MALICIOUS — kezosi.pdf
MALICIOUS — kezosi.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
f5b9a4da7e58e0e266640d60eba0812e08caa648c1985b907f9b938ef473d4bd - SHA-1:
7b88a26a4b2bb9869b9f987d745665d578f1488c - MD5:
e03d7fe9021ac27129d98fce30361482 - ssdeep:
1536:d1h9uiyjwb4XUZz6cIIu0wk5O4qJUsq1Q7qZLy69AtBfYWe46t/VanA5t4hW7/qV:DhPyUUXUt6cIIub7qZmeQBfA46t9v48q - TLSH:
T14B3AD0F31297DC4C268B6B93A9B314687589E7C82533DF6044C8B6ACC4BC5BD6E15A80 - Submitted as: kezosi.pdf
- File type: pdf · Size: 92925 bytes
- Verdict: malicious (96/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: https://static.s123-cdn-static.com/uploads/4385437/normal_5fcf3e93e02f7.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://trafficel.ru/wb?keyword=status%20bar%20react%20native%20android, https://cdn-cms.f-static.net/uploads/4402517/normal_5fae3be8567be.pdf, https://uploads.strikinglycdn.com/files/c59fd666-273d-414d-8461-3200b3e8c9d9/74562527024.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://trafficel.ru/wb?keyword=status%20bar%20react%20native%20android
- https://s3.amazonaws.com/zoromexemuzid/bewetazazarener.pdf
- https://cdn-cms.f-static.net/uploads/4402517/normal_5fae3be8567be.pdf
- https://uploads.strikinglycdn.com/files/c59fd666-273d-414d-8461-3200b3e8c9d9/74562527024.pdf
- https://s3.amazonaws.com/zasepo/mubiviwupapolejekinedura.pdf
- https://cdn-cms.f-static.net/uploads/4499651/normal_5fb6b18fc90e9.pdf
- https://cdn-cms.f-static.net/uploads/4375708/normal_5fa1c89cb98a6.pdf
- https://s3.amazonaws.com/potofaw/lakexorazuposokurinidej.pdf
- https://static1.squarespace.com/static/5fc07dde27a199023ab34438/t/5fc1ae3d1972c46e3cddaaec/1606528573678/the_outer_worlds_the_illustrated_manual.pdf
- https://s3.amazonaws.com/lejivugeleguwod/bonunetemepawete.pdf
- https://static.s123-cdn-static.com/uploads/4385437/normal_5fcf3e93e02f7.pdf
- https://static1.squarespace.com/static/5fc16c877848ba205d1c3861/t/5fcf33ad798354522d0aa47e/1607414706423/pilot_salary_in_usa_2019.pdf
- https://static1.squarespace.com/static/5fc79cbd418d7934ac780470/t/5fc8e3f87ff5a343eb008b12/1607001081084/evowars._io_crazy_games.pdf
- https://static1.squarespace.com/static/5fc0c6a4a87939686407af5f/t/5fc136aaeaf37e3b64c80947/1606497963254/43991918310.pdf
- https://uploads.strikinglycdn.com/files/d104e2ac-2765-4785-9288-a7661015aafd/lowotozuxiguni.pdf
- https://s3.amazonaws.com/lodunixodetum/42019943339.pdf
- https://static1.squarespace.com/static/5fc0d57abd14ff0dd29c5223/t/5fc409d13485235c864424f0/1606683089440/63993583576.pdf
- https://static1.squarespace.com/static/5fc1a7b9084698658e639c4c/t/5fc31cb1e18c5c478e61bb8b/1606622385833/jon_z_ya_no_eres_mia_english_lyrics.pdf
- https://cdn-cms.f-static.net/uploads/4488807/normal_5faf8dc872ca1.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- trafficel.ru
- s3.amazonaws.com
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- static1.squarespace.com
- static.s123-cdn-static.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report