MALICIOUS — normal_606d5ac587748.pdf
MALICIOUS — normal_606d5ac587748.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 5 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
0b0b3a0a8da4d76b24d47f6277757684c78ed68d4b7dc020ed580e203e3f3200 - SHA-1:
b51cbd1feb1e92ec55f348e3a4c076a2aaae2708 - MD5:
5eb06e889313eaafc4c462ff6086f184 - ssdeep:
1536:jIPp9ZCiEpiS6TddnGsGibjqcfEAu+0INOV3GPz9tDrtYZhoBH7qwbjQ5MW1A1:wLpAuddnGP+dN/zb4OJqNMWs - TLSH:
T17B39E0F3A19BCD4C74CADF531EE730AEA49AD3486432A7904588763DC17C36EAE20911 - Submitted as: normal_606d5ac587748.pdf
- File type: pdf · Size: 85428 bytes
- Verdict: malicious (94/100)
Detections (5 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!5EB06E889313
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: https://sovajavab.weebly.com/uploads/1/3/4/0/134041947/7223497.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://zajinet.ru/123?utm_term=best+photo+editor+app++for+mobile, https://sovajavab.weebly.com/uploads/1/3/4/0/134041947/7223497.pdf, https://2daccc73-8708-4113-a26a-4f38906335d9.filesusr.com/ugd/f65175_edec690b9de843f4adf3b983f5b32f9c.pdf?index=true - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://zajinet.ru/123?utm_term=best+photo+editor+app++for+mobile
- https://sovajavab.weebly.com/uploads/1/3/4/0/134041947/7223497.pdf
- https://2daccc73-8708-4113-a26a-4f38906335d9.filesusr.com/ugd/f65175_edec690b9de843f4adf3b983f5b32f9c.pdf?index=true
- https://dodapufil.weebly.com/uploads/1/3/0/8/130813701/7287843.pdf
- https://53ee2ee6-42da-4c96-954f-60f726bc8d53.filesusr.com/ugd/de2744_3828df38618a4207a679b81056ae6fb6.pdf?index=true
- http://fc-aromat.ru/nike_team_sponsorship_request208qt.pdf
- https://88966db1-4a83-4446-b941-f65022a6235f.filesusr.com/ugd/928e0f_c597b8c14a814a50b1adeb4f007f4daa.pdf?index=true
- http://vekvelo.ru/what_are_the_aims_of_rh_law1h25k.pdf
- http://xapesosav.epizy.com/carol_ann_duffy_mean_time_collection.pdf
- http://reduslim-shopofficial.site/60574104617qum3p.pdf
- https://ruzamoga.weebly.com/uploads/1/3/4/7/134761687/rabedudegexitafuvu.pdf
- http://bokakemipik.epizy.com/monadelphous_job_application_form.pdf
- https://teregurejojexol.weebly.com/uploads/1/3/4/8/134879353/zawodizum-tupijuzujeruxuw.pdf
- http://vosegigusuxiku.rf.gd/tuwufamizajizokowazed.pdf
- http://insurancecarusa.com/golugikokokudabfban.pdf
- https://xitodilizunew.weebly.com/uploads/1/3/4/1/134108755/zafutusigizole_mudabozavumuri_xogoregavomo_gojad.pdf
- https://6b137298-3864-41c5-aaa3-11744000c3c2.filesusr.com/ugd/b916f4_a4aaea97257440a98e766269e93cc63f.pdf?index=true
- http://muvubavove.epizy.com/zetexazalukixizewupa.pdf
- http://dejotiwamur.epizy.com/aplicativo_netflix_para_windows.pdf
- https://lurevovikofa.weebly.com/uploads/1/3/4/6/134693735/2727454.pdf
- http://varistop.site/download_game_blossom_blast_saga_mod_apk5wgch.pdf
- https://zavifojixu.weebly.com/uploads/1/3/3/9/133997579/5146781.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- zajinet.ru
- sovajavab.weebly.com
- 2daccc73-8708-4113-a26a-4f38906335d9.filesusr.com
- dodapufil.weebly.com
- 53ee2ee6-42da-4c96-954f-60f726bc8d53.filesusr.com
- fc-aromat.ru
- 88966db1-4a83-4446-b941-f65022a6235f.filesusr.com
- vekvelo.ru
- xapesosav.epizy.com
- reduslim-shopofficial.site
- ruzamoga.weebly.com
- bokakemipik.epizy.com
- teregurejojexol.weebly.com
- insurancecarusa.com
- xitodilizunew.weebly.com
- 6b137298-3864-41c5-aaa3-11744000c3c2.filesusr.com
- muvubavove.epizy.com
- dejotiwamur.epizy.com
- lurevovikofa.weebly.com
- varistop.site
- zavifojixu.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
- vosegigusuxiku.rf.gd
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report