MALICIOUS — 6842207.pdf
MALICIOUS — 6842207.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
ec7a990e131f3c6a79f8d1162b632ae460e928795ebb6d740d03ee9588b8dc7c - SHA-1:
8a0613a0b51855bcce92ad8e4f3cbc638ebb3f17 - MD5:
b7856ae2736d2b381c5f9e0aff7dd435 - ssdeep:
1536:s/64rZNPLBOK1wbRlf9MEv8WpTTZMHAJzSXTNukP0UEeKktqq7kTM98t+KFa/g:aZNDBqvlt8WpGISpukP0UVth7198t+8h - TLSH:
T11138D0F32247FDCCBB8B5B53AAE72828A489C2993732D65411C4FB6CC13C5AC2D11961 - Submitted as: 6842207.pdf
- File type: pdf · Size: 77659 bytes
- Verdict: malicious (96/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: https://static.s123-cdn-static.com/uploads/4402718/normal_5fc96199e4da3.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://gettraff.ru/wb?keyword=arugam%20bay%20surf%20guide, https://tetemubegogik.weebly.com/uploads/1/3/4/4/134443084/af496.pdf, https://static1.squarespace.com/static/5fc54dfe3dfdd95b60f249af/t/5fd1f307871f8c6e595ff70d/1607594761301/sonic_games_unblocked_super_smash_flash_2.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gettraff.ru/wb?keyword=arugam%20bay%20surf%20guide
- https://tetemubegogik.weebly.com/uploads/1/3/4/4/134443084/af496.pdf
- https://static1.squarespace.com/static/5fc54dfe3dfdd95b60f249af/t/5fd1f307871f8c6e595ff70d/1607594761301/sonic_games_unblocked_super_smash_flash_2.pdf
- https://s3.amazonaws.com/wazotojemov/acute_toxicity_testing.pdf
- https://lajezufil.weebly.com/uploads/1/3/4/6/134636359/gebaxa.pdf
- https://nosisakapu.weebly.com/uploads/1/3/4/7/134773138/bobujupo-towodajik-livezisiwobu.pdf
- https://cdn-cms.f-static.net/uploads/4365612/normal_5f8ce97fae7d1.pdf
- https://static1.squarespace.com/static/5fc0028ac14dfd36feec75cc/t/5fc8f9a67262e04a071718d9/1607006634414/forrest_gump_bubba_shrimp_monologue.pdf
- https://tevirilozarenov.weebly.com/uploads/1/3/2/6/132695732/niwoboke-kowemilinad-fuwumumamixe-fubebo.pdf
- https://s3.amazonaws.com/jonora/88466256388.pdf
- https://static.s123-cdn-static.com/uploads/4402718/normal_5fc96199e4da3.pdf
- https://s3.amazonaws.com/kesumasaka/north_college_canvas.pdf
- https://s3.amazonaws.com/vifusupegiza/64786285553.pdf
- https://s3.amazonaws.com/minegikukovel/58642188896.pdf
- https://s3.amazonaws.com/ginutu/31641903563.pdf
- https://s3.amazonaws.com/nemafu/sinanamupi.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- gettraff.ru
- tetemubegogik.weebly.com
- static1.squarespace.com
- s3.amazonaws.com
- lajezufil.weebly.com
- nosisakapu.weebly.com
- cdn-cms.f-static.net
- tevirilozarenov.weebly.com
- static.s123-cdn-static.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report