MALICIOUS — 46bbe5_283f48e65332443c91531de7fb0108eb.pdf
MALICIOUS — 46bbe5_283f48e65332443c91531de7fb0108eb.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100). 5 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
1bea9b5fd32999d036c0274e7f9e3d173674e8cb5755bca6e8bac55467982f4d - SHA-1:
35d8a6a1900a0a7d511d362e6a4fe9ba88fc8782 - MD5:
0f0365216e24a4013abd4eb27f4bf640 - ssdeep:
1536:TrEZdWwr62WUKpgJn0dBUU14N2Cp9aI7hX36guZvgfNOkc/gBQcTT:XqlmRz2SdCUE9a3ZvgfNOkIU - TLSH:
T15139E1F310CBCD0C7A8AA74769E6059D605ED688A132E790108DBFBCC97D6BD3E50A11 - Submitted as: 46bbe5_283f48e65332443c91531de7fb0108eb.pdf
- File type: pdf · Size: 85365 bytes
- Verdict: malicious (96/100)
Detections (5 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Trellix Stinger (McAfee): PDF/Phish-FAB!0F0365216E24
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 96/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated malicious by URL analysis: https://uploads.strikinglycdn.com/files/9a9cfb3a-ee01-482f-9d17-fff461e7dd11/38751025207.pdf - network signal, weight 0.70, confidence 0.80
- Embedded network infrastructure: https://kuzutuzo.ru/wix?keyword=choices+stories+you+play+apk+mod, https://b9a4c3d6-4ccf-4d04-9b0f-c2e9c357e15d.filesusr.com/ugd/e5cbe5_1836dbdd779e4358a5f68255ff7dd8ee.pdf?index=true, https://cdn.sqhk.co/wikomawile/ahiVeKo/58951207876.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://kuzutuzo.ru/wix?keyword=choices+stories+you+play+apk+mod
- https://b9a4c3d6-4ccf-4d04-9b0f-c2e9c357e15d.filesusr.com/ugd/e5cbe5_1836dbdd779e4358a5f68255ff7dd8ee.pdf?index=true
- https://cdn.sqhk.co/wikomawile/ahiVeKo/58951207876.pdf
- https://uploads.strikinglycdn.com/files/3d86bc39-6226-4ec5-aed3-2e75ce1e0b81/iliad_book_10_questions.pdf
- http://kufigada.22web.org/what_documents_needed_for_a_drivers_license.pdf
- https://d62ff7d9-aefc-4ab8-8cdf-af38868aea16.filesusr.com/ugd/54b9a1_703fa8ff84814b73a39b05a99577441f.pdf?index=true
- https://uploads.strikinglycdn.com/files/65d39df6-f7b1-44b6-8305-7a1ca3d4fb1e/zidoseben.pdf
- https://cdn.sqhk.co/gezefesete/b8iijan/dawoxefirefosewi.pdf
- https://uploads.strikinglycdn.com/files/9a9cfb3a-ee01-482f-9d17-fff461e7dd11/38751025207.pdf
- https://cdn.sqhk.co/nogorodizet/egeNdgi/roblox_murder_mystery_2_codes_september.pdf
- https://cdn-cms.f-static.net/uploads/4393364/normal_5fd81c403b58f.pdf
- https://cdn.sqhk.co/xipapotug/ghjgGWO/22793429480.pdf
- https://uploads.strikinglycdn.com/files/1cb22adb-b609-45cc-b68f-81367df20d0e/bukujikefobutiwewuwabo.pdf
- https://cdn.sqhk.co/wirujurumugi/gT5ghig/nuzit.pdf
- http://bitediwufekoxem.epizy.com/hanuman_songs_in_tamil.pdf
- https://uploads.strikinglycdn.com/files/2fce8313-6fd7-4387-9ee1-9171923280cc/borixinokojomopari.pdf
- https://bb55feb6-a0c4-48ae-8f72-aea2c45912f8.filesusr.com/ugd/b9801a_da0b013b592744329528877169da4ea7.pdf?index=true
- https://static.s123-cdn-static.com/uploads/4463810/normal_5fc8bb928251d.pdf
- https://711a90e7-97f2-4eab-8690-3003ec1e9b64.filesusr.com/ugd/a0905b_c737db87d7174f36978da7654aa0fe10.pdf?index=true
- https://static.s123-cdn-static.com/uploads/4387573/normal_5ffe0a783935a.pdf
- https://276658a2-c6b1-4a23-bc3b-56c82bce4278.filesusr.com/ugd/f9448a_e271d028daaa447c84bc7bfd64911f03.pdf?index=true
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
Embedded domains
- kuzutuzo.ru
- b9a4c3d6-4ccf-4d04-9b0f-c2e9c357e15d.filesusr.com
- cdn.sqhk.co
- uploads.strikinglycdn.com
- kufigada.22web.org
- d62ff7d9-aefc-4ab8-8cdf-af38868aea16.filesusr.com
- cdn-cms.f-static.net
- bitediwufekoxem.epizy.com
- bb55feb6-a0c4-48ae-8f72-aea2c45912f8.filesusr.com
- static.s123-cdn-static.com
- 711a90e7-97f2-4eab-8690-3003ec1e9b64.filesusr.com
- 276658a2-c6b1-4a23-bc3b-56c82bce4278.filesusr.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report