MALICIOUS — 6849931.pdf
MALICIOUS — 6849931.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 5 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
0a9893c238b4b7ade371d1b72d799dbc8ef8600dfb64d269949614a1fc26134d - SHA-1:
99d17f0ad5740f52c9a3f12d34caa406568d8c63 - MD5:
a6ad5fc9b49d26db752b4d34119de99d - ssdeep:
1536:xqd7juusEN1wsYlkOTUr41HKnmxb8G1KcX+wXO0+bvOcnQQoJMIGy1hFf:od7JtYl1Arlmx4cB+UgQQoJMo7N - TLSH:
T12E38CFF39087DD4CB9C75F43ADE7259D2484E388303383A1558CBA2CA4382AE7F25961 - Submitted as: 6849931.pdf
- File type: pdf · Size: 82176 bytes
- Verdict: malicious (94/100)
Detections (5 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!A6AD5FC9B49D
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: https://0df6220b-9630-4647-aab6-0d9db69b9d59.filesusr.com/ugd/8b97dd_a48367aa31b44f01837000b22f3d586e.pdf?index=true - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: http://genusadnlo.space/, https://0df6220b-9630-4647-aab6-0d9db69b9d59.filesusr.com/ugd/8b97dd_a48367aa31b44f01837000b22f3d586e.pdf?index=true, http://evilcheats.fun/military_diet_list05r7i.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://feedproxy.google.com/~r/wb/ENAH/~3/bVCGPfG74RQ/wb?keyword=apc%20smart%20ups%201500%20battery%20replacement%20part%20number
- http://genusadnlo.space/
- https://0df6220b-9630-4647-aab6-0d9db69b9d59.filesusr.com/ugd/8b97dd_a48367aa31b44f01837000b22f3d586e.pdf?index=true
- http://evilcheats.fun/military_diet_list05r7i.pdf
- https://aece7fbc-7072-4055-9cfa-29e0da41b620.filesusr.com/ugd/e878fd_c97482544e14465197928cc57f968f9c.pdf?index=true
- https://fezimadi.weebly.com/uploads/1/3/4/4/134487715/sigado.pdf
- https://tabureribe.weebly.com/uploads/1/3/0/8/130813037/b6a6c2f4c8e454a.pdf
- https://8fa10226-37c2-454d-bd65-ced70ecbf0c4.filesusr.com/ugd/c34aa9_4458ed14264f42829d5bd5c1324110a0.pdf?index=true
- https://cb8582fb-ab29-4f13-bfd4-623ca244ab52.filesusr.com/ugd/d61b30_e9b70e56a8084280870e06d275198404.pdf?index=true
- https://1d942ef5-affb-47d8-8f99-70a3d187b733.filesusr.com/ugd/3283b0_4ec6f611e52046e098405e3ea6cb2cfa.pdf?index=true
- http://tafuxasomup.getenjoyment.net/zambia_national_anthem_lyrics.pdf
- http://rawoxaxevog.mygamesonline.org/how_long_does_it_take_for_an_atomic_clock_to_set.pdf
- http://sunmarkt.ru/how_to_increase_volume_on_nortel_phone0hc5n.pdf
- http://ionatr.fun/charam_sukh_web_series_freeo6jk1.pdf
- https://69c5641f-197a-42c1-bef1-daa502c1f1d7.filesusr.com/ugd/948cea_4b7853882f8e44da905cd49106fa7fd0.pdf?index=true
- https://uploads.strikinglycdn.com/files/42a4ea82-28c9-4cda-ba7c-dcee3c06024b/tulopafapolokagagap.pdf
- https://uploads.strikinglycdn.com/files/59ddda44-0669-4318-adb3-632297b35d9f/5376082376.pdf
- https://4be8a7ba-6c9a-47a4-99fc-a5961b41a404.filesusr.com/ugd/132250_541e3c1633234b47833829bd65935981.pdf?index=true
- https://pudavupotel.weebly.com/uploads/1/3/5/3/135335197/joxatuxadufofepigox.pdf
- http://copyright-rules-help.com/elgato_hd60_pro_device_not_foundx5xva.pdf
- http://najekaweza.onlinewebshop.net/60779366350.pdf
- https://5984e891-aecd-43e6-866f-efdb297c9c35.filesusr.com/ugd/403565_29cc4ba019304f50ad5b03e9af78a314.pdf?index=true
- https://c31d65df-273c-4bcc-acfb-7b03b0724b99.filesusr.com/ugd/e7e4a0_34461c4cf8244c23a285f599da036482.pdf?index=true
- http://xepuxesadara.mypressonline.com/vimekux.pdf
- http://seweripuwas.mywebcommunity.org/carper_s_understanding_the_law.pdf
Embedded domains
- feedproxy.google.com
- genusadnlo.space
- 0df6220b-9630-4647-aab6-0d9db69b9d59.filesusr.com
- evilcheats.fun
- aece7fbc-7072-4055-9cfa-29e0da41b620.filesusr.com
- fezimadi.weebly.com
- tabureribe.weebly.com
- 8fa10226-37c2-454d-bd65-ced70ecbf0c4.filesusr.com
- cb8582fb-ab29-4f13-bfd4-623ca244ab52.filesusr.com
- 1d942ef5-affb-47d8-8f99-70a3d187b733.filesusr.com
- tafuxasomup.getenjoyment.net
- rawoxaxevog.mygamesonline.org
- sunmarkt.ru
- ionatr.fun
- 69c5641f-197a-42c1-bef1-daa502c1f1d7.filesusr.com
- uploads.strikinglycdn.com
- 4be8a7ba-6c9a-47a4-99fc-a5961b41a404.filesusr.com
- pudavupotel.weebly.com
- copyright-rules-help.com
- najekaweza.onlinewebshop.net
- 5984e891-aecd-43e6-866f-efdb297c9c35.filesusr.com
- c31d65df-273c-4bcc-acfb-7b03b0724b99.filesusr.com
- xepuxesadara.mypressonline.com
- seweripuwas.mywebcommunity.org
- www.w3.org
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report