MALICIOUS — sixifewemivux.pdf
MALICIOUS — sixifewemivux.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 5 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
04a7928c1fa89217654d8b8baf83218474e4072d85e7a484e983105b62544a6f - SHA-1:
17f4e2b5293a6da695d2e0363833f29421ab07ad - MD5:
34d8b65ac475f236ddd690e71311c8d6 - ssdeep:
1536:yAy0hncM2Qd8bfmD9T9L31UcfMy2hYQYu8EqjIv2UulOrZ7HCI/:jcR6D7lDfoX+j+Jul0R5 - TLSH:
T10C38C0F341ABEE4C76A6BF436DAA129D208DE64C6133DB6411487B6DC4AC6BD7E10600 - Submitted as: sixifewemivux.pdf
- File type: pdf · Size: 83905 bytes
- Verdict: malicious (96/100)
Detections (5 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!34D8B65AC475
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: https://uploads.strikinglycdn.com/files/f3ab98be-e4af-45cd-895f-12db2be0a6cd/what_is_the_best_brand_for_stackable_washer_and_dryer.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://yafferge.ru/wb?keyword=the%20devil%20wears%20prada%20movie%20review, https://uploads.strikinglycdn.com/files/4c4708a6-57d5-42a5-b02f-323fc41882a2/71040420325.pdf, http://fashion-deals.xyz/19632979016soiyo.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://yafferge.ru/wb?keyword=the%20devil%20wears%20prada%20movie%20review
- https://uploads.strikinglycdn.com/files/4c4708a6-57d5-42a5-b02f-323fc41882a2/71040420325.pdf
- http://fashion-deals.xyz/19632979016soiyo.pdf
- https://b03e51a8-7171-48c0-94d6-e4c032e6f37f.filesusr.com/ugd/9421c8_ab2cf3d944364bb6ac27afb7f7ac034d.pdf?index=true
- https://cdn.sqhk.co/daboxazile/jW1hcER/uber_mexico_oficinas_corporativas.pdf
- https://uploads.strikinglycdn.com/files/f3ab98be-e4af-45cd-895f-12db2be0a6cd/what_is_the_best_brand_for_stackable_washer_and_dryer.pdf
- http://bnatural.space/4_pics_1_word_level_2604r1s8c.pdf
- http://misstourist.info/2014_honda_cr_v_service_manualcdluw.pdf
- https://15319a82-8c66-4906-b3c2-464277991f2b.filesusr.com/ugd/070acf_97dde8b9d6d7412091d88b3cc49c6de7.pdf?index=true
- https://d8ec88ce-93b1-4b83-b294-7016fd5b5063.filesusr.com/ugd/366252_7cba3da10331411c9a9e2b1bad213e32.pdf?index=true
- https://38f9ccf9-db33-4582-994d-0ea518e52d38.filesusr.com/ugd/368de4_2a47ef9235004ca6b89294064d28f7be.pdf?index=true
- http://hyipinvest.site/can_i_share_a_music_video_on_facebookz1ql1.pdf
- https://uploads.strikinglycdn.com/files/436551a5-c609-4e89-83c0-9c415ce07ab7/97530380427.pdf
- https://2ed821ec-8078-4e74-b11b-c5cec6a88262.filesusr.com/ugd/65e777_b9e1a475f4644c3c99c48d224b29eb80.pdf?index=true
- http://krepezh.guru/664700772959gljj.pdf
- https://d5bea983-5bca-41ba-aae6-6b688785cc77.filesusr.com/ugd/9ec29b_b5868b3db5d94bf08b5e36d5ccf4883d.pdf?index=true
- http://flymoney.net/142307837342vzoi.pdf
- http://azorocheat5.xyz/unlimited_high_speed_internet_service4t0gj.pdf
- https://uploads.strikinglycdn.com/files/bc545f06-9d45-4d2b-b358-7b786387e7a3/kelodekipifavudopu.pdf
- http://rollernefrit.xyz/the_art_of_seeing_aldous_huxley_audiobook4cv1d.pdf
- https://cdn.sqhk.co/xewiliwilax/jdkgiDu/infective_endocarditis_criteria_ppt.pdf
- https://cdn.sqhk.co/nobutowug/GijhaRA/16457056731.pdf
- https://uploads.strikinglycdn.com/files/91d23bfe-e4f2-4d81-86a4-ab53ac8ccdd3/rizakupedezeni.pdf
- https://cdn.sqhk.co/sarimotel/jhDmhg3/zombie_attack_java_games.pdf
- https://44eeb0f0-4dc9-4d8b-b3fd-cc7ace98e90e.filesusr.com/ugd/a083a1_0d7c40076d0d485c9067e10ca1a471ff.pdf?index=true
Embedded domains
- yafferge.ru
- uploads.strikinglycdn.com
- fashion-deals.xyz
- b03e51a8-7171-48c0-94d6-e4c032e6f37f.filesusr.com
- cdn.sqhk.co
- bnatural.space
- misstourist.info
- 15319a82-8c66-4906-b3c2-464277991f2b.filesusr.com
- d8ec88ce-93b1-4b83-b294-7016fd5b5063.filesusr.com
- 38f9ccf9-db33-4582-994d-0ea518e52d38.filesusr.com
- hyipinvest.site
- 2ed821ec-8078-4e74-b11b-c5cec6a88262.filesusr.com
- d5bea983-5bca-41ba-aae6-6b688785cc77.filesusr.com
- flymoney.net
- azorocheat5.xyz
- rollernefrit.xyz
- 44eeb0f0-4dc9-4d8b-b3fd-cc7ace98e90e.filesusr.com
- 734e8db3-b9db-457c-abaa-08c06218e7ae.filesusr.com
- www.w3.org
- purl.org
- ns.adobe.com
- krepezh.guru
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report