MALICIOUS — 6227095.pdf
MALICIOUS — 6227095.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 5 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
15be1e419c8b69262011bf5abcb06ef91269e25309a2c359aaaafb1432fb8ced - SHA-1:
e9f20cd95a3c021882a0a8c9b7b998b6c8282e11 - MD5:
a81996fcda41bc3c317cc60c1d02d592 - ssdeep:
1536:2C2eQX45Mp5pHOLvv4B8mzkYi5LbwdiwkxzeLK9GZsq5eCYTZKSG3B3qva:YeU45quLH4B8mzxitb869HIZvqTZKSGD - TLSH:
T1F838CFF35097EE4C768A6B8379E72A78B0C9D3842032A75154887B1D89FC66F7F10A50 - Submitted as: 6227095.pdf
- File type: pdf · Size: 81180 bytes
- Verdict: malicious (94/100)
Detections (5 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!A81996FCDA41
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: https://a50dbba5-e4fd-40cc-afa9-a45495a5accf.filesusr.com/ugd/7f929b_772b17c8d5a54c678752a0d904d03427.pdf?index=true - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://lozipotod.ru/wb?keyword=aretha%20nessun%20dorma%20story, https://1eb42bdc-3da6-4b32-b75f-4382f1721f8e.filesusr.com/ugd/35474d_47b03c69d4164e7c83c9081e3c002b24.pdf?index=true, https://99516632-72ce-40f3-a9a1-a01c91361c65.filesusr.com/ugd/e42c35_32ef044dca2241a1970efbda76d889c1.pdf?index=true - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://lozipotod.ru/wb?keyword=aretha%20nessun%20dorma%20story
- https://s3.amazonaws.com/gofilafixu/10902241202.pdf
- https://1eb42bdc-3da6-4b32-b75f-4382f1721f8e.filesusr.com/ugd/35474d_47b03c69d4164e7c83c9081e3c002b24.pdf?index=true
- https://99516632-72ce-40f3-a9a1-a01c91361c65.filesusr.com/ugd/e42c35_32ef044dca2241a1970efbda76d889c1.pdf?index=true
- https://uploads.strikinglycdn.com/files/784caf29-ded0-430e-a3c1-f442235b40e0/cheetah_tv_mount_directions.pdf
- https://uploads.strikinglycdn.com/files/36d20381-d6f9-47e2-83e9-9255ed6664f9/what_are_the_ranks_in_the_raaf.pdf
- https://s3.amazonaws.com/kumasala/sobazojasulaz.pdf
- https://uploads.strikinglycdn.com/files/3a3a3ef6-0d4b-4117-b5f2-b7313d6bd2d6/6838966688.pdf
- https://a50dbba5-e4fd-40cc-afa9-a45495a5accf.filesusr.com/ugd/7f929b_772b17c8d5a54c678752a0d904d03427.pdf?index=true
- https://s3.amazonaws.com/lazesej/31954992213.pdf
- https://s3.amazonaws.com/desenaz/bereket_vakf_burs_bavurusu_formu.pdf
- http://istlan.space/xfinity_prepaid_internet_and_instant_tvolfrd.pdf
- https://s3.amazonaws.com/fonazuzixagizir/behavioral_star_questions_and_answers.pdf
- https://uploads.strikinglycdn.com/files/92a92fab-4784-4e18-be47-b673effb1d4e/web_services_basics_tutorial.pdf
- https://c78267de-509c-4cb0-9394-6b21b7876e04.filesusr.com/ugd/290ce3_28275a710ffb444eb550c38a2f97a9d0.pdf?index=true
- https://4868a29a-6d77-448d-a9c5-bc5c6a1713c3.filesusr.com/ugd/060e50_39a92b20eadd4fe19df24c4a3211fadb.pdf?index=true
- https://uploads.strikinglycdn.com/files/ecd48833-6c1e-4e65-9a66-a4f6cefbc558/what_are_the_top_social_problems_in_america.pdf
- http://berkeciftci.net/247234017135ebu3.pdf
- https://uploads.strikinglycdn.com/files/e7e86232-1947-46fb-917e-4058a3414e4b/89674553449.pdf
- http://agreevudb.rest/49539462715w3fhi.pdf
- https://94db4134-5784-44c5-a63d-963e509970fa.filesusr.com/ugd/9c58c5_840890a1e8fb429588433e36153f5f6a.pdf?index=true
- https://uploads.strikinglycdn.com/files/e54b3a63-1a2d-45da-b165-969e6aee6314/how_to_check_license_status_sc.pdf
- http://teachersaid.fun/catholic_bible_concordance_freeuj2hd.pdf
- https://9e77dbea-16d6-438e-9859-4a68c5388828.filesusr.com/ugd/3225da_52dcfe90f0c54d7dbd6de157f4a6da5f.pdf?index=true
- https://ba10d46a-d7c1-43af-8542-f1a50f31aa8a.filesusr.com/ugd/4dded2_b51a3c0b80f146fcbad16e477ff61896.pdf?index=true
Embedded domains
- lozipotod.ru
- s3.amazonaws.com
- 1eb42bdc-3da6-4b32-b75f-4382f1721f8e.filesusr.com
- 99516632-72ce-40f3-a9a1-a01c91361c65.filesusr.com
- uploads.strikinglycdn.com
- a50dbba5-e4fd-40cc-afa9-a45495a5accf.filesusr.com
- istlan.space
- c78267de-509c-4cb0-9394-6b21b7876e04.filesusr.com
- 4868a29a-6d77-448d-a9c5-bc5c6a1713c3.filesusr.com
- berkeciftci.net
- 94db4134-5784-44c5-a63d-963e509970fa.filesusr.com
- teachersaid.fun
- 9e77dbea-16d6-438e-9859-4a68c5388828.filesusr.com
- ba10d46a-d7c1-43af-8542-f1a50f31aa8a.filesusr.com
- slimerecipe.org
- www.w3.org
- purl.org
- ns.adobe.com
- agreevudb.rest
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report