MALICIOUS — 1d4a506e20d7bd5e22b3ed11204012b34c7354086ccd11afafc565a65550d368
MALICIOUS — 1d4a506e20d7bd5e22b3ed11204012b34c7354086ccd11afafc565a65550d368 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 4 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
1d4a506e20d7bd5e22b3ed11204012b34c7354086ccd11afafc565a65550d368 - SHA-1:
0a418e62179cda24491dcb074b7f9f60534e37de - MD5:
a7e3d1684abc5c9a01c2e72921242f02 - ssdeep:
3072:zrqIB8G5hVFcVj2lsy5HTWPPPiWDENApsetm8B6kXnIMQKdjfNQiW4mUU:zOk8eNUCcPPiWDBsetm066IML2t - TLSH:
T18140F1F7209BDD9CBA877F43AAAB196D7095CBD9307192405458B33CC0B82AD7DC4A81 - Submitted as: 1d4a506e20d7bd5e22b3ed11204012b34c7354086ccd11afafc565a65550d368
- File type: pdf · Size: 180055 bytes
- Verdict: malicious (94/100)
Detections (4 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (rule
Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: https://dodoxatufasiw.weebly.com/uploads/1/3/2/6/132681482/xatagatujerugufu.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://crewmak.ru/pbw?utm_term=pokemon+xy+series+full+episodes, https://xipunozelizu.weebly.com/uploads/1/3/1/3/131382486/zaroxufolimurefufug.pdf, https://xeravatiwawu.weebly.com/uploads/1/3/4/6/134603636/6f0b31b329.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://crewmak.ru/pbw?utm_term=pokemon+xy+series+full+episodes
- https://xipunozelizu.weebly.com/uploads/1/3/1/3/131382486/zaroxufolimurefufug.pdf
- https://xeravatiwawu.weebly.com/uploads/1/3/4/6/134603636/6f0b31b329.pdf
- https://dodoxatufasiw.weebly.com/uploads/1/3/2/6/132681482/xatagatujerugufu.pdf
- https://biditojutorosas.weebly.com/uploads/1/3/4/6/134657596/267221.pdf
- https://kilazazemuvazu.weebly.com/uploads/1/3/1/4/131452741/7c5a0f53c6bb3.pdf
- https://memumozevevu.weebly.com/uploads/1/3/4/3/134378747/wexopomodinorem.pdf
- https://bepewosub.weebly.com/uploads/1/3/4/4/134445398/mamufekexutaj-giwovosi.pdf
- https://vokugekezigak.weebly.com/uploads/1/3/4/5/134592112/tolefubaloni.pdf
- https://uploads.strikinglycdn.com/files/52e66845-e678-4fb0-90ce-108c06a75579/gavipobewiwazafuwobelu.pdf
- http://bulafiko.pbworks.com/w/file/fetch/144759765/1730536151.pdf
- https://lanekugufer.weebly.com/uploads/1/3/5/3/135351315/a00b556228622d.pdf
- http://wenitat.pbworks.com/w/file/fetch/144551961/55906723005.pdf
- https://uploads.strikinglycdn.com/files/5ab57f3d-869c-4979-a2bc-608562b7c341/vifeguzutozugawoxalunijep.pdf
- http://jolowajuwijo.pbworks.com/w/file/fetch/144522741/taxoginolakivute.pdf
- https://dasifapuzo.weebly.com/uploads/1/3/1/4/131454731/loguxizafef.pdf
- https://panulozeti.weebly.com/uploads/1/3/5/3/135351273/e88a185.pdf
- https://movakesomerinid.weebly.com/uploads/1/3/4/5/134528648/zubilafu_xukitawaga.pdf
- https://uploads.strikinglycdn.com/files/044dd5f7-2b5c-4fb8-a8b5-899b0daa2b9a/12_gods_and_goddesses_of_mount_olympus.pdf
- http://xutosop.pbworks.com/f/cube_game_formula_download_in_tamil.pdf
- https://uploads.strikinglycdn.com/files/59427759-4b8d-46ae-b1ae-480b5e2ff426/microsoft_365_teams_user_guide.pdf
- https://uploads.strikinglycdn.com/files/c1b8da67-78ca-4f2c-abfb-67456d73356e/vaxororijovetabolaponexex.pdf
- https://pimejowutaviju.weebly.com/uploads/1/3/4/4/134495028/cba32.pdf
- https://roxasudafuj.weebly.com/uploads/1/3/0/7/130740166/wowoxikawuvus.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- crewmak.ru
- xipunozelizu.weebly.com
- xeravatiwawu.weebly.com
- dodoxatufasiw.weebly.com
- biditojutorosas.weebly.com
- kilazazemuvazu.weebly.com
- memumozevevu.weebly.com
- bepewosub.weebly.com
- vokugekezigak.weebly.com
- uploads.strikinglycdn.com
- bulafiko.pbworks.com
- lanekugufer.weebly.com
- wenitat.pbworks.com
- jolowajuwijo.pbworks.com
- dasifapuzo.weebly.com
- panulozeti.weebly.com
- movakesomerinid.weebly.com
- xutosop.pbworks.com
- pimejowutaviju.weebly.com
- roxasudafuj.weebly.com
- www.w3.org
- purl.org
- ns.adobe.com
File paths
- J:\z
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report