3d2d0a6c65c240f57077 - MD5:
399f68c9b30b83e8af6184435fee30c4 - ssdeep:
1536:SS2i7uTWh/xR6j28OPKEPKRjEscaicIc0+vvxyguwNEg/fYhVHwh+8:n7uTWTR228OPKwKasLvxhuQfYhVHwv - TLSH:
T1A136C0F72143CD4C7B862F83AFBA40155095D2CC3126E2A964C8A71DD9BCAEE3E50552 - Submitted as: 10314258646.pdf
- File type: pdf · Size: 66784 bytes
- Verdict: malicious (98/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 98/100 is the fusion of 6 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: https://static.s123-cdn-static.com/uploads/4413563/normal_5fcf9505b43c3.pdf - network signal, weight 0.70, confidence 0.80
- Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - Embedded network infrastructure: https://traffmen.ru/strik?utm_term=red+crucible+firestorm+download+pc, https://static.s123-cdn-static.com/uploads/4413563/normal_5fcf9505b43c3.pdf, https://static.s123-cdn-static.com/uploads/4421611/normal_5fc9014b18861.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://traffmen.ru/strik?utm_term=red+crucible+firestorm+download+pc
- https://static.s123-cdn-static.com/uploads/4413563/normal_5fcf9505b43c3.pdf
- https://static.s123-cdn-static.com/uploads/4421611/normal_5fc9014b18861.pdf
- https://static.s123-cdn-static.com/uploads/4388613/normal_5fcc71ffb6bb3.pdf
- https://uploads.strikinglycdn.com/files/06250152-6a04-463f-b27c-51a6a326ffd5/how_to_implement_lean_manufacturing_download.pdf
- https://cdn-cms.f-static.net/uploads/4452594/normal_5fbd648579356.pdf
- https://static1.squarespace.com/static/5fc28637c89e1c4b8fc8d350/t/5fc6b2043570fb44d1f08b15/1606857222319/car_driving_school_simulator_mod_apk_android_1.pdf
- https://cdn-cms.f-static.net/uploads/4402938/normal_5fb4b3a83043c.pdf
- https://static.s123-cdn-static.com/uploads/4407084/normal_5fc735f8c49cc.pdf
- https://static1.squarespace.com/static/5fc6cf4a579eee3ae0699cf0/t/5fcf2e4910aae775716b7fba/1607413322404/5455118545.pdf
- https://uploads.strikinglycdn.com/files/9f80c93c-8e4d-4ab1-a0a5-57bab8f1292b/89343294466.pdf
- https://static1.squarespace.com/static/5fc0f769ec917750a3d83c85/t/5fca39f4cf87d0256ff745aa/1607088628812/vaxowezevewozegofoxog.pdf
- https://cdn-cms.f-static.net/uploads/4401540/normal_5f909e8b94cb8.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- traffmen.ru
- static.s123-cdn-static.com
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- static1.squarespace.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report