MALICIOUS — 4170d94626.pdf
MALICIOUS — 4170d94626.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 5 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
fc65c51db968a0456eddf16bdb3f953fec16327af63e1746411318d03a13fc91 - SHA-1:
60d0cc4fef56d5377bfb3fa58479f6a459ed0ac1 - MD5:
2146f62e3822f05a324082c08b34e09d - ssdeep:
1536:7KL/3tUNA+XwCWUDp3dNPcXbDX2DhpRPnU7Xyp6UbZQamGNioWggm5Gg:+aNAAwCWEXPWP2DhpRPWCp6gmGNioWgR - TLSH:
T18C38CFF321DBDC4C7BCA6B436CBB65686486E7C4313297A4594CBA5CC47C6AD7E20220 - Submitted as: 4170d94626.pdf
- File type: pdf · Size: 80947 bytes
- Verdict: malicious (96/100)
Detections (5 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!2146F62E3822
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: https://uploads.strikinglycdn.com/files/9561e2f3-a7d3-42d4-8c35-9acd297ac90a/how_to_turn_on_a_tappan_electric_oven.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://ponafet.ru/wb?keyword=proform%20hybrid%20trainer%20pro%20assembly, https://gevaboru.weebly.com/uploads/1/3/4/6/134685165/7667340.pdf, https://98cdd5c5-c43e-49eb-9373-39517e896cbb.filesusr.com/ugd/90661f_b1f208b66c1e486cab8c424eb0963cdc.pdf?index=true - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ponafet.ru/wb?keyword=proform%20hybrid%20trainer%20pro%20assembly
- https://gevaboru.weebly.com/uploads/1/3/4/6/134685165/7667340.pdf
- https://98cdd5c5-c43e-49eb-9373-39517e896cbb.filesusr.com/ugd/90661f_b1f208b66c1e486cab8c424eb0963cdc.pdf?index=true
- https://lovefuzabuzonif.weebly.com/uploads/1/3/4/1/134109130/zolis.pdf
- https://23da7c74-6e14-424a-b22a-901aa35eafb1.filesusr.com/ugd/9cc572_55b69d2735974d3bb32f24864032107d.pdf?index=true
- https://1a2149e7-ca7f-4e7c-a584-0e483de6f3af.filesusr.com/ugd/9219f8_1a6b730d291943cdb9ab4627e5c6a264.pdf?index=true
- http://republvinb.fun/maccready_fallout_4_companion_guide8wwfe.pdf
- https://3d3b31fc-6152-41c7-b1d4-a4af3afcce63.filesusr.com/ugd/3f8d85_1057469b847a46b7917e951cde583435.pdf?index=true
- https://uploads.strikinglycdn.com/files/9561e2f3-a7d3-42d4-8c35-9acd297ac90a/how_to_turn_on_a_tappan_electric_oven.pdf
- https://a24bc4ef-4ee2-4fae-af0c-c9fea810b245.filesusr.com/ugd/67d96c_2d8f9168c2b342dcb8658284e76a9a59.pdf?index=true
- https://1c985592-4fe2-425a-b8d2-7dc24782370c.filesusr.com/ugd/a13bc2_dfddf23135f2435d948b16a06747066c.pdf?index=true
- https://86cafecd-0af7-43e6-b578-14605c742a6c.filesusr.com/ugd/c4ddd0_ed48f58090294d30a03923fd3f1d31c2.pdf?index=true
- https://uploads.strikinglycdn.com/files/9444b5d9-b815-4190-89c9-f57cc3bf2a7f/xadekaxarexe.pdf
- https://7f1d4f38-7308-4051-b389-b8ed31312188.filesusr.com/ugd/e948c1_e66afeb0e17b400089000e8ad99d52d2.pdf?index=true
- https://17673d3b-e5d0-4e0e-8211-f079fadf35f5.filesusr.com/ugd/13ae68_e7c8a1bf4e9248519f0903137b6f35f0.pdf?index=true
- https://xarugowa.weebly.com/uploads/1/3/4/7/134733051/112272.pdf
- https://uploads.strikinglycdn.com/files/1dc64f3c-4273-422a-8bdf-084bdd1dc319/how_does_pain_affect_the_body.pdf
- https://uploads.strikinglycdn.com/files/6db68a08-13a7-4e1f-89eb-3bc7444dc5c5/4078548649.pdf
- https://d0bf7e8b-5449-41c0-93e9-161603c0719f.filesusr.com/ugd/197ed4_8d724ca46d474cee86835b53a7013a42.pdf?index=true
- https://1a2149e7-ca7f-4e7c-a584-0e483de6f3af.filesusr.com/ugd/9219f8_e058f1b8801c4a3b8122b610f48f0dec.pdf?index=true
- http://docita.fun/fozanatatagedeniwuwobej0qgl.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- ponafet.ru
- gevaboru.weebly.com
- 98cdd5c5-c43e-49eb-9373-39517e896cbb.filesusr.com
- lovefuzabuzonif.weebly.com
- 23da7c74-6e14-424a-b22a-901aa35eafb1.filesusr.com
- 1a2149e7-ca7f-4e7c-a584-0e483de6f3af.filesusr.com
- republvinb.fun
- 3d3b31fc-6152-41c7-b1d4-a4af3afcce63.filesusr.com
- uploads.strikinglycdn.com
- a24bc4ef-4ee2-4fae-af0c-c9fea810b245.filesusr.com
- 1c985592-4fe2-425a-b8d2-7dc24782370c.filesusr.com
- 86cafecd-0af7-43e6-b578-14605c742a6c.filesusr.com
- 7f1d4f38-7308-4051-b389-b8ed31312188.filesusr.com
- 17673d3b-e5d0-4e0e-8211-f079fadf35f5.filesusr.com
- xarugowa.weebly.com
- d0bf7e8b-5449-41c0-93e9-161603c0719f.filesusr.com
- docita.fun
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report