Report - 41304353790.pdf

PDF Suspicious Link PDF
ScreenShot
Created 2021.08.23 11:54 Machine s1_win7_x6402
Filename 41304353790.pdf
Type PDF document, version 1.4
AI Score Not founds Behavior Score
2.0
ZERO API file : mailcious
VT API (file) 13 detected (Phish, Gerphish, Camelot, Phishing, Malicious, score, Phisher, Gen2, CLASSIC, Static AI, Suspicious PDF)
md5 b90be1be290be860d8a5be2b40ca7c08
sha256 977ddc92e3c5a2bf4a144baf00568544d43914752687c8d8a230a1c95476831f
ssdeep 1536:dSIty9DDxVPLHcTQUEnYvbDmNe2HAiE8TG2gPQi1vk2N8kOltP1Q:LqDD3PDPUaYv3mNeJiE8s4i5k2b6t2
imphash
impfuzzy
  Network IP location

Signature (4cnts)

Level Description
watch File has been identified by 13 AntiVirus engines on VirusTotal as malicious
watch One or more non-whitelisted processes were created
notice Allocates read-write-execute memory (usually to unpack itself)
notice Uses Windows utilities for basic Windows functionality

Rules (2cnts)

Level Name Description Collection
warning PDF_Suspicious_Link_Z PDF Suspicious Link binaries (upload)
notice PDF_Format_Z PDF Format binaries (upload)

Network (0cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?

Suricata ids



Similarity measure (PE file only) - Checking for service failure