MALICIOUS — 1ad79a8e85ffbb1023514fd337d65e01c4453aef9b08f5a4b6c856c1f2325982
MALICIOUS — 1ad79a8e85ffbb1023514fd337d65e01c4453aef9b08f5a4b6c856c1f2325982 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 5 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
1ad79a8e85ffbb1023514fd337d65e01c4453aef9b08f5a4b6c856c1f2325982 - SHA-1:
a7fe9df17d71cce44234445cea47ab7e9938db63 - MD5:
2e5d75dc46cd8f5c7420ebaafc546a53 - ssdeep:
1536:Dl0piJXq/mQoDtnT4vSMzKHclvgwuMQKBD12tZL7qtIcvTWmHxRSN:+iJa2D8QHa4GIbL+Wc1HA - TLSH:
T1A738D0F7519BDD8C769A9B477DBB256C34C9D3886123DB800488BA6CC86C2BC3E11661 - Submitted as: 1ad79a8e85ffbb1023514fd337d65e01c4453aef9b08f5a4b6c856c1f2325982
- File type: pdf · Size: 76796 bytes
- Verdict: malicious (96/100)
Detections (5 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!2E5D75DC46CD
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: https://static.s123-cdn-static.com/uploads/4368238/normal_5fdec8d1c4432.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://botokaw.ru/123?utm_term=bed+and+bath+extra+long+twin+sheets, http://bilapak.66ghz.com/44442640603.pdf, https://uploads.strikinglycdn.com/files/0d6a53f0-8a69-4b80-b3d8-00aafbed6737/duralast_900_amp_jump_starter_charger.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://botokaw.ru/123?utm_term=bed+and+bath+extra+long+twin+sheets
- http://bilapak.66ghz.com/44442640603.pdf
- https://s3.amazonaws.com/litunux/is_panda_express_safe_to_eat_while_pregnant.pdf
- https://s3.amazonaws.com/gidibesuxi/pilujiw.pdf
- https://uploads.strikinglycdn.com/files/0d6a53f0-8a69-4b80-b3d8-00aafbed6737/duralast_900_amp_jump_starter_charger.pdf
- http://kubagaxupusu.epizy.com/ampli_vox_ac15cc1x.pdf
- http://nudobovedazopor.epizy.com/quality_and_reliability_engineering_book.pdf
- https://cdn-cms.f-static.net/uploads/4489716/normal_6056d0bf810c0.pdf
- https://xijaxerunoseme.weebly.com/uploads/1/3/4/3/134306079/8627986.pdf
- https://s3.amazonaws.com/vabedafozo/88721895045.pdf
- https://uploads.strikinglycdn.com/files/38e015d4-a13c-46e3-aee0-518523766e48/troy_bilt_tb130_xp_parts_diagram.pdf
- https://static.s123-cdn-static.com/uploads/4368238/normal_5fdec8d1c4432.pdf
- https://static.s123-cdn-static.com/uploads/4489042/normal_60082931d5a97.pdf
- https://sasofisapen.weebly.com/uploads/1/3/4/5/134590640/malur.pdf
- https://bunojero.weebly.com/uploads/1/3/0/8/130874162/jozinawuxifapo-viwituvitorub-tekovoke-fetuveje.pdf
- https://vuxuminitemup.weebly.com/uploads/1/3/0/8/130874085/d80f0.pdf
- https://lefojokux.weebly.com/uploads/1/3/5/3/135399193/sewapixofopaguv-radujo-gadofogan.pdf
- https://figiroxofidun.weebly.com/uploads/1/3/0/7/130740151/dasurozoxomisam.pdf
- https://wofibenozoga.weebly.com/uploads/1/3/5/3/135321696/2147862.pdf
- https://cdn-cms.f-static.net/uploads/4419218/normal_5fe6ce421fdec.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
Embedded domains
- botokaw.ru
- bilapak.66ghz.com
- s3.amazonaws.com
- uploads.strikinglycdn.com
- kubagaxupusu.epizy.com
- nudobovedazopor.epizy.com
- cdn-cms.f-static.net
- xijaxerunoseme.weebly.com
- static.s123-cdn-static.com
- sasofisapen.weebly.com
- bunojero.weebly.com
- vuxuminitemup.weebly.com
- lefojokux.weebly.com
- figiroxofidun.weebly.com
- wofibenozoga.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report