MALICIOUS — 9631194.pdf
MALICIOUS — 9631194.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 5 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
05bc804a7d2d1dc744bbb4d15314e1cd1b470b618445ccc94245db91eef355a6 - SHA-1:
d031ad001eac95e4c126e8ab0d78fc6011c84844 - MD5:
e743bb511453f562cd7e4c543b5f603f - ssdeep:
1536:RXnEViOfqg+dPGqWFRflFcB56mhzUR1ZUYS/Do1Gdt48+S3rkwbY:xnei2zyPTmR3U5xqZUs1Gdt487r6 - TLSH:
T11538C0F310F3DD8C7B979F43B9FA1569148AE68DA02687A144C8676CC87C5AEBF10910 - Submitted as: 9631194.pdf
- File type: pdf · Size: 81561 bytes
- Verdict: malicious (94/100)
Detections (5 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!E743BB511453
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: https://676a7a22-5bec-432e-92e0-9d4a0a27851c.filesusr.com/ugd/a1fb72_5f590d38888744fb801462af7fd27444.pdf?index=true - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://dugedepap.ru/wb?keyword=how%20to%20change%20a%20dryer%20thermostat, https://cdn.sqhk.co/wulupumiwi/KifIb9U/zuratoluwi.pdf, https://cdn.sqhk.co/dokadajij/dqhhRxA/2000246330.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://dugedepap.ru/wb?keyword=how%20to%20change%20a%20dryer%20thermostat
- https://cdn.sqhk.co/wulupumiwi/KifIb9U/zuratoluwi.pdf
- https://cdn.sqhk.co/dokadajij/dqhhRxA/2000246330.pdf
- http://gunepevoxop.66ghz.com/8434567126.pdf
- https://676a7a22-5bec-432e-92e0-9d4a0a27851c.filesusr.com/ugd/a1fb72_5f590d38888744fb801462af7fd27444.pdf?index=true
- http://lawedeg.rf.gd/virginia_state_corporation_commission_llc_forms.pdf
- https://cdn-cms.f-static.net/uploads/4530910/normal_601aefb5ac3a4.pdf
- https://cdn-cms.f-static.net/uploads/4456984/normal_600c82b312987.pdf
- http://tolizidusinakil.22web.org/devexpress_reports_demo_winforms.pdf
- https://47ab6ce1-aee6-4086-a8e7-31fe393d2411.filesusr.com/ugd/afbef4_3c759ca3a4b64fb6ba5e8a27e9f7c2d5.pdf?index=true
- https://cdn-cms.f-static.net/uploads/4373519/normal_603bd76a9001a.pdf
- https://2cc3dcad-61c1-4442-8662-ca5be7cd8672.filesusr.com/ugd/71b93f_1ae1d985cb35428d843f5f25fcaff349.pdf?index=true
- https://cdn.sqhk.co/filovosa/ejcthEV/harvard_business_review_costco.pdf
- http://lexojowal.epizy.com/domain_driven_design_evans.pdf
- https://cdn-cms.f-static.net/uploads/4446633/normal_5fdc1c5fc7c12.pdf
- https://cdn.sqhk.co/vuwewiwudesi/YzirkjA/53724930197.pdf
- https://6c8027e1-9878-41b3-a9ef-32ba2b6bcd02.filesusr.com/ugd/185811_4ecff627b4dc4cfdae204b562bfdd055.pdf?index=true
- https://s3.amazonaws.com/zalomi/acrylic_glazing_sheet_b_q.pdf
- https://s3.amazonaws.com/wizitifowubux/nc_durable_power_of_attorney_form_2019.pdf
- https://static.s123-cdn-static.com/uploads/4393626/normal_6002e9056371a.pdf
- https://s3.amazonaws.com/forupokisip/47705293261.pdf
- https://cdn.sqhk.co/zisujidixa/eQWdSgc/vasukiwinurezoja.pdf
- https://b20aee1f-b1b7-4e4e-be5e-d884e4ece670.filesusr.com/ugd/10e3af_aedeb5a96b58496696bc7d6e7d9c4ab3.pdf?index=true
- https://s3.amazonaws.com/dazutun/98820340328.pdf
- https://static.s123-cdn-static.com/uploads/4459175/normal_5fe0d9f3d1f88.pdf
Embedded domains
- dugedepap.ru
- cdn.sqhk.co
- gunepevoxop.66ghz.com
- 676a7a22-5bec-432e-92e0-9d4a0a27851c.filesusr.com
- cdn-cms.f-static.net
- tolizidusinakil.22web.org
- 47ab6ce1-aee6-4086-a8e7-31fe393d2411.filesusr.com
- 2cc3dcad-61c1-4442-8662-ca5be7cd8672.filesusr.com
- lexojowal.epizy.com
- 6c8027e1-9878-41b3-a9ef-32ba2b6bcd02.filesusr.com
- s3.amazonaws.com
- static.s123-cdn-static.com
- b20aee1f-b1b7-4e4e-be5e-d884e4ece670.filesusr.com
- www.w3.org
- purl.org
- ns.adobe.com
- lawedeg.rf.gd
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report