MALICIOUS — how_to_tone_your_back_with_resistance_bands.pdf
MALICIOUS — how_to_tone_your_back_with_resistance_bands.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 5 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
1877d0b867e1336b9749269c7c82670eeb39fa88df8ad6c9c830a5fd8835725e - SHA-1:
45e1db0ff289ec71339e30b2a30946cb679e182a - MD5:
0704051eb45f3aaea7f4e0c8f250335e - ssdeep:
1536:K10vs2mPaQGi8+QxSLwFmEUVHQlPEuyqeHMSPUrjHdaBuykH/T:EcePaQWfcwFmEUVwlP7yO3Hdahk7 - TLSH:
T11438D1F361DFCF8C3E474B532AAB36596445C2D87622DBA00588B66CC87C67EAF00552 - Submitted as: how_to_tone_your_back_with_resistance_bands.pdf
- File type: pdf · Size: 78528 bytes
- Verdict: malicious (96/100)
Detections (5 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!0704051EB45F
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: https://uploads.strikinglycdn.com/files/4f43df60-4dc3-4049-abbf-072534bf1676/lazajiwire.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://pelibifir.ru/strik?utm_term=how+to+tone+your+back+with+resistance+bands, https://9610c43f-1b2a-4a8a-b660-75aaf3908198.filesusr.com/ugd/286fb8_3b2159c6f2384a4f98557136f1e625fa.pdf?index=true, https://cdn-cms.f-static.net/uploads/4367273/normal_60462950e8830.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://pelibifir.ru/strik?utm_term=how+to+tone+your+back+with+resistance+bands
- https://9610c43f-1b2a-4a8a-b660-75aaf3908198.filesusr.com/ugd/286fb8_3b2159c6f2384a4f98557136f1e625fa.pdf?index=true
- https://cdn-cms.f-static.net/uploads/4367273/normal_60462950e8830.pdf
- https://uploads.strikinglycdn.com/files/4f43df60-4dc3-4049-abbf-072534bf1676/lazajiwire.pdf
- https://cdn-cms.f-static.net/uploads/4413713/normal_6046688b8ee39.pdf
- https://ca483b97-61ac-4196-bca0-6b249c18eca9.filesusr.com/ugd/b27199_1564969e697a4535a75b5a6a522a33ee.pdf?index=true
- https://f1ddcea9-c323-452c-a4d3-aaefec61e50a.filesusr.com/ugd/defd8a_4e6b6b7a0a2c46919a66765731c30086.pdf?index=true
- http://nakekizedexu.getenjoyment.net/xijixuwemifabiwa.pdf
- http://ionatr.space/the_tao_of_network_security_monitoring_beyond_intrusion_detection_downloadkcjo8.pdf
- http://okstore.info/87256369737ge5fp.pdf
- http://zizodoroluxonaf.sportsontheweb.net/fujitidimidubodin.pdf
- https://f770b3d7-c897-40e0-9323-5ad0abd91552.filesusr.com/ugd/1fa6dd_9a3d229ec703496083816d3dbe2a4293.pdf?index=true
- https://cdn-cms.f-static.net/uploads/4409621/normal_605b88e887af7.pdf
- http://1gusevshop.space/mobakivujis6r1j.pdf
- https://cdn-cms.f-static.net/uploads/4405430/normal_601881b443dd7.pdf
- https://cdn-cms.f-static.net/uploads/4450430/normal_6069f88606981.pdf
- https://cdn-cms.f-static.net/uploads/4412160/normal_604b298850c76.pdf
- https://uploads.strikinglycdn.com/files/a250912f-4d88-4b11-934f-9cb8a11cdbc2/vakowazogezizujuzasi.pdf
- https://uploads.strikinglycdn.com/files/24c167b9-3c36-4458-8881-346f10f83816/63974382579.pdf
- http://best-store.club/35319074310n19ga.pdf
- https://uploads.strikinglycdn.com/files/25b92092-b0c0-4730-870a-423b91d9c229/42775647875.pdf
- https://336ddc11-c37d-4cd6-9685-7accad2975f7.filesusr.com/ugd/479fa9_7d496c610e4040f380b753adc7cdc267.pdf?index=true
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- pelibifir.ru
- 9610c43f-1b2a-4a8a-b660-75aaf3908198.filesusr.com
- cdn-cms.f-static.net
- uploads.strikinglycdn.com
- ca483b97-61ac-4196-bca0-6b249c18eca9.filesusr.com
- f1ddcea9-c323-452c-a4d3-aaefec61e50a.filesusr.com
- nakekizedexu.getenjoyment.net
- ionatr.space
- okstore.info
- zizodoroluxonaf.sportsontheweb.net
- f770b3d7-c897-40e0-9323-5ad0abd91552.filesusr.com
- 1gusevshop.space
- best-store.club
- 336ddc11-c37d-4cd6-9685-7accad2975f7.filesusr.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report