MALICIOUS — wheel_of_time_book_1_audiobook.pdf
MALICIOUS — wheel_of_time_book_1_audiobook.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 4 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
05a924e5d3aee6ffccba4ad99f3380a775ad59eaf98779c4359bcaf064ea9e8e - SHA-1:
76cb3b4291b40be275f350071c2cec83d8875a11 - MD5:
8582c3333a1f98399490a73feda87947 - ssdeep:
3072:NOrdqFDYKGKMLvjppe9GwBFFA4sudcn+X:NOr0F5G7DjppeI0FmLS - TLSH:
T1F33CE1F3019BCD8CBE89EF436DA63459608E9398A072EA54105D7A6CD47D2FE3E40D60 - Submitted as: wheel_of_time_book_1_audiobook.pdf
- File type: pdf · Size: 120791 bytes
- Verdict: malicious (94/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: https://b304dada-1952-41b2-af44-d16a3232bb3f.filesusr.com/ugd/c19c34_1371e430444447d5bdad7498edec8966.pdf?index=true - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://druttle.ru/strik?utm_term=wheel+of+time+book+1+audiobook, https://mejonozawus.weebly.com/uploads/1/3/4/0/134016798/4dc32e3f59439.pdf, http://jipinasin.epizy.com/blank_august_2019_calendar_printable.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://druttle.ru/strik?utm_term=wheel+of+time+book+1+audiobook
- https://mejonozawus.weebly.com/uploads/1/3/4/0/134016798/4dc32e3f59439.pdf
- http://jipinasin.epizy.com/blank_august_2019_calendar_printable.pdf
- https://uploads.strikinglycdn.com/files/e0d0e905-b2bc-45b0-9ada-2a05c5fbd50d/nabiwowimiwivuvi.pdf
- https://0f939073-77d1-4307-aaa8-42539c8515e3.filesusr.com/ugd/85c9df_647e64ede7fd485699714950c58c0072.pdf?index=true
- https://b304dada-1952-41b2-af44-d16a3232bb3f.filesusr.com/ugd/c19c34_1371e430444447d5bdad7498edec8966.pdf?index=true
- http://yandex-delivery.cc/us_military_phonetic_alphabet_chartjspkn.pdf
- https://592908bf-dd96-48cc-88d9-ffebbdd10d84.filesusr.com/ugd/f34823_78e2ed73d38540b898179e055b56f5b4.pdf?index=true
- http://tomandbxof.site/31814880513y179h.pdf
- https://ec8c99fd-5413-4e38-b6a0-2ccbba71fc6f.filesusr.com/ugd/de02f3_17a1631a4f44473193a632fe8d11bdf0.pdf?index=true
- https://56f9ebfc-1b58-4ccd-90b9-24793863e956.filesusr.com/ugd/0f3536_e5b7ff0eb6ec4d6faef33e82929a1c13.pdf?index=true
- https://uploads.strikinglycdn.com/files/8e8f2116-2faf-4742-a948-fca85202fccc/the_nightingale_and_the_rose_characters.pdf
- https://9f9bd9fa-00fe-4673-b34e-9a629881f524.filesusr.com/ugd/09273f_b4eb41e78c99445b97d861a0216cbafa.pdf?index=true
- https://uploads.strikinglycdn.com/files/5ebc6e2d-d821-445a-aaf8-ae5adb9535f4/what_does_the_word_listless_mean.pdf
- https://25f35837-e8ad-4357-b490-8f69bec4165a.filesusr.com/ugd/96c61c_b853b25088074cb4bc1c58804327a1cf.pdf?index=true
- http://mgacessoria.online/tifadalun05igi.pdf
- http://wupaxine.epizy.com/27471383416.pdf
- https://34570882-574e-4d25-8c0e-d8b9b6c2967f.filesusr.com/ugd/cb2bed_f4b66a09e72c425bbb7f569c5f2d10f8.pdf?index=true
- https://uploads.strikinglycdn.com/files/c83d00df-4496-407b-8947-693200108eba/sebexeziritijim.pdf
- http://jedafalakax.epizy.com/texas_instruments_ti-nspire_cx_cas_vs_hp_prime.pdf
- https://nagalijas.weebly.com/uploads/1/3/1/3/131398542/2834244.pdf
- https://gojamomer.weebly.com/uploads/1/3/2/8/132815882/b862e5c0f.pdf
- http://maluvovim.epizy.com/concept_of_balanced_scorecard.pdf
- https://papukelub.weebly.com/uploads/1/3/4/6/134666119/98299.pdf
- http://deroselewem.epizy.com/72495264942.pdf
Embedded domains
- druttle.ru
- mejonozawus.weebly.com
- jipinasin.epizy.com
- uploads.strikinglycdn.com
- 0f939073-77d1-4307-aaa8-42539c8515e3.filesusr.com
- b304dada-1952-41b2-af44-d16a3232bb3f.filesusr.com
- yandex-delivery.cc
- 592908bf-dd96-48cc-88d9-ffebbdd10d84.filesusr.com
- tomandbxof.site
- ec8c99fd-5413-4e38-b6a0-2ccbba71fc6f.filesusr.com
- 56f9ebfc-1b58-4ccd-90b9-24793863e956.filesusr.com
- 9f9bd9fa-00fe-4673-b34e-9a629881f524.filesusr.com
- 25f35837-e8ad-4357-b490-8f69bec4165a.filesusr.com
- mgacessoria.online
- wupaxine.epizy.com
- 34570882-574e-4d25-8c0e-d8b9b6c2967f.filesusr.com
- jedafalakax.epizy.com
- nagalijas.weebly.com
- gojamomer.weebly.com
- maluvovim.epizy.com
- papukelub.weebly.com
- deroselewem.epizy.com
- bokixewabukogu.weebly.com
- itfamily.info
- www.w3.org
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report