MALICIOUS — 519a61_db380140cfb4421aaee87267deac191e.pdf
MALICIOUS — 519a61_db380140cfb4421aaee87267deac191e.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 5 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
0cda5a256f102f95cf9ee7a33d753702e3b508a39d17e4af4e7e991e7c6451b1 - SHA-1:
fd499c89bf710b7713c2e90a8ffda30729a0955a - MD5:
f0744ad94e38980526911e5af7d45632 - ssdeep:
1536:vR5lTKMe2AvqmfUF9cLcFkdfYyz1uExoPgV58dtc:NKRNfUFFFyuExB5d - TLSH:
T1D737E0F7509BEE4C7F87AF832EA7156DA046D68820329B6004C53A6CC5BC2EE3F91551 - Submitted as: 519a61_db380140cfb4421aaee87267deac191e.pdf
- File type: pdf · Size: 74326 bytes
- Verdict: malicious (94/100)
Detections (5 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!F0744AD94E38
- Kaspersky (KVRT): HEUR:Hoax.PDF.Agent.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: https://933afb0c-60ca-4ff4-ba38-e7c804ca925d.filesusr.com/ugd/941881_44e586c9d8bd4e5dae53dc13d60d1eb0.pdf?index=true - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://nipisod.ru/wix?keyword=who+says+always+in+harry+potter, http://se-mrush.com/jutadilonixavedasiwosemoqi011.pdf, https://933afb0c-60ca-4ff4-ba38-e7c804ca925d.filesusr.com/ugd/941881_44e586c9d8bd4e5dae53dc13d60d1eb0.pdf?index=true - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://nipisod.ru/wix?keyword=who+says+always+in+harry+potter
- http://se-mrush.com/jutadilonixavedasiwosemoqi011.pdf
- https://933afb0c-60ca-4ff4-ba38-e7c804ca925d.filesusr.com/ugd/941881_44e586c9d8bd4e5dae53dc13d60d1eb0.pdf?index=true
- https://s3.amazonaws.com/pegebunov/77680814209.pdf
- https://s3.amazonaws.com/wajufifenoxuj/sherlock_holmes_crimes_and_punishments_trophy_guide.pdf
- http://fewuzefar.rf.gd/the_room_audience_participation_guide.pdf
- http://bepinutarefe.rf.gd/kalnirnay_calendar_july_2019.pdf
- http://20970907.net/kerudogebasatuvexa4a4zh.pdf
- https://s3.amazonaws.com/kikunojulejuj/tilidojapizalosozi.pdf
- http://shtangennstutkupitseychas.xyz/furovavapirawewuxitamdd0c8.pdf
- http://vekifurusib.22web.org/human_genetics_interpreting_pedigrees_worksheet_answers.pdf
- http://pagebake.com/sustainable_living_guide_austin_tx4xead.pdf
- https://34e2f0dc-0077-42bd-a047-efa2502e92af.filesusr.com/ugd/8a05ec_b290fc0ee8b04f2b982f4c8c31564a32.pdf?index=true
- http://romusamepoma.epizy.com/download_audio_bacaan_alquran_30_juz.pdf
- https://86908e24-11f3-43a1-9346-bf531f45ee0b.filesusr.com/ugd/97493d_e0498c53860747738ad9404acf426f8b.pdf?index=true
- http://dfds.in/math_problems_for_third_gradersihokw.pdf
- https://s3.amazonaws.com/zoluwivebiro/9994387718.pdf
- https://ce83042b-5faf-46b5-bcbb-9b4d05ec7d33.filesusr.com/ugd/a31856_e7239b33a97642d2a239b63c068b2c9f.pdf?index=true
- http://politach.com/2020_turkce_pop_mp3_indir70ned.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- nipisod.ru
- se-mrush.com
- 933afb0c-60ca-4ff4-ba38-e7c804ca925d.filesusr.com
- s3.amazonaws.com
- 20970907.net
- shtangennstutkupitseychas.xyz
- vekifurusib.22web.org
- pagebake.com
- 34e2f0dc-0077-42bd-a047-efa2502e92af.filesusr.com
- romusamepoma.epizy.com
- 86908e24-11f3-43a1-9346-bf531f45ee0b.filesusr.com
- dfds.in
- ce83042b-5faf-46b5-bcbb-9b4d05ec7d33.filesusr.com
- politach.com
- www.w3.org
- purl.org
- ns.adobe.com
- fewuzefar.rf.gd
- bepinutarefe.rf.gd
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report