MALICIOUS — leladigiw-papopa.pdf
MALICIOUS — leladigiw-papopa.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 5 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
05d8befbe68632946d1fdde22d09b593dc31c686740f4bcdd29511657213160a - SHA-1:
128127e5f85d20de38d9a44fc92158e58478d3ad - MD5:
433b3e0b4d70fd72201916c20a4dbb81 - ssdeep:
1536:RDfknyuBZimWMXoWMKyLcQAXQ0yWu70+hdgYfFhfv8UzaExPnd1:MZi1MYW8gXQ0yWehdgYDfztxPj - TLSH:
T11238D0F3109BCCCC7B8B1B536AB712186186E74D723297F45488772CC4B826EAF50952 - Submitted as: leladigiw-papopa.pdf
- File type: pdf · Size: 80182 bytes
- Verdict: malicious (94/100)
Detections (5 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!433B3E0B4D70
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: https://574dee49-ee40-4737-ae02-340ce2b26f9d.filesusr.com/ugd/b44cf7_905c88a9318c47cbb05eb129decdb445.pdf?index=true - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: http://jefozogez.66ghz.com/47241223080.pdf, http://komozazene.getenjoyment.net/bharat_acharya_microprocessor_book.pdf, http://keluzizizeroki.getenjoyment.net/velobilux.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://feedproxy.google.com/~r/wb/ENAH/~3/B9wesDdUo4k/wb?keyword=what%20is%20the%20easiest%20way%20to%20learn%20dutch
- http://jefozogez.66ghz.com/47241223080.pdf
- http://komozazene.getenjoyment.net/bharat_acharya_microprocessor_book.pdf
- http://keluzizizeroki.getenjoyment.net/velobilux.pdf
- http://nenonazuf.scienceontheweb.net/gosuxogi.pdf
- https://cdn.sqhk.co/satidaruxami/gehggcC/77071360594.pdf
- http://bufagefitazi.rf.gd/65076539768.pdf
- https://574dee49-ee40-4737-ae02-340ce2b26f9d.filesusr.com/ugd/b44cf7_905c88a9318c47cbb05eb129decdb445.pdf?index=true
- http://solifixogalek.mypressonline.com/business_plan_elements.pdf
- http://eferevole.com/halloween_coordinate_graphing_worksheetx6wqq.pdf
- https://e5720c39-3c1c-4a52-9be9-509675281b5a.filesusr.com/ugd/0010c8_56ad6c7dbe78431f91e20ceb0e410c84.pdf?index=true
- https://d2faa26e-66ca-44cd-8f84-883624a71019.filesusr.com/ugd/dbbfd0_c3c2db75d8d644a590903e67a78b752b.pdf?index=true
- http://turitize.rf.gd/how_to_set_daylight_savings_on_g_shock.pdf
- http://craftsmansmetics.com/proform_exercise_bike_ratingsbt46z.pdf
- http://supportcopyright.net/30736195997j7xyt.pdf
- http://tososite.onlinewebshop.net/one_of_us_is_lying_audiobook_google_drive.pdf
- http://xiwupulo.medianewsonline.com/kjv_bible_verses_about_loved_ones_in_heaven.pdf
- https://c9254e9e-0e71-498a-8384-ab4c929b52b4.filesusr.com/ugd/0699ff_d582941c24414de88409dfb5dc740bb2.pdf?index=true
- https://cdn.sqhk.co/jigavozef/slxgegc/turbo_drag_race_scene.pdf
- http://savagit.rf.gd/fuvitivedekanawibumamu.pdf
- http://zonerokemub.getenjoyment.net/libro_de_historia_universal_contemporanea_1_bachillerato.pdf
- http://vujuvisesakok.myartsonline.com/fevatobazisamolidig.pdf
- http://jazeforip.22web.org/how_do_i_recover_my_facebook_email.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
Embedded domains
- feedproxy.google.com
- jefozogez.66ghz.com
- komozazene.getenjoyment.net
- keluzizizeroki.getenjoyment.net
- nenonazuf.scienceontheweb.net
- cdn.sqhk.co
- 574dee49-ee40-4737-ae02-340ce2b26f9d.filesusr.com
- solifixogalek.mypressonline.com
- eferevole.com
- e5720c39-3c1c-4a52-9be9-509675281b5a.filesusr.com
- d2faa26e-66ca-44cd-8f84-883624a71019.filesusr.com
- craftsmansmetics.com
- supportcopyright.net
- tososite.onlinewebshop.net
- xiwupulo.medianewsonline.com
- c9254e9e-0e71-498a-8384-ab4c929b52b4.filesusr.com
- zonerokemub.getenjoyment.net
- vujuvisesakok.myartsonline.com
- jazeforip.22web.org
- www.w3.org
- purl.org
- ns.adobe.com
- bufagefitazi.rf.gd
- turitize.rf.gd
- savagit.rf.gd
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report