MALICIOUS — 1a95c791d0436466b7bb4daf14f73265c92a8b99c5e339b5f874890f6e59d5f5
MALICIOUS — 1a95c791d0436466b7bb4daf14f73265c92a8b99c5e339b5f874890f6e59d5f5 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 5 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
1a95c791d0436466b7bb4daf14f73265c92a8b99c5e339b5f874890f6e59d5f5 - SHA-1:
94bebc18071a0880b6ba816eb9ad9de8cdadb7ba - MD5:
fffded522870f4737a274cb80609f8cd - ssdeep:
1536:0LmIa8ih/Qhb7chJtES696w4+mkP8OfDVKpeo85nS:2g8ih/Qhb7chG96l7u9fDQ/ - TLSH:
T11838CFF350DBDC2DBE875F837AB72A9C9489D6CD6120EB501088B76C847C65E6F20642 - Submitted as: 1a95c791d0436466b7bb4daf14f73265c92a8b99c5e339b5f874890f6e59d5f5
- File type: pdf · Size: 80498 bytes
- Verdict: malicious (94/100)
Detections (5 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!FFFDED522870
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: https://cdn-cms.f-static.net/uploads/4383579/normal_604d343b40d0b.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://jottigo.ru/strik?utm_term=what+is+technical+drawing, https://cdn.sqhk.co/jirozixo/FjeOpid/zixugurezufovo.pdf, https://cdn-cms.f-static.net/uploads/4383579/normal_604d343b40d0b.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://jottigo.ru/strik?utm_term=what+is+technical+drawing
- https://cdn.sqhk.co/jirozixo/FjeOpid/zixugurezufovo.pdf
- https://cdn-cms.f-static.net/uploads/4383579/normal_604d343b40d0b.pdf
- https://vafomelopujoxo.weebly.com/uploads/1/3/4/8/134864043/09441c0b9.pdf
- https://kawavaturitavo.weebly.com/uploads/1/3/5/3/135321378/38b974006ac36.pdf
- https://cdn.sqhk.co/fuluzagile/ngdeFie/95839122526.pdf
- http://nuzabokazovuwa.iblogger.org/apostille_texas_form_2101.pdf
- http://xigosilefonaboj.iblogger.org/tuwebapewo.pdf
- https://s3.amazonaws.com/bisiku/visiwaxomofuxofisat.pdf
- https://cdn.sqhk.co/forinabam/hbjhgCl/34128394589.pdf
- https://s3.amazonaws.com/zodererezuzuxi/mejuwiluwelawi.pdf
- https://fujepibipaxider.weebly.com/uploads/1/3/1/0/131070521/8367665.pdf
- http://ralepixevoz.epizy.com/lease_termination_agreement.pdf
- https://cdn-cms.f-static.net/uploads/4401558/normal_603a4e78de5cd.pdf
- https://static.s123-cdn-static.com/uploads/4454163/normal_5fcf8da0c74b2.pdf
- https://durunefa.weebly.com/uploads/1/3/4/7/134712847/8034159.pdf
- https://cdn.sqhk.co/posojuvapono/blgNbje/black_friday_2020_laptop_deals_dell.pdf
- https://sujumakatu.weebly.com/uploads/1/3/1/3/131379709/fc34d1c70.pdf
- http://kuwademepekipil.epizy.com/17033396017.pdf
- https://s3.amazonaws.com/lodazojamuva/loxekefu.pdf
- http://muxobuduxude.epizy.com/english_to_spanish_basic_words.pdf
- https://static.s123-cdn-static.com/uploads/4459036/normal_5ff05c3005dd1.pdf
- http://jarunotaso.rf.gd/material_requirement_planning_process.pdf
- https://s3.amazonaws.com/buxoparadazegu/august_alsina_song_cry_music.pdf
- http://pufuwobexoz.iblogger.org/instagram_video_templates_free.pdf
Embedded domains
- o.eu
- jottigo.ru
- cdn.sqhk.co
- cdn-cms.f-static.net
- vafomelopujoxo.weebly.com
- kawavaturitavo.weebly.com
- nuzabokazovuwa.iblogger.org
- xigosilefonaboj.iblogger.org
- s3.amazonaws.com
- fujepibipaxider.weebly.com
- ralepixevoz.epizy.com
- static.s123-cdn-static.com
- durunefa.weebly.com
- sujumakatu.weebly.com
- kuwademepekipil.epizy.com
- muxobuduxude.epizy.com
- pufuwobexoz.iblogger.org
- lufivav.epizy.com
- www.w3.org
- purl.org
- ns.adobe.com
- jarunotaso.rf.gd
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report