MALICIOUS — 0ed7d046fece3098dbc1001b88d376c101e345c85a87a001f1d4f694ed74082f
MALICIOUS — 0ed7d046fece3098dbc1001b88d376c101e345c85a87a001f1d4f694ed74082f is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 4 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
0ed7d046fece3098dbc1001b88d376c101e345c85a87a001f1d4f694ed74082f - SHA-1:
059622d07a8705ea2f91736c6d5d3313185fa31c - MD5:
4cd27d098aa4007f713ab85826772c85 - ssdeep:
1536:yBGcp/0dvtAo0XSdMCBrkk+MrSDRZZK3MzPq927HuhHRfAW2WAvsSB5MxQPGbLlH:yb08oOo6kXQZg3E7HuhdAZ7USB5Mxp - TLSH:
T1593CE1F32087DD4D768B8B5329EB269DB189C6897032EA844589776DC4BC2FD7F14801 - Submitted as: 0ed7d046fece3098dbc1001b88d376c101e345c85a87a001f1d4f694ed74082f
- File type: pdf · Size: 115795 bytes
- Verdict: malicious (96/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: http://kokoxudalux.pbworks.com/w/file/fetch/144420255/33576515858.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://xajibur.ru/123?utm_term=allen+bradley+powerflex+4+manual+pdf+espa%25C3%25B1ol, https://zobujopexa.weebly.com/uploads/1/3/0/9/130969678/nozesosurilas.pdf, https://xorodipilubila.weebly.com/uploads/1/3/5/3/135311864/c2209c.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://xajibur.ru/123?utm_term=allen+bradley+powerflex+4+manual+pdf+espa%25C3%25B1ol
- https://zobujopexa.weebly.com/uploads/1/3/0/9/130969678/nozesosurilas.pdf
- https://xorodipilubila.weebly.com/uploads/1/3/5/3/135311864/c2209c.pdf
- http://zorisomofi.pbworks.com/w/file/fetch/144545151/what_is_intercession_prayer.pdf
- http://kokoxudalux.pbworks.com/w/file/fetch/144420255/33576515858.pdf
- https://dogamoduxex.weebly.com/uploads/1/3/4/4/134481485/bigozutuf_nekotebamurenol_sajas_mirefakumevo.pdf
- http://molitutolu.pbworks.com/f/17315317285.pdf
- https://fejawizekojiwi.weebly.com/uploads/1/3/1/4/131438151/a30bf7.pdf
- https://rurujopolobadez.weebly.com/uploads/1/3/4/4/134444805/xomeburit_magug_wazokerurisagig_zerugonotedekak.pdf
- https://uploads.strikinglycdn.com/files/752f240a-ab15-4848-9b08-68cb03eb6583/lego_mindstorms_ev4_building_instructions.pdf
- https://uploads.strikinglycdn.com/files/11a9fe23-5f89-4e81-9c14-b1a566c39d85/what_sd_card_for_samsung_galaxy_tab_a6.pdf
- https://cdn-cms.f-static.net/uploads/4444622/normal_60270d3c11af9.pdf
- http://xiwitanul.pbworks.com/w/file/fetch/144442953/fetilovinujipexe.pdf
- http://wepoline.pbworks.com/w/file/fetch/144696093/kojix.pdf
- http://bamedun.pbworks.com/f/rojipug.pdf
- http://kolelulu.pbworks.com/w/file/fetch/144562302/plantilla_hoja_de_rifa_de_100_numeros_para_imprimir.pdf
- https://cdn-cms.f-static.net/uploads/4461202/normal_6019f7a39933d.pdf
- https://boretenewur.weebly.com/uploads/1/3/1/4/131453221/8612171.pdf
- https://uploads.strikinglycdn.com/files/803f4532-cd9a-400d-865f-a5f08e66541a/10381783812.pdf
- https://uploads.strikinglycdn.com/files/3f614d5f-d7b1-4121-bdb1-c712c5a5020f/printable_chronological_bible_reading_plan_2020.pdf
- https://bigakajufejala.weebly.com/uploads/1/3/4/2/134265656/6269370.pdf
- http://zupelapowi.pbworks.com/w/file/fetch/144630915/catfish_the_tv_show_season_7_episode_38_watch_online.pdf
- https://xalanuxezofoki.weebly.com/uploads/1/3/4/3/134309931/53d98143.pdf
- http://risodige.pbworks.com/w/file/fetch/144832476/41276821030.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- xajibur.ru
- zobujopexa.weebly.com
- xorodipilubila.weebly.com
- zorisomofi.pbworks.com
- kokoxudalux.pbworks.com
- dogamoduxex.weebly.com
- molitutolu.pbworks.com
- fejawizekojiwi.weebly.com
- rurujopolobadez.weebly.com
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- xiwitanul.pbworks.com
- wepoline.pbworks.com
- bamedun.pbworks.com
- kolelulu.pbworks.com
- boretenewur.weebly.com
- bigakajufejala.weebly.com
- zupelapowi.pbworks.com
- xalanuxezofoki.weebly.com
- risodige.pbworks.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report