MALICIOUS — 10818074812.pdf
MALICIOUS — 10818074812.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 5 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
f9f5b7bd904fe6e2d421147c41740d1f4ce63eccbcad06d8e46c1e026d62540d - SHA-1:
b55fd02a36fd90798334dd62f3fe92e71e9a0c05 - MD5:
10a6d84fb730cbe2ceb43bf624dfa51c - ssdeep:
1536:rAFtCiuXGrlNO/AUU+xqW1pCLu+BtWkcQTsqMeTbDnbb6/QrfL/:+4jUO/BUhA/+64bDna4rD - TLSH:
T12937CFF72283DD4C7A975B877EF62698504AD34D6121DBA15088B36CC4BC27E7F10A42 - Submitted as: 10818074812.pdf
- File type: pdf · Size: 70757 bytes
- Verdict: malicious (96/100)
Detections (5 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!10A6D84FB730
- Kaspersky (KVRT): HEUR:Hoax.PDF.Agent.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: https://static.s123-cdn-static.com/uploads/4466675/normal_5fde120664c83.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://catamma.ru/pbw?utm_term=fox+4+news+dfw, https://static.s123-cdn-static.com/uploads/4466675/normal_5fde120664c83.pdf, https://cdn-cms.f-static.net/uploads/4463287/normal_601f551174704.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://catamma.ru/pbw?utm_term=fox+4+news+dfw
- https://static.s123-cdn-static.com/uploads/4466675/normal_5fde120664c83.pdf
- https://cdn-cms.f-static.net/uploads/4463287/normal_601f551174704.pdf
- https://cdn-cms.f-static.net/uploads/4380219/normal_6028c101dc38e.pdf
- https://rovunulaji.weebly.com/uploads/1/3/4/5/134529744/wakupumor.pdf
- https://uploads.strikinglycdn.com/files/600e8bf9-abf3-49fa-8072-ac1ba7a8c4d5/45313746129.pdf
- http://zewalar.pbworks.com/w/file/fetch/144565398/ruvivebalenufe.pdf
- https://zenugewitewane.weebly.com/uploads/1/3/5/9/135960096/wemuzubekiko.pdf
- http://luwapoveduvi.pbworks.com/w/file/fetch/144659589/ap_chemistry_review_sheet.pdf
- https://gamorajemusuro.weebly.com/uploads/1/3/4/3/134316050/naleniwi.pdf
- http://disisopaz.pbworks.com/w/file/fetch/144704766/how_to_apply_cheats_in_gta_san_andreas_android.pdf
- https://tamalokumolegi.weebly.com/uploads/1/3/4/6/134656593/gukadosimajilapig.pdf
- https://cdn-cms.f-static.net/uploads/4393033/normal_602888a2d6b19.pdf
- https://lubipufubuk.weebly.com/uploads/1/3/4/5/134597980/7654769.pdf
- https://uploads.strikinglycdn.com/files/29c96563-f691-46fc-9a36-b1baf5eeec9d/gta_5_money_cheat_pc_offline_ps4.pdf
- https://uploads.strikinglycdn.com/files/9cdf3a2f-889d-47d1-bbcf-5d9eae6b5de1/is_the_taurus_pt111_g2_a_good_gun.pdf
- https://static.s123-cdn-static.com/uploads/4464869/normal_5fe530309df8e.pdf
- https://zagefejov.weebly.com/uploads/1/3/2/7/132710748/1642561.pdf
- https://dubelife.weebly.com/uploads/1/3/4/3/134379826/bufonot-luvewuvudikodu-rorukegixu.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- catamma.ru
- static.s123-cdn-static.com
- cdn-cms.f-static.net
- rovunulaji.weebly.com
- uploads.strikinglycdn.com
- zewalar.pbworks.com
- zenugewitewane.weebly.com
- luwapoveduvi.pbworks.com
- gamorajemusuro.weebly.com
- disisopaz.pbworks.com
- tamalokumolegi.weebly.com
- lubipufubuk.weebly.com
- zagefejov.weebly.com
- dubelife.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report