MALICIOUS — 2ebfb608652b729.pdf
MALICIOUS — 2ebfb608652b729.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100). 4 of 50 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
2d3939f8fcb8140f93f6f1597789e1c1e321c727108eafa8c186bb7c7ae35fa9 - SHA-1:
586f4be222c2603a93e276ee0277f4795d24d720 - MD5:
99a7f52e182d76f3f31eee0d2e8d6053 - ssdeep:
1536:QVcBun5di7XWcGjIba+MmsBFIvlXurAlcpuhJap5BSXshCcE6B9GYXm755Er:adi1GjIbKpjOckcpWJiGYXm754 - TLSH:
T1DD3BE0F3515BCDCC7A9B5B8765A715A4608EC3CC2179E69400C86B5CCD7C2ECAF90921 - Submitted as: 2ebfb608652b729.pdf
- File type: pdf · Size: 106865 bytes
- Verdict: malicious (94/100)
Detections (4 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Embedded link rated suspicious by URL analysis: https://77da94c0-0f0a-445b-87af-e489a0b5ef66.filesusr.com/ugd/db1da1_58b77a18320940efb2903fcec42516c8.pdf?index=true - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: http://libertinemodels.com/best_chocolate_mud_cake_recipe_everc37oi.pdf, https://uploads.strikinglycdn.com/files/ceaf78c1-3528-4122-aa32-47c9b863ab23/c_tuba_finger_chart_4_valve.pdf, http://mon-cmso.best/701607634738ab19.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://feedproxy.google.com/~r/wb/ENAH/~3/dRGGkpkNhSI/wb?keyword=american%20gods%20season%202%20episode%205%20vulture
- http://libertinemodels.com/best_chocolate_mud_cake_recipe_everc37oi.pdf
- https://uploads.strikinglycdn.com/files/ceaf78c1-3528-4122-aa32-47c9b863ab23/c_tuba_finger_chart_4_valve.pdf
- http://mon-cmso.best/701607634738ab19.pdf
- https://cdn-cms.f-static.net/uploads/4366009/normal_6014214261ea5.pdf
- https://77da94c0-0f0a-445b-87af-e489a0b5ef66.filesusr.com/ugd/db1da1_58b77a18320940efb2903fcec42516c8.pdf?index=true
- http://fikipis.iblogger.org/truist_financial_atlanta_address.pdf
- https://cdn-cms.f-static.net/uploads/4445731/normal_6018e61add1b7.pdf
- https://ab737b70-891a-4a1f-8db9-ee548211cb31.filesusr.com/ugd/ce14f3_ad9fcade1a2a452b8b9ed48bdd590c17.pdf?index=true
- http://iranianvc.com/finders_keepers_losers_weepers_song_lyricsv74u2.pdf
- https://uploads.strikinglycdn.com/files/ccf636f0-f48e-40a9-9597-b6a1421704e3/how_to_replace_the_chain_on_a_remington_chainsaw.pdf
- http://fuxarirudutosas.iblogger.org/cell_biology_crossword_answers.pdf
- http://wefinexof.iblogger.org/32._bimschv.pdf
- http://pipopituga.22web.org/fiwibekifopuwubipat.pdf
- http://dixaxag.rf.gd/89663340229.pdf
- http://eurofamily.pro/36395779533tlag9.pdf
- https://uploads.strikinglycdn.com/files/f8857347-9091-44d5-b8dc-8e65922380b9/how_to_subscribe_with_twitch_prime_on_ipad.pdf
- https://cdn-cms.f-static.net/uploads/4470402/normal_606ab549c76e9.pdf
- https://uploads.strikinglycdn.com/files/48fcbe42-b774-4875-a2c8-91179a4e059e/honda_civic_2006_radio_code_error_e.pdf
- http://zusomiverufal.rf.gd/kireji.pdf
- http://refofigeto.epizy.com/danabudisumebaluxe.pdf
- http://ru-order-687646765445.art/15751204831k7a0a.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
Embedded domains
- feedproxy.google.com
- libertinemodels.com
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- 77da94c0-0f0a-445b-87af-e489a0b5ef66.filesusr.com
- fikipis.iblogger.org
- ab737b70-891a-4a1f-8db9-ee548211cb31.filesusr.com
- iranianvc.com
- fuxarirudutosas.iblogger.org
- wefinexof.iblogger.org
- pipopituga.22web.org
- eurofamily.pro
- refofigeto.epizy.com
- www.w3.org
- purl.org
- ns.adobe.com
- mon-cmso.best
- dixaxag.rf.gd
- zusomiverufal.rf.gd
- ru-order-687646765445.art
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report