MALICIOUS — 67df95cd57c5fb0.pdf
MALICIOUS — 67df95cd57c5fb0.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 5 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
069a4b714966d5ab66e375ea261a2e2193ede9221cd6b7bb8abd388a4c228708 - SHA-1:
ca93f9c763f0b40ccf1fd939d52ee94575eb7bfa - MD5:
68f3bbbff2c3727179d6c43ee8371238 - ssdeep:
1536:tx+oTAjH5ObUQKWqz97lF2avZOHPjDucF90jKJ6uIDVd1baag0K4:GVFO4WqznTAHPXuw9kA6FVd1bv - TLSH:
T12438DFF3A1ABDE8D3A478B933CB71A9C658DD249B23293505494272CC4BC67DBF20461 - Submitted as: 67df95cd57c5fb0.pdf
- File type: pdf · Size: 83791 bytes
- Verdict: malicious (94/100)
Detections (5 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!68F3BBBFF2C3
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: https://307a23dc-bb60-4906-9a68-69e45957aa19.filesusr.com/ugd/d2057d_d72d7c8a72374d23bba7d2588ec6af5f.pdf?index=true - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://mezovuduw.ru/wb?keyword=eleanor%20and%20park%20book%20description, http://refajunabewatog.iblogger.org/fugifawuwunofede.pdf, http://glasshookahcatering.com/insinkerator_model_hot_1_parts_manualr8oba.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://mezovuduw.ru/wb?keyword=eleanor%20and%20park%20book%20description
- http://refajunabewatog.iblogger.org/fugifawuwunofede.pdf
- http://glasshookahcatering.com/insinkerator_model_hot_1_parts_manualr8oba.pdf
- https://cdn.sqhk.co/jaruxabal/Te6wjgi/tap_windows_adapter_v9_virus.pdf
- http://xozawuledol.iblogger.org/equality_act_2020_download.pdf
- https://307a23dc-bb60-4906-9a68-69e45957aa19.filesusr.com/ugd/d2057d_d72d7c8a72374d23bba7d2588ec6af5f.pdf?index=true
- http://sufalejadi.rf.gd/embed_servicenow_report_in_sharepoint.pdf
- http://donbetosstreettacos.com/gopeselibumowulijavej1snw1.pdf
- https://s3.amazonaws.com/gozilum/positive_effects_of_globalization.pdf
- http://fefezaw.rf.gd/adobe_acrobat_reader_9_standard_free.pdf
- https://cdn.sqhk.co/nipigagavadu/cghgVia/talking_shark_video.pdf
- https://cdn-cms.f-static.net/uploads/4370097/normal_6041bfa35084b.pdf
- https://static.s123-cdn-static.com/uploads/4423780/normal_5ff10964bd466.pdf
- https://cdn.sqhk.co/zipodumup/a9icxJK/skin_for_among_us_wallpaper_pink.pdf
- https://s3.amazonaws.com/vuliwisuwig/joseph_prince_communion_book.pdf
- https://d45380bd-a93d-4ef2-b2bd-4c7806d1f6db.filesusr.com/ugd/5d2cf3_fc46185a40d84a5294c163b142d0f7f6.pdf?index=true
- http://milanbeachs.space/28558761922u57h6.pdf
- https://4bf641bf-117a-4913-931f-55e49063997f.filesusr.com/ugd/5befcb_06c8ac48d7534ca4bb8f6692e15b8fe6.pdf?index=true
- https://cdn.sqhk.co/kezixowog/4Vgd353/weekend_warriors_mma_1._160_mod_apk.pdf
- http://successinyourlif.website/hamming_codefo635.pdf
- http://diwifesatikebak.epizy.com/59975902558.pdf
- https://cdn-cms.f-static.net/uploads/4470835/normal_60475950a0155.pdf
- https://cdn.sqhk.co/vavusiwi/ifjbMjd/20131488219.pdf
- https://add83a7c-0e31-48b3-928b-061d82ba9144.filesusr.com/ugd/205ae4_16438a720bf946a5916a2132a57ee356.pdf?index=true
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- mezovuduw.ru
- refajunabewatog.iblogger.org
- glasshookahcatering.com
- cdn.sqhk.co
- xozawuledol.iblogger.org
- 307a23dc-bb60-4906-9a68-69e45957aa19.filesusr.com
- donbetosstreettacos.com
- s3.amazonaws.com
- cdn-cms.f-static.net
- static.s123-cdn-static.com
- d45380bd-a93d-4ef2-b2bd-4c7806d1f6db.filesusr.com
- milanbeachs.space
- 4bf641bf-117a-4913-931f-55e49063997f.filesusr.com
- diwifesatikebak.epizy.com
- add83a7c-0e31-48b3-928b-061d82ba9144.filesusr.com
- www.w3.org
- purl.org
- ns.adobe.com
- sufalejadi.rf.gd
- fefezaw.rf.gd
- successinyourlif.website
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report